TechnicalCollectible prompt

Find leaked API keys and rotate them safely

Find every secret that reached the browser, the repo or the logs, then rotate each in the right order.

Claude CodeCursorCodex

Curated by Nvoka

Nvoka wordmark logo
Nvoka wordmark logoTechnical

Find leaked API keys and rotate them safely

Act as a senior security engineer. Audit secrets and environment variables in my {{tech_stack}} project. Services we hold keys for: {{integrations}}. Never print a secret value in your answer; refer to each by name and its last 4 characters. 1. Inventory: every environment variable, where it's defined (env files, host dashboard, CI) and where code reads it 2. Browser exposure: anything with a public prefix such as VITE_, NEXT_PUBLIC_, PUBLIC_ or REACT_APP_ ends up in the bundle. Build for production and search the output JavaScript and source maps for key patterns. Also look for keys hard-coded in components 3. Classify each: safe in the browser by design (a Supabase anon or publishable key behind row-level security, a Stripe publishable key, a Turnstile site key) or server-only (service role keys, Stripe secret and webhook secrets, AI provider keys, database URLs, email API keys) 4. Git history: scan every commit with a tool like gitleaks or trufflehog. A key deleted in a later commit is still leaked 5. Other leaks: public production source maps, error messages, logs, analytics events, and browser code calling an AI or email API directly Fix, in this order: - Rotate every exposed server secret first, update the host and redeploy. Rewriting git history comes after, and only if I agree - Move server-only calls behind a server function or API route that checks the user and rate limits - Add an env example file with names only, a gitignore check, a pre-commit secret scan and a CI scan - Validate required variables at startup, so a missing one fails loudly Never fix a leak by renaming the variable or obfuscating the value. Return a table: secret name, where it leaked, risk, action, and done or waiting on me. Then list exactly which dashboards I need to open to rotate keys.
Technicalnvoka.com/library/nvoka-secrets-and-environment-variable-auditScan to open
Technical

Find leaked API keys and rotate them safely

Find every secret that reached the browser, the repo or the logs, then rotate each in the right order.

Nvoka logo

Curated by Nvoka

Claude CodeCursorCodexGitHub Copilot
Add to my library

Make it yours

Fill in the blanks and change any word. Only your copy changes, never the card.

Fill in the blanks

0 of 2 filled

Your prompt

Act as a senior security engineer. Audit secrets and environment variables in my {{tech_stack}} project. Services we hold keys for: {{integrations}}. Never print a secret value in your answer; refer to each by name and its last 4 characters. 1. Inventory: every environment variable, where it's defined (env files, host dashboard, CI) and where code reads it 2. Browser exposure: anything with a public prefix such as VITE_, NEXT_PUBLIC_, PUBLIC_ or REACT_APP_ ends up in the bundle. Build for production and search the output JavaScript and source maps for key patterns. Also look for keys hard-coded in components 3. Classify each: safe in the browser by design (a Supabase anon or publishable key behind row-level security, a Stripe publishable key, a Turnstile site key) or server-only (service role keys, Stripe secret and webhook secrets, AI provider keys, database URLs, email API keys) 4. Git history: scan every commit with a tool like gitleaks or trufflehog. A key deleted in a later commit is still leaked 5. Other leaks: public production source maps, error messages, logs, analytics events, and browser code calling an AI or email API directly Fix, in this order: - Rotate every exposed server secret first, update the host and redeploy. Rewriting git history comes after, and only if I agree - Move server-only calls behind a server function or API route that checks the user and rate limits - Add an env example file with names only, a gitignore check, a pre-commit secret scan and a CI scan - Validate required variables at startup, so a missing one fails loudly Never fix a leak by renaming the variable or obfuscating the value. Return a table: secret name, where it leaked, risk, action, and done or waiting on me. Then list exactly which dashboards I need to open to rotate keys.
See all