mediumexposed-ai-config-file

Exposed AI Tooling Config File

This {tool} file is publicly readable. It reveals your internal architecture notes, coding conventions, and the prompts guiding development — useful reconnaissance for anyone targeting the app — and its presence means your deployment is serving repository files rather than just build output, so other private files may

Why it matters

This {tool} file is publicly readable. It reveals your internal architecture notes, coding conventions, and the prompts guiding development — useful reconnaissance for anyone targeting the app — and its presence means your deployment is serving repository files rather than just build output, so other private files may be reachable too.

How ShipReady detects it

AI-specific exposure — the product's differentiating module. Covers two distinct failure modes of AI-built applications: 1. Tooling artifacts deployed by accident. AI coding tools generate config and instruction files at the repo root; developers who push a whole repo (rather than just its build output) to static hosting serve them publicly. Some are merely instructions; others hold live API keys. 2. Secrets promoted into the client bundle via a PUBLIC env var prefix. This is the single most characteristic AI-app mistake: AI assistants correctly explain that a variable must be prefixed (NEXT_PUBLIC_, VITE_, ...) to be readable in the browser, and developers apply that prefix to a *server* secret. The bundler then inlines the real value into JavaScript that anyone can read. Both are confirmed by observation, never inferred from framework fingerprints alone.

Detection is deterministic. ShipReady reports this only when it observes the condition directly, and prefers to miss a real problem over inventing one. Rule version 1.3.0.

How to fix it

This is the prompt ShipReady puts in your report — written to be pasted straight into Cursor, Claude Code, or whichever assistant built the app.

An AI coding-tool config or instruction file is publicly accessible. It can leak internal architecture notes and prompts and reveals which tool built the site. Remove these files from what you deploy — serve only your build output, not the whole repository.

Frequently asked questions

What does "Exposed AI Tooling Config File" mean?
This {tool} file is publicly readable. It reveals your internal architecture notes, coding conventions, and the prompts guiding development — useful reconnaissance for anyone targeting the app — and its presence means your deployment is serving repository files rather than just build output, so other private files may
How serious is it?
ShipReady rates this medium. Fix soon. Meaningfully weakens a defence or degrades how the site works.
How do I fix it?
Paste the fix prompt on this page into Cursor, Claude Code or your AI editor. It is the same prompt ShipReady puts in your report.
Can I check my own site?
Yes — ShipReady scans up to ten pages of any public site for free and reports this alongside every other check.

Related checks

Does your site have this?

ShipReady checks this and 73 other things across up to ten pages of your site. Free, no signup.

Scan my site