Agent skill

Client Secret Exposure Audit

by sickn33 in sickn33/agentic-awesome-skills

Audit a deployed web app for secrets exposed to the browser: hardcoded API keys/tokens in JS, secrets in HTML meta/attributes/comments, publicly reachable source/config/deploy files, and header/CORS…

MITAuto-check: notesBackend & APIs

Install Client Secret Exposure Audit

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill client-secret-exposure-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills client-secret-exposure-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/client-secret-exposure-audit .claude/skills/client-secret-exposure-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
client-secret-exposure-audit
GitHub stars
47k
Used in
1 other repo
Token cost
~2.6k tokens
SKILL.md length
942 words
Files
2 (incl. references)
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Audit a deployed web app for secrets exposed to the browser: hardcoded API keys/tokens in JS, secrets in HTML meta/attributes/comments, publicly reachable source/config/deploy files, and header/CORS…

  • Works in 6 steps: Fetch the page and inspect response… → Grep the HTML for secrets and sinks → Pull every JavaScript bundle and scan it → …
  • Backend & APIs work in your project
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Examples, plus 5 more sections
  • Calls curl; reaches demo-for-opensource.vercel.app; needs API_SECRET and ADMIN_TOKEN

What it does

Client Secret Exposure Audit is an agent skill from sickn33/agentic-awesome-skills. Audit a deployed web app for secrets exposed to the browser: hardcoded API keys/tokens in JS, secrets in HTML meta/attributes/comments, publicly reachable source/config/deploy files, and header/CORS misconfig.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/example-report.md`).

It sits in Backend & APIs. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/client-secret-exposure-audit”

Requirements

  • Docker
  • A credential in API_SECRET
  • A credential in ADMIN_TOKEN

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Fetch the page and inspect response headers
  2. Grep the HTML for secrets and sinks
  3. Pull every JavaScript bundle and scan it
  4. Probe for publicly reachable source / config / deploy files
  5. Triage and score
  6. Report

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • demo-for-opensource.vercel.app

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_SECRET
    • ADMIN_TOKEN
    • JWT_SECRET
    • DATABASE_PASSWORD
    • PAYMENT_SIGNING_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Client Secret Exposure Audit loads about 2.6k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 60 tokens; SKILL.md has 942 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:108
    for p in /.env /.env.local /.env.production /.git/config /.git/HEAD \

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 942 words, ~2,608 tokens.

Download SKILL.mdSave it as .claude/skills/client-secret-exposure-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
client-secret-exposure-audit
description
Audit a deployed web app for secrets exposed to the browser: hardcoded API keys/tokens in JS, secrets in HTML meta/attributes/comments, publicly reachable source/config/deploy files, and header/CORS misconfig.
category
security
risk
safe
source
self
source_type
self
date_added
2026-09-10
author
siddanta-ar1
tags
security, secrets, owasp, reconnaissance, web, headers
tools
claude, cursor, gemini

Client-Side Secret & Sensitive-File Exposure Audit

Overview

Modern web apps ship a lot of code and config to the browser. When credentials leak into that client-visible surface — hardcoded in JavaScript, tucked into HTML meta/data-* attributes or comments, or served as raw source/config/deploy files that were never meant to be public — anyone can read them with curl and a browser. This skill is a defensive, read-only workflow for finding that class of exposure on a web app you are authorized to assess.

It maps to OWASP A02:2021 Cryptographic Failures (sensitive data exposure), A05:2021 Security Misconfiguration, and CWE-798 (hardcoded credentials), CWE-200 (sensitive information exposure), CWE-540 (source code in a production build). It only fetches resources the server already hands to any anonymous visitor — it does not exploit, brute-force, or mutate anything.

When to Use This Skill

  • Use when you need to check whether a deployed site leaks API keys, tokens, or passwords in its client-side bundle before shipping or during a review.
  • Use when working with a static/SPA deployment (Vercel, Netlify, Nginx, S3, GitHub Pages) and you want to confirm no source/config/deploy files are publicly reachable.
  • Use when the user asks to "find secrets," "audit exposed files," "check the JS/HTML for credentials," or run a lightweight sensitive-data-exposure pass on a URL they own or are authorized to test.
  • Do not use this to attack third-party sites. See Security & Safety Notes.

How It Works

Set the target once. Every command below reads only what the server serves publicly.

bash
BASE="https://TARGET.example"     # authorized target, no trailing path
WORK="$(mktemp -d)"; cd "$WORK"
Step 1: Fetch the page and inspect response headers
bash
curl -s -D headers.txt -o body.html "$BASE/"
cat headers.txt

Flag on the headers:

  • access-control-allow-origin: * — permissive CORS (worse when paired with credentials).
  • Missing Content-Security-Policy, X-Frame-Options/frame-ancestors, X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy.
  • Missing/weak Strict-Transport-Security.
  • Server/framework version banners that fingerprint the stack.
Step 2: Grep the HTML for secrets and sinks
bash
grep -inE "secret|passwd|password|api[_-]?key|apikey|token|bearer|authorization|\
akia|sk_live|sk_test|pk_live|whsec_|ghp_|aiza|private[_-]?key|mongodb(\+srv)?://|\
data-[a-z-]*(secret|token|key|access)" body.html
grep -inE "<!--" body.html            # read every HTML comment
grep -ioE '<meta[^>]+>' body.html     # meta tags often carry keys/ids
grep -ioE '<script[^>]+src="[^"]+"'   body.html   # enumerate JS bundles

Secrets hide in data-* attributes, <meta> tags, hidden <div>s, and <!-- comments --> at least as often as in scripts.

Step 3: Pull every JavaScript bundle and scan it
bash
# extract script srcs, resolve relative paths against $BASE, fetch and scan
grep -ioE 'src="[^"]+\.js"' body.html | sed -E 's/^src="//; s/"$//' \
 | while read -r p; do
     u="$p"; case "$p" in http*) ;; /*) u="$BASE$p";; *) u="$BASE/$p";; esac
     f="js_$(echo "$p" | tr '/:' '__')"
     curl -s "$u" -o "$f" && echo "== $u =="
   done
grep -rinE "secret|password|api[_-]?key|token|bearer|sk_(live|test)|pk_(live|test)|\
whsec_|akia|aiza|jwt|signing[_-]?key|admin[_-]?token|mongodb|redis://" js_* 2>/dev/null

Also scan any sourcemaps (*.js.map) — they can rebuild original source with comments intact.

Step 4: Probe for publicly reachable source / config / deploy files

SPAs often have a catch-all rewrite that returns index.html for unknown paths, so compare response sizes — a path whose size differs from the SPA fallback is a real, distinct file.

bash
FALLBACK=$(curl -s "$BASE/____nope____$RANDOM" | wc -c)   # SPA fallback size
for p in /.env /.env.local /.env.production /.git/config /.git/HEAD \
  /package.json /package-lock.json /vercel.json /.vercel/project.json \
  /Dockerfile /docker-compose.yml /wrangler.toml /.gitignore \
  /server/index.js /src/config/app.config.js /config.js \
  /src/services/payment.service.js /webpack.config.js /next.config.js; do
    read -r code size < <(curl -s -o /dev/null -w "%{http_code} %{size_download}" "$BASE$p")
    [ "$code" = "200" ] && [ "$size" != "$FALLBACK" ] && echo "REAL FILE  $code $size  $p"
done

For any real file found, fetch it and re-run the Step 2/3 secret grep. Follow require(...)/import paths inside those files to discover more source files (routes, controllers, services, webhooks) and repeat.

Step 5: Triage and score

Rate each finding by blast radius, not by where it was found:

SeverityExamples
CriticalLive provider secret keys (sk_live_, cloud AKIA…+secret, DB URI with password, private signing/JWT secret, admin bearer token) reachable anonymously
HighServer-side source/config/deploy files exposed; test-mode secret keys; internal service tokens; webhook signing secrets
MediumCORS *, missing CSP/security headers, verbose banners, weak randomness for security values (Math.random() for tokens/refs)
Low / InfoPublic keys correctly client-side, analytics IDs, non-secret config, stack fingerprinting

A key being "test/demo" does not make it safe if the pattern would ship a live key the same way — report the pattern.

Step 6: Report

Write findings as Markdown using the format in references/example-report.md: one row/section per finding with Severity · Category (OWASP/CWE) · Location · Evidence (redacted) · Impact · Remediation. Redact real secret material to a prefix + length. End with prioritized remediation and a note on which secrets must be rotated, not just removed (anything committed/served is already compromised).

Examples

Example 1: Secrets in HTML meta and hidden elements
bash
BASE="https://demo-for-opensource.vercel.app"; curl -s "$BASE/" -o body.html
grep -inE "recaptcha-secret|data-aws-secret|data-webhook-secret|mongodb\+srv" body.html
# -> meta recaptcha-secret=..., data-aws-access=AKIA…/data-aws-secret=…,
#    data-webhook-secret=whsec_…, and a hidden JSON blob with a mongodb+srv URI
#    (username:password@cluster). All reachable with a single unauthenticated GET.
Show full SKILL.md (376 more words)Show less
Example 2: Hardcoded credentials in a JS config bundle
bash
curl -s "$BASE/public/assets/js/config.js" | \
  grep -inE "API_SECRET|ADMIN_TOKEN|JWT_SECRET|DATABASE_PASSWORD|PAYMENT_SIGNING_KEY"
# -> API_SECRET, ADMIN_TOKEN (JWT), JWT_SECRET, DATABASE_PASSWORD, and a payment
#    signing key, all assigned as plain string constants shipped to every browser.
Example 3: Server source exposed behind a SPA fallback
bash
FALLBACK=$(curl -s "$BASE/__nope__" | wc -c)
for p in /server/index.js /docker-compose.yml /src/services/payment.service.js; do
  sz=$(curl -s "$BASE$p" | wc -c); [ "$sz" != "$FALLBACK" ] && echo "REAL $sz $p"
done
# -> docker-compose.yml leaks a Redis password; payment.service.js leaks
#    Stripe/Khalti secret keys + webhook secret. Distinct sizes prove they are
#    real files, not the SPA catch-all page.

A full worked report for this target is in references/example-report.md.

Best Practices

  • ✅ Confirm written authorization and scope (the exact hostnames) before fetching.
  • ✅ Compare every probed path against the SPA fallback size to avoid false 200s.
  • ✅ Follow require/import chains in any exposed source file to find more files.
  • ✅ Redact real secret values in the report; record enough to identify, not reuse.
  • ✅ Flag secrets for rotation — served/committed secrets are already burned.
  • ❌ Don't use discovered credentials to authenticate, pivot, or access data.
  • ❌ Don't run this against sites you don't own or aren't authorized to test.
  • ❌ Don't treat "it's a test/demo key" as safe — report the shipping pattern.

Limitations

  • Read-only reconnaissance of client-served assets; it does not test injection, auth logic, IDOR, or server-side flaws — pair with @web-security-testing.
  • Path probing uses a wordlist; it finds common exposures, not every file.
  • This skill does not replace environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if authorization, scope, or safety boundaries are missing.

Security & Safety Notes

  • Authorized targets only. Run exclusively against systems you own or have explicit written permission to assess. Unauthorized scanning may be illegal.
  • Every command here performs only unauthenticated GET requests for resources the server already serves publicly — no exploitation, brute force, or mutation.
  • Handle any real secrets you uncover as sensitive: store findings in an access- controlled location, redact them in shared reports, and recommend rotation.
  • Do not exfiltrate data or reuse discovered credentials — locating an exposure is the deliverable; using it is out of scope.

Common Pitfalls

  • Problem: Every probed path returns HTTP 200, hiding real files. Solution: SPA catch-all rewrite. Baseline the fallback body size and only treat paths with a different size as real files.
  • Problem: Grep misses secrets stored in data-* attributes or comments. Solution: Also scan <meta>, data-*, hidden elements, and every <!-- comment -->, not just <script> bodies.
  • Problem: Dismissing a finding because the key is labeled "test/demo." Solution: Report the pattern — the same code path would ship a live key.
  • @web-security-testing — broader OWASP Top 10 workflow; use for injection, auth, and access-control testing this skill does not cover.
  • @dependency-management-deps-audit — pairs well for supply-chain/component risk once client exposure is triaged.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/client-secret-exposure-audit of sickn33/agentic-awesome-skills.

  • SKILL.md
  • references/example-report.md

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Client Secret Exposure Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Client Secret Exposure Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Client Secret Exposure Audit this skillsickn33/agentic-awesome-skills47k1 repos~2.6kAutomated safety check: NotesMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Backend Dev Guidelineslangfuse/langfuse36k—~1.9kAutomated safety check: PassCustom licence
Mintlify APImacro-inc/macro4.6k2 repos~333Automated safety check: PassMIT
Mirrord Kafkametalbear-co/mirrord5.4k1 repos~6kAutomated safety check: PassMIT
Rtvi Vlm Perf TestingNVIDIA-AI-Blueprints/video-search-and-summarization1.9k—~8.6kAutomated safety check: NotesApache-2.0

Similar skills

  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Backend Dev Guidelines

    langfuse/langfuse

    Build or review Langfuse backend code. An agent skill from langfuse/langfuse.

    36k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Mintlify API

    macro-inc/macro

    Interact with the Mintlify REST API to manage deployments, trigger builds, and query documentation site metadata programmatically.

    4.6k GitHub starsUsed in 2 repos~333 tokens
    Backend & APIsAuto-check passed
  • Mirrord Kafka

    metalbear-co/mirrord

    Helps DevOps engineers configure mirrord Operator's Kafka queue splitting feature end-to-end.

    5.4k GitHub starsUsed in 1 repo~6k tokens
    Backend & APIsAuto-check passed
  • Rtvi Vlm Perf Testing

    NVIDIA-AI-Blueprints/video-search-and-summarization

    Plan, run, and diagnose reproducible RT-VLM GPU performance canaries and benchmarks.

    1.9k GitHub stars~8.6k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Mail Time

    veliovgroup/mail-time

    A skill your agent uses when building, wiring, reviewing, or debugging MailTime and ostrio:mailer email queues for horizontally scaled Node.js, Bun, or Meteor apps.

    143 GitHub stars~1k tokensUpdated 3 days ago
    DatabasesAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Client Secret Exposure Audit

What does Client Secret Exposure Audit do?

Audit a deployed web app for secrets exposed to the browser: hardcoded API keys/tokens in JS, secrets in HTML meta/attributes/comments, publicly reachable source/config/deploy files, and header/CORS…. Client Secret Exposure Audit is an agent skill from sickn33/agentic-awesome-skills. Audit a deployed web app for secrets exposed to the browser: hardcoded API keys/tokens in JS, secrets in HTML meta/attributes/comments, publicly reachable source/config/deploy files, and header/CORS misconfig.

When should I use Client Secret Exposure Audit?

Client Secret Exposure Audit fits situations like: backend & APIs work in your project.

How do I install Client Secret Exposure Audit in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill client-secret-exposure-audit -a claude-code`. Or copy the skill folder (skills/client-secret-exposure-audit in sickn33/agentic-awesome-skills) into .claude/skills/client-secret-exposure-audit in your project. Claude Code loads it when a task matches its description.

How do I install Client Secret Exposure Audit in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill client-secret-exposure-audit -a codex`. Or copy the skill folder (skills/client-secret-exposure-audit in sickn33/agentic-awesome-skills) into .agents/skills/client-secret-exposure-audit in your project. Codex loads it when a task matches its description.

Can I use Client Secret Exposure Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill client-secret-exposure-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/client-secret-exposure-audit, .gemini/skills/client-secret-exposure-audit, .github/skills/client-secret-exposure-audit and .opencode/skills/client-secret-exposure-audit in your project.

What does Client Secret Exposure Audit need to run?

Going by SKILL.md and its folder, Client Secret Exposure Audit needs the command-line tools its instructions call (curl) and credentials named API_SECRET, ADMIN_TOKEN, JWT_SECRET and DATABASE_PASSWORD. Our summary lists: Docker; A credential in API_SECRET; A credential in ADMIN_TOKEN.

Does Client Secret Exposure Audit access the network?

SKILL.md names 1 domain. In commands or code: demo-for-opensource.vercel.app; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Client Secret Exposure Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Client Secret Exposure Audit use?

Client Secret Exposure Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Client Secret Exposure Audit use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Client Secret Exposure Audit?

Skills that share tags, products or a category with Client Secret Exposure Audit: Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars), Backend Dev Guidelines (langfuse/langfuse, 36k stars), Mintlify API (macro-inc/macro, 4.6k stars) and Mirrord Kafka (metalbear-co/mirrord, 5.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Client Secret Exposure Audit?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.