Client-Side .env Sanitizer & Secret Leak Checker
AI editors frequently prepend NEXT_PUBLIC_ to private keys just to silence client undefined errors. Audit your environment variables client-side and generate a clean .env.example with dummy placeholders.
.env or .env.local11 variables detectedThe NEXT_PUBLIC_ Trap
When you ask an AI assistant to fetch user data or create a checkout session from a client component, it encounters a build error saying process.env.STRIPE_SECRET_KEY is undefined. Its quickest solution? Prefix it with NEXT_PUBLIC_.
Next.js then bakes that live key directly into the compiled JavaScript bundle. Anyone who opens Chrome DevTools can read your secret key in plain text.
3 Critical Leaks & 1 Warnings
Immediate fixes required before committing or pushing code.
# Project environment variables (vibe coded app)
NODE_ENV=your_node_env_here
PORT=your_port_here
# Next.js Public Keys
NEXT_PUBLIC_APP_URL=your_app_url_here
NEXT_PUBLIC_SUPABASE_URL=your_supabase_url_here
NEXT_PUBLIC_SUPABASE_ANON_KEY=your_supabase_anon_key_here
# CRITICAL BUG: AI added NEXT_PUBLIC_ to private secrets so client code could read them!
NEXT_PUBLIC_STRIPE_SECRET_KEY=sk_live_...
NEXT_PUBLIC_SUPABASE_SERVICE_ROLE_KEY=your_supabase_service_role_key
# Database connection string with raw password
DATABASE_URL=postgresql://user:password@localhost:5432/dbname
# AI Provider API Keys
OPENAI_API_KEY=sk-proj-...
ANTHROPIC_API_KEY=sk-ant-...
# Stripe Webhook Secret
STRIPE_WEBHOOK_SECRET=your_stripe_webhook_secret_here
Even if you delete a key from your current file, it still lives in your Git history. Attackers scan commit histories with bots. The Founder Pass ($15 one-time) scans your entire repository history and code files for lingering secrets.