smithery/justinlevinedotme

security-vite

|- Review Vite security audit patterns for SPA and dev server security. Use for auditing VITE_* exposure, build-time secrets, and proxy configs. Use proactively when reviewing Vite apps (vite.config.ts present). - user: "Audit Vite env vars" → check for secrets with VITE_ prefix - user: "Check Vite build config" → verify define block and source maps - user: "Review Vite dev server" → check host binding and proxy security - user: "Scan Vite bundles" → search dist/ for leaked API keys or secrets …

Installation

$ npx skills add smithery/justinlevinedotme --skill security-vite

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery/justinlevinedotme.

npx skills add smithery/justinlevinedotme

Browse all from smithery/justinlevinedotme

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 4,878 B
  • docs SUMMARY.md 621 B

History

  1. First recorded snapshot · 0 installs

SKILL.md

<overview>

Security audit patterns for Vite applications focusing on environment variable exposure, build-time secrets, and SPA-specific vulnerabilities.

</overview>

<rules>

Environment Variable Exposure

The VITE_ Footgun

VITE_*    → Bundled into client JavaScript → Visible to everyone
No prefix → Only available in vite.config.ts → Safe for secrets

Audit steps:

  1. grep -r "VITE_" . -g ".env"
  2. Check import.meta.env.VITE_* usage in source
  3. Common mistakes:

- VITEAPISECRET (SHOULD be server-only) - VITEDATABASEURL (MUST NOT use) - VITESTRIPESECRET_KEY (only publishable keys)

Env Files Priority

Vite loads in this order (later overrides earlier):

.env                # Always loaded
.env.local          # Always loaded, gitignored
.env.[mode]         # e.g., .env.production
.env.[mode].local   # e.g., .env.production.local, gitignored

Check: Are .env.local and .env.*.local in .gitignore?

envPrefix Overrides

If envPrefix is configured, Vite exposes any variables with those prefixes. MUST treat envPrefix as a security-sensitive setting.

</rules>

<vulnerabilities>

Build-Time vs Runtime

Dangerous: Secrets in vite.config.ts

// CRITICAL: Secret in config (ends up in bundle)
export default defineConfig({
  define: {
    'process.env.API_KEY': JSON.stringify(process.env.API_KEY),
  },
});

// The above makes API_KEY available in client code!

Safe Pattern

// Only use VITE_ prefix for truly public values
export default defineConfig({
  define: {
    '__APP_VERSION__': JSON.stringify(process.env.npm_package_version),
  },
});

// Keep secrets on server (use a backend API)

Dev Server Security

Open to Network

// SHOULD NOT expose dev server to network without reason
export default defineConfig({
  server: {
    host: '0.0.0.0',  // or host: true
  },
});

This is dangerous on shared networks. MUST verify if intentional.

Proxy Misconfiguration

export default defineConfig({
  server: {
    proxy: {
      '/api': {
        target: 'http://localhost:3000',
        changeOrigin: true,
        // Missing secure options for production-like setup
      },
    },
  },
});

SPA Security Issues

Client-Side Auth Only

// "Protection" only in React Router - NOT actual security
const ProtectedRoute = ({ children }) => {
  const { user } = useAuth();
  if (!user) return <Navigate to="/login" />;
  return children;
};

// API calls still need server-side auth!
// This is UI convenience, not security.

Secrets in Bundle

# MUST check the built bundle for secrets
rg -a "(sk_live|sk_test|AKIA|api[_-]?key)" dist/

Source Maps in Production

// Check vite.config.ts
export default defineConfig({
  build: {
    sourcemap: true,  // SHOULD NOT expose source code in production
  },
});

</vulnerabilities>

<guidelines>

Common Vulnerabilities

Issue Where to Look Severity
VITE_* secrets .env*, source files CRITICAL
Secrets in define vite.config.ts CRITICAL
Source maps in prod vite.config.ts MEDIUM
Dev server exposed vite.config.ts server.host MEDIUM
Client-only auth Route guards without API auth HIGH
API keys in bundle dist/ directory CRITICAL

</guidelines>

<commands>

Quick Audit Commands

# Find VITE_ secrets
grep -r "VITE_" . -g "*.env*"

# Find import.meta.env usage
rg 'import\.meta\.env' . -g "*.ts" -g "*.tsx" -g "*.vue"

# Check define in config
rg 'define:' vite.config.*

# Scan built bundle for secrets
rg -a "(sk_live|AKIA|ghp_|api[_-]?key['\"]?\s*[:=])" dist/

# Check for source maps
fd '\.map$' dist/

</commands>

<constraints>

Hardening Checklist

  • No secrets in VITE_* variables
  • .env.local and .env.*.local in .gitignore
  • sourcemap: false in production build
  • server.host is not 0.0.0.0 or true (unless intentional)
  • All sensitive API calls go through a backend (not direct from browser)
  • No secrets in vite.config.ts define block

</constraints>