client-secret-exposure-audit
client-secret-exposure-audit is an code AI skill with a core value of Audit a deployed web app for secrets exposed to the browser: hardcoded API keys/tokens in JS, secrets in HTML meta/attributes/comments, publicly reachable source/config/deploy files, and header/CORS m. It
helps developers solve real-world problems in the code domain, boosting
efficiency, automating repetitive tasks, and optimizing workflows.
Audit a deployed web app for secrets exposed to the browser: hardcoded API keys/tokens in JS, secrets in HTML meta/attributes/comments, publicly reachable source/config/deploy files, and header/CORS m
Quick Facts
mkdir -p ./skills/client-secret-exposure-audit && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/client-secret-exposure-audit/SKILL.md -o ./skills/client-secret-exposure-audit/SKILL.md Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).
Skill Content
# Client-Side Secret & Sensitive-File Exposure Audit
Overview
Modern web apps ship a lot of code and config to the browser. When credentials
leak into that client-visible surface — hardcoded in JavaScript, tucked into HTML
`meta`/`data-*` attributes or comments, or served as raw source/config/deploy
files that were never meant to be public — anyone can read them with `curl` and a
browser. This skill is a **defensive, read-only** workflow for finding that class
of exposure on a web app **you are authorized to assess**.
It maps to OWASP **A02:2021 Cryptographic Failures** (sensitive data exposure),
**A05:2021 Security Misconfiguration**, and CWE-798 (hardcoded credentials),
CWE-200 (sensitive information exposure), CWE-540 (source code in a production
build). It only fetches resources the server already hands to any anonymous
visitor — it does not exploit, brute-force, or mutate anything.
When to Use This Skill
- Use when you need to check whether a deployed site leaks API keys, tokens, or
passwords in its client-side bundle before shipping or during a review.
- Use when working with a static/SPA deployment (Vercel, Netlify, Nginx, S3,
GitHub Pages) and you want to confirm no source/config/deploy files are
publicly reachable.
- Use when the user asks to "find secrets," "audit exposed files," "check the
JS/HTML for credentials," or run a lightweight sensitive-data-exposure pass on
a URL they own or are authorized to test.
- Do **not** use this to attack third-party sites. See *Security & Safety Notes*.
How It Works
Set the target once. Every command below reads only what the server serves
publicly.
BASE="https://TARGET.example" # authorized target, no trailing path
WORK="$(mktemp -d)"; cd "$WORK"Step 1: Fetch the page and inspect response headers
curl -s -D headers.txt -o body.html "$BASE/"
cat headers.txtFlag on the headers:
- `access-control-allow-origin: *` — permissive CORS (worse when paired with
credentials).
- Missing `Content-Security-Policy`, `X-Frame-Options`/`frame-ancestors`,
`X-Content-Type-Options: nosniff`, `Referrer-Policy`, `Permissions-Policy`.
- Missing/weak `Strict-Transport-Security`.
- `Server`/framework version banners that fingerprint the stack.
Step 2: Grep the HTML for secrets and sinks
grep -inE "secret|passwd|password|api[_-]?key|apikey|token|bearer|authorization|\
akia|sk_live|sk_test|pk_live|whsec_|ghp_|aiza|private[_-]?key|mongodb(\+srv)?://|\
data-[a-z-]*(secret|token|key|access)" body.html
grep -inE "<!--" body.html # read every HTML comment
grep -ioE '<meta[^>]+>' body.html # meta tags often carry keys/ids
grep -ioE '<script[^>]+src="[^"]+"' body.html # enumerate JS bundlesSecrets hide in `data-*` attributes, `<meta>` tags, `hidden` `<div>`s, and
`<!-- comments -->` at least as often as in scripts.
Step 3: Pull every JavaScript bundle and scan it
# extract script srcs, resolve relative paths against $BASE, fetch and scan
grep -ioE 'src="[^"]+\.js"' body.html | sed -E 's/^src="//; s/"$//' \
| while read -r p; do
u="$p"; case "$p" in http*) ;; /*) u="$BASE$p";; *) u="$BASE/$p";; esac
f="js_$(echo "$p" | tr '/:' '__')"
curl -s "$u" -o "$f" && echo "== $u =="
done
grep -rinE "secret|password|api[_-]?key|token|bearer|sk_(live|test)|pk_(live|test)|\
whsec_|akia|aiza|jwt|signing[_-]?key|admin[_-]?token|mongodb|redis://" js_* 2>/dev/nullAlso scan any sourcemaps (`*.js.map`) — they can rebuild original source with
comments intact.
Step 4: Probe for publicly reachable source / config / deploy files
SPAs often have a catch-all rewrite that returns `index.html` for unknown paths,
so **compare response sizes** — a path whose size differs from the SPA fallback
is a real, distinct file.
FALLBACK=$(curl -s "$BASE/____nope____$RANDOM" | wc -c) # SPA fallback size
for p in /.env /.env.local /.env.production /.git/config /.git/HEAD \
/package.json /pac🎯 Best For
- Claude users
- Software engineers
- Development teams
- Tech leads
💡 Use Cases
- Code quality improvement
- Best practice enforcement
📖 How to Use This Skill
- 1
Install the Skill
Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.
- 2
Load into Your AI Assistant
Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.
- 3
Apply client-secret-exposure-audit to Your Work
Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.
- 4
Review and Refine
Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.
❓ Frequently Asked Questions
Is client-secret-exposure-audit compatible with Cursor and VS Code?
Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.
Do I need specific dependencies for client-secret-exposure-audit?
Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.
How do I install client-secret-exposure-audit?
Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/client-secret-exposure-audit/SKILL.md, ready to use.
Can I customize this skill for my team?
Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.
⚠️ Common Mistakes to Avoid
Skipping validation
Always test AI-generated code changes, even for simple refactors.
Missing dependency updates
Check if the skill requires updated dependencies or new packages.