Project overview
public-client-leak-audit scopes the public/private boundary, sweeps for backend paths, infrastructure details, rate-limit mechanics, secrets, and tests that reveal server behavior, then checks client-side hardening. It covers permissions, message origins, token storage, DOM sinks, origin pinning, build-time configuration, and remote code or config. The rewrite rule keeps observable client contracts while hiding how the private service works.
Repository facts
- Primary language
- Shell
- License
- MIT
- Repository updated
- Jul 5, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacy
Platforms
Claude Code, Codex, and more
Capabilities
Verification and evals
Audience
Security engineers