Agent skill

Leaked Secrets

by thedaviddias in thedaviddias/Front-End-Checklist

A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.

MITAuto-check: notesDevOps & Cloud

Install Leaked Secrets

skills CLI
$ npx skills add thedaviddias/Front-End-Checklist --skill leaked-secrets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install thedaviddias/Front-End-Checklist leaked-secrets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/thedaviddias/Front-End-Checklist.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/leaked-secrets .claude/skills/leaked-secrets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
leaked-secrets
GitHub stars
74k
Token cost
~596 tokens
SKILL.md length
269 words
Files
2 (incl. references)
Skills in repo
390
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.

  • Reviewing client-side JavaScript
  • SKILL.md covers Quick Reference, Check, Fix and Explain, plus 1 more section
  • Calls git
  • Git history for exposed credentials

What it does

Leaked Secrets is an agent skill from thedaviddias/Front-End-Checklist. Use when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.

Its SKILL.md is about 600 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/rule.md`).

It sits in DevOps & Cloud, covering Secrets management and Git workflow. It works with JavaScript and Git. The repository describes itself as: 🗂 The essential checklist for modern web development, for humans and AI agents. The licence is MIT.

When your agent uses it

  • Reviewing client-side JavaScript
  • Git history for exposed credentials

Example prompts

  • “/leaked-secrets”

What it can do on your machine

Read from SKILL.md and the folder at commit e8d14d0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • frontendchecklist.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Leaked Secrets loads about 596 tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 33 tokens; SKILL.md has 269 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~596
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:21
    - Common leak locations: `.env` files committed to git, hardcoded API keys in JS bundles, service account credentials in

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from thedaviddias/Front-End-Checklist at commit e8d14d0, republished under its MIT licence (© thedaviddias). 269 words, ~596 tokens.

Download SKILL.mdSave it as .claude/skills/leaked-secrets/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
leaked-secrets
description
Use when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.
metadata.category
security
metadata.priority
critical
metadata.difficulty
intermediate
metadata.estimatedTime
20
metadata.source
frontendchecklist.io
metadata.url
https://frontendchecklist.io/rules/security/leaked-secrets

Leaked Environment Variables

An API key embedded in client-side JavaScript gives anyone with a browser devtools tab full access to your cloud services, databases, or third-party APIs — leading to data breaches, unexpected charges, or account takeover.

Quick Reference

  • Any secret in client-side JavaScript is publicly readable — treat all front-end code as public
  • In Next.js, only variables prefixed with NEXT_PUBLIC_ are exposed to the browser — never put secrets in these
  • Common leak locations: .env files committed to git, hardcoded API keys in JS bundles, service account credentials in window.__INITIAL_STATE__
  • Use git log -S 'keyword' to search git history for previously committed secrets; rotate any found secrets immediately
  • Tools: GitLeaks, TruffleHog, GitHub Secret Scanning can detect leaks in repositories automatically

Check

Scan the page HTML source and JavaScript bundles for patterns that look like secrets: API keys, tokens, passwords, private keys, connection strings, or credentials. Check for common patterns like sk_, pk_, AIza, ghp_, AKIA, and base64-encoded strings in unusual contexts.

Fix

Move all secrets server-side. Replace client-exposed credentials with server-side API proxies. Rotate any leaked credentials immediately — treat them as compromised. Implement git-secrets or a pre-commit hook to prevent future leaks.

Explain

Explain why client-side JavaScript is public code, how secrets leak into bundles, what the impact of a leaked API key is, and how to architect applications to keep secrets server-side.

Code Review

Review server config, headers, forms, and integration points related to Leaked Environment Variables. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/rules/security/leaked-secrets

© thedaviddias, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/leaked-secrets of thedaviddias/Front-End-Checklist.

  • SKILL.md
  • references/rule.md

Open the folder on GitHubat commit e8d14d0

Compare with similar skills

Leaked Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Leaked Secrets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Leaked Secrets this skillthedaviddias/Front-End-Checklist74k—~596Automated safety check: NotesMIT
Check npmgrafana/skills282—~1.3kAutomated safety check: WarnApache-2.0
Secrets GitleaksAgentSecOps/SecOpsAgentKit2202 repos~4.1kAutomated safety check: PassCustom licence
Secrets DetectionHabitat-Thinking/ai-literacy-superpowers114—~2.2kAutomated safety check: NotesCustom licence
Git Gh Pat AuthNEventStore/NEventStore1.6k—~828Automated safety check: PassMIT
Git HooksProrise-cool/Claude-Code-Multi-Agent306—~3.6kAutomated safety check: NotesNone

Similar skills

  • Check npm

    grafana/skills

    Official

    Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days.

    282 GitHub stars~1.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: warnings
  • Secrets Gitleaks

    AgentSecOps/SecOpsAgentKit

    Hardcoded secret detection and prevention in git repositories and codebases using Gitleaks.

    220 GitHub starsUsed in 2 repos~4.1k tokens
    DevOps & CloudAuto-check passed
  • Secrets Detection

    Habitat-Thinking/ai-literacy-superpowers

    A skill your agent uses when auditing a project for secrets committed to source control, setting up gitleaks, or hardening the "No secrets in source" harness constraint — covers scanning…

    114 GitHub stars~2.2k tokensUpdated 20 days ago
    DevOps & CloudAuto-check: notes
  • Git Gh Pat Auth

    NEventStore/NEventStore

    A skill your agent uses when: authenticating git and GitHub CLI for NEventStore tasks, fixing gh auth errors, setting PAT environment variables, preparing a shell session for git push and gh issue…

    1.6k GitHub stars~828 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Git Hooks

    Prorise-cool/Claude-Code-Multi-Agent

    Central authority on git hook implementations, modern best practices, and tooling for .NET/C, JavaScript/TypeScript, Python, and polyglot repositories.

    306 GitHub stars~3.6k tokensUpdated 25 days ago
    DevelopmentAuto-check: notes
  • Repo Audit

    zebbern/claude-code-guide

    Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets.

    4.7k GitHub stars~831 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from thedaviddias/Front-End-Checklist

All 390 skills in this repo
  • Content Dates Audit

    thedaviddias/Front-End-Checklist

    Audits article and blog pages for visible publish dates, Article JSON-LD with datePublished and dateModified, and Open Graph time tags, then fixes what is missing.

    74k GitHub stars~691 tokensUpdated 4 days ago
    Auto-check passed
  • FAQPage Schema Markup

    thedaviddias/Front-End-Checklist

    Adds, checks and fixes FAQPage JSON-LD on pages with visible question-and-answer sections so it matches what readers see and can qualify for rich results.

    74k GitHub stars~774 tokensUpdated 4 days ago
    Auto-check passed
  • Favicon Audit and Setup

    thedaviddias/Front-End-Checklist

    Checks that a site's favicon is linked, reachable and large enough for Google search results, and sets up ICO, SVG and Apple touch icon files when they are missing.

    74k GitHub stars~731 tokensUpdated 4 days ago
    Auto-check passed
  • Content Freshness Signals

    thedaviddias/Front-End-Checklist

    Audits article pages for freshness signals, covering the Last-Modified header, Article JSON-LD dateModified and a visible last-updated date, and fixes mismatches.

    74k GitHub stars~741 tokensUpdated 4 days ago
    Auto-check passed
  • Geo Meta Tags Audit

    thedaviddias/Front-End-Checklist

    Audits and fixes geo.region, geo.placename and geo.position meta tags on regional pages, noting where they help (Bing) and where they do not (Google).

    74k GitHub stars~763 tokensUpdated 4 days ago
    Auto-check passed
  • Improve a Front-End Checklist Rule

    thedaviddias/Front-End-Checklist

    Scores and rewrites a Front-End Checklist rule MDX file against a scored quality rubric, replacing generic stub prompts with specific, actionable ones.

    74k GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check passed

Works with

Categories

Questions about Leaked Secrets

What does Leaked Secrets do?

A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens. Leaked Secrets is an agent skill from thedaviddias/Front-End-Checklist. Use when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.

When should I use Leaked Secrets?

Leaked Secrets fits situations like: reviewing client-side JavaScript; Git history for exposed credentials.

How do I install Leaked Secrets in Claude Code?

Run `npx skills add thedaviddias/Front-End-Checklist --skill leaked-secrets -a claude-code`. Or copy the skill folder (skills/leaked-secrets in thedaviddias/Front-End-Checklist) into .claude/skills/leaked-secrets in your project. Claude Code loads it when a task matches its description.

How do I install Leaked Secrets in Codex?

Run `npx skills add thedaviddias/Front-End-Checklist --skill leaked-secrets -a codex`. Or copy the skill folder (skills/leaked-secrets in thedaviddias/Front-End-Checklist) into .agents/skills/leaked-secrets in your project. Codex loads it when a task matches its description.

Can I use Leaked Secrets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add thedaviddias/Front-End-Checklist --skill leaked-secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/leaked-secrets, .gemini/skills/leaked-secrets, .github/skills/leaked-secrets and .opencode/skills/leaked-secrets in your project.

What does Leaked Secrets need to run?

Going by SKILL.md and its folder, Leaked Secrets needs the command-line tools its instructions call (git).

Does Leaked Secrets access the network?

SKILL.md names 1 domain. As links in the text: frontendchecklist.io. This is read from the text; nothing was executed.

Is Leaked Secrets safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Leaked Secrets use?

Leaked Secrets is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Leaked Secrets use?

About 596 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Leaked Secrets?

Skills that share tags, products or a category with Leaked Secrets: Check npm (grafana/skills, 282 stars), Secrets Gitleaks (AgentSecOps/SecOpsAgentKit, 220 stars), Secrets Detection (Habitat-Thinking/ai-literacy-superpowers, 114 stars) and Git Gh Pat Auth (NEventStore/NEventStore, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Leaked Secrets?

thedaviddias (a GitHub user) maintains it in thedaviddias/Front-End-Checklist, which has 74,421 GitHub stars. The repository holds 390 skills in this directory. The repository was last updated on October 6, 2026.

Source: thedaviddias/Front-End-Checklist on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.