smithery/justinlevinedotme

security-ai-keys

|- Review AI API key leakage patterns and redaction strategies. Use for identifying exposed keys for OpenAI, Anthropic, Gemini, and 10+ other providers. Use proactively when code integrates AI providers or when environment variables/keys are present. - user: "Check for leaked OpenAI keys" → scan for `sk-` patterns and client-side exposure - user: "Is my Gemini integration secure?" → audit vertex AI config and key redaction - user: "Review AI provider logging" → ensure secrets are redacted from …

Installation

$ npx skills add smithery/justinlevinedotme --skill security-ai-keys

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery/justinlevinedotme.

npx skills add smithery/justinlevinedotme

Browse all from smithery/justinlevinedotme

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Declared
Cline Not declared
OpenCode Not declared

Skill metadata

Parsed from SKILL.md frontmatter.

Declared agents gemini

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 3,200 B
  • docs SUMMARY.md 721 B

History

  1. First recorded snapshot · 0 installs

SKILL.md

<overview> Security audit patterns for AI API key leakage in applications integrating AI providers. </overview>

<rules>

Core Principles

  • AI API keys MUST be treated as secrets and kept server-side
  • Keys MUST NOT be shipped to browsers or mobile clients
  • Keys SHOULD be redacted before logging or error reporting
  • Keys MUST be rotated immediately if exposure is suspected

</rules>

<vulnerabilities>

Common Leak Paths

Client-Side Exposure

  • NEXTPUBLIC / VITE_ env vars containing AI keys
  • Direct calls to AI provider endpoints from browser code

Build Artifacts

  • Keys embedded in bundles (dist/, build/, .next/)
  • Source maps exposing server code containing keys

Logs and Telemetry

  • console.log / logger statements that include key values
  • Error tracking payloads (Sentry, Datadog) with headers included

</vulnerabilities>

<workflow>

<phase name="audit">

Quick Audit Commands

# Env files: AI keys accidentally exposed to client
rg -n "(NEXT_PUBLIC_|VITE_).*(OPENAI|OPENROUTER|ANTHROPIC|GEMINI|GOOGLE|VERTEX|BEDROCK|AWS|AZURE|MISTRAL|COHERE|GROQ|PERPLEXITY|TOGETHER|REPLICATE|FIREWORKS|HUGGINGFACE|HF_)" . -g "*.env*"

# Client code calling AI APIs directly (check for browser use)
rg -n "api\.openai\.com|openrouter\.ai|api\.anthropic\.com|generativelanguage\.googleapis\.com|aiplatform\.googleapis\.com|bedrock.*amazonaws\.com|api\.mistral\.ai|api\.cohere\.ai|api\.groq\.com|api\.together\.xyz|api\.perplexity\.ai|api\.replicate\.com|api\.fireworks\.ai|openai\.azure\.com" . -g "*.js" -g "*.ts" -g "*.jsx" -g "*.tsx" -g "*.vue"

# Scan build outputs for likely keys (heuristic)
rg -a "sk-[A-Za-z0-9]{20,}|sk-ant-[A-Za-z0-9-]{20,}|sk-or-[A-Za-z0-9-]{20,}|AIza[0-9A-Za-z_-]{35}|hf_[A-Za-z0-9]{20,}" dist/ build/ .next/ 2>/dev/null

# Service account credentials and cloud auth files
rg -n "\"type\"\s*:\s*\"service_account\"|GOOGLE_APPLICATION_CREDENTIALS|AWS_ACCESS_KEY_ID|AWS_SECRET_ACCESS_KEY|AZURE_OPENAI_API_KEY" . -g "*.env*" -g "*.json"

</phase>

</workflow>

<checklist>

Hardening Checklist

  • AI provider keys only in server runtime (never in browser)
  • .env.local and .env.*.local are gitignored
  • Logs redact or omit secrets (request headers, env values)
  • Build artifacts scanned before deploy
  • Keys rotated if exposure suspected

</checklist>

<reference>

Scripts

  • scripts/scan.sh - First-pass AI key leakage scan

</reference>