highexposed-ai-credential-config

Exposed AI tooling config that can contain credentials

This {tool} file is publicly readable. Files of this kind hold model-provider API keys, MCP server credentials, and workspace environment variables, so exposing it can hand an attacker working keys to your paid AI accounts and connected services — and it also maps your internal tooling for them. Treat any credential it

Why it matters

This {tool} file is publicly readable. Files of this kind hold model-provider API keys, MCP server credentials, and workspace environment variables, so exposing it can hand an attacker working keys to your paid AI accounts and connected services — and it also maps your internal tooling for them. Treat any credential it contains as compromised.

How ShipReady detects it

AI-specific exposure — the product's differentiating module. Covers two distinct failure modes of AI-built applications: 1. Tooling artifacts deployed by accident. AI coding tools generate config and instruction files at the repo root; developers who push a whole repo (rather than just its build output) to static hosting serve them publicly. Some are merely instructions; others hold live API keys. 2. Secrets promoted into the client bundle via a PUBLIC env var prefix. This is the single most characteristic AI-app mistake: AI assistants correctly explain that a variable must be prefixed (NEXT_PUBLIC_, VITE_, ...) to be readable in the browser, and developers apply that prefix to a *server* secret. The bundler then inlines the real value into JavaScript that anyone can read. Both are confirmed by observation, never inferred from framework fingerprints alone.

Detection is deterministic. ShipReady reports this only when it observes the condition directly, and prefers to miss a real problem over inventing one. Rule version 1.3.0.

How to fix it

This is the prompt ShipReady puts in your report — written to be pasted straight into Cursor, Claude Code, or whichever assistant built the app.

An AI tooling config file that can hold credentials (MCP server definitions, model-provider API keys, or workspace environment variables) is publicly served. Rotate every key referenced in that file, then stop deploying it: add it to your ignore/exclude list, deploy only build output rather than the whole repository, and block requests to dotfile paths at your host or CDN.

Frequently asked questions

What does "Exposed AI tooling config that can contain credentials" mean?
This {tool} file is publicly readable. Files of this kind hold model-provider API keys, MCP server credentials, and workspace environment variables, so exposing it can hand an attacker working keys to your paid AI accounts and connected services — and it also maps your internal tooling for them. Treat any credential it
How serious is it?
ShipReady rates this high. Fix before launch. A real weakness that an attacker can act on.
How do I fix it?
Paste the fix prompt on this page into Cursor, Claude Code or your AI editor. It is the same prompt ShipReady puts in your report.
Can I check my own site?
Yes — ShipReady scans up to ten pages of any public site for free and reports this alongside every other check.

Related checks

Does your site have this?

ShipReady checks this and 73 other things across up to ten pages of your site. Free, no signup.

Scan my site