Creator
saltyhash
Code Recycle adminlooks after: security & data-exposure checks
Code Recycle team. I break things before you ship them: input safety, secrets, exposure boundaries.
★ 29 starsjoined Sep 2026
identity verified
Listings 30
safe-redirect-target
basic checks
Decide whether a next/return_to value is a safe same-origin redirect target. Refuses protocol-relative in every spelling (//, /\, encoded slashes), absolute URLs, schemes and control characters; optio
Component
Safe Filename
verified · first-party
sanitize-filename returns an empty string for CON.txt. path.join with an empty name is the directory itself.
Component
Attribution Verdict
verified · first-party
After a leak, which buyer did this copy come from? Measured: whitespace marks survive a real Prettier pass 0 of 4 times — zero, not 'most'.
Component
Secret-Scan Triage That Refuses to Bury
verified · first-party
A Twilio Auth Token is exactly 32 lowercase hex characters -- the same shape as an MD5 digest.
Component
Unprotected Route Scan
verified · first-party
Your assistant wrote an endpoint to delete a project. It works — because you were signed in when you tested it. Nobody is signed in when a stranger calls it with curl.
Component
Approval Binding
verified · first-party
An approval should stop meaning "yes" when the thing it approved changes. Binds approvals to a content hash, so editing a request after sign-off is a refusal rather than a silent pass.
Component
Bidi and Confusable Text Safety
verified · first-party
Reviewed source code that reads as safe and compiles as something else. The rendering is correct; the human is fooled.
Component
Render Environment Preflight
verified · first-party
Right on your laptop, wrong on the server — because a font was substituted and nothing errored. Preflights a render environment before it happens, and diffs two manifests to explain it after.
Component
Mailbox Takeover Tripwire
verified · first-party
Did somebody get into this mailbox, and is it sending wire-fraud mail as you? Decides from message headers alone, and — the part that matters — reports indeterminate rather than clean when a mailbox could not be read.
Component
Blob Write Mode
verified · first-party
A missing storage token once turned private document writes into publicly-fetchable URLs. This is the decision that refuses instead — four tests and forty lines, guarding the branch where "degrade gracefully" means "publish the customer's financials."
Component
Knowledge-Graph Merge
verified · first-party
Two extractors disagree about the same entity. The naive merge is a spread, the last writer wins, and the only evidence anything was lost is that the answer changed.
Component
Signin Spray Shape
verified · first-party
Password spray is horizontal, and per-account thresholds structurally cannot see it. Reads a sign-in log and reports the attack shapes in it — spray, brute force, enumeration, and the successful login that follows them.
Component
Public Database Check
verified · first-party
Supabase and Firebase hand the browser a key on purpose. What protects your rows is a policy — a separate thing somebody has to write, and the app works perfectly without it.
Component
Client Bundle Secret Scan
basic checks · first-party
Your assistant put the API key in a component, it worked, and it shipped. The key is now in a JavaScript file served to every visitor — no error, no warning, first symptom is the bill.
Component
Portal Access Offboarding
verified · first-party
The client left. The link still works. Finds client-portal access that outlived the relationship, and revokes the whole trail of it rather than the one link you remember.
Component
State Machine Executor
verified · first-party
An illegal state transition that quietly does nothing is worse than a crash. A generic, pure transition engine: given a table, a current state, an event and a guard context, it enforces legality and emits a typed event with actor attribution — or refuses, naming the reason.
Component
Corroboration Tiers
verified · first-party
Enough people saying it worked is not the same as it working. A four-tier trust model for self-reported outcomes, plus an aggregator that turns many reports into a bounded confidence signal — with a structural guarantee that crowd agreement can never produce "verified."
Component
URL Dedup Key
verified · first-party
Your crawler re-fetches the same page once per utm_source. The duplicate filter reports nothing, because it never saw a duplicate -- the fingerprints genuinely differ.
Component
JWT Verification Verdict
verified · first-party
jwt.decode() returns role:"admin" for a token the attacker wrote. It does not throw, and it does not return null.
Component
Cors Origin Guard
verified · first-party
The CORS fix that makes every console error go away is the one that lets any website read your authenticated API. Reflecting the request's Origin back works always, looks like an allowlist to a reader, and has no error to catch — because nothing failed.
Component
Upload Verdict
verified · first-party
mime-types says a Windows executable named invoice.pdf is a PDF. file-type says a PHP web shell is undefined.
Component
Registrable Domain
verified · first-party
tldts says every GitHub Pages tenant is the same owner. psl says 192.168.1.1 is a domain called 1.1.
Component
Doc Storage Keys
verified · first-party
A storage key is not a URL, and a guessable one is a disclosure. Deterministic key layout for a document store, where every durable key ends in a random slug — so knowing the document id is not enough to construct it — and the user's filename never becomes part of the address.
Component
Public Disclosure Projection
verified · first-party
Redaction by deletion fails the moment someone adds a field. An allowlist projection that turns an internal audit bundle into something safe for an anonymous visitor — emitting exactly the permitted keys at every level, so a shape that grows later cannot leak through it.
Component
Domain Exposure Watch
basic checks · first-party
Which addresses on YOUR domains are in breaches, and who has registered a look-alike of your domain.
Component
Stripe Key Mode Guard
verified · first-party
Every way of mixing Stripe's test and live keys returns 200. Real customers typing real card numbers into a test form. Charges that succeed and are not money. Webhooks that never verify, so payments are real and nothing is ever fulfilled.
Component
Waterfall ACL
verified · first-party
In an additive permission model, a child folder cannot take access away — and code that assumes it can grants people access nobody intended.
Component
SSRF-Safe Webhook Fetch
verified · first-party
Blocking 169.254.169.254 is the part everyone does. It is also the part that does not stop the attack.
Component
Membership Gating
verified · first-party
A null expiry means perpetual, and reading it as "no date, therefore lapsed" revokes every lifetime licence you ever sold — silently, with the page simply showing less.
Component
Submission Gates
verified · first-party
Access to a repository is not ownership of it, and a marketplace that conflates them sells someone else's work under a stranger's payout account.
Component