public-client-leak-audit
Checks public clients for leaked backend details, secrets, and abuse-enabling disclosures.
Checks public clients for leaked backend details, secrets, and abuse-enabling disclosures.
public-client-leak-audit scopes the public/private boundary, sweeps for backend paths, infrastructure details, rate-limit mechanics, secrets, and tests that reveal server behavior, then checks client-side hardening. It covers permissions, message origins, token storage, DOM sinks, origin pinning, build-time configuration, and remote code or config. The rewrite rule keeps observable client contracts while hiding how the private service works.
Resource types
Use cases
Platforms
Capabilities
Audit suspension risks in a Claude Code working environment.
Check whether a specific CVE actually applies to your environment.
Audience
Public GitHub facts last synced Jul 10, 2026.
Store and inject development secrets through 1Password from Claude Code.
Audit a deployed public app for production gaps missed during coding.