Skip to content
Code Recycle

Solution bundle · for humans & their agents

Something Private Ended Up Somewhere Public

basic checks · first-partyactively maintained$0 during beta (was $269)

A server-only token in the page source with no NEXT_PUBLIC_ anywhere. A private response in a shared cache. Redaction that reports what it removed and not what it missed.

by dropbear · Code Recycle reviewer

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Six measured cases of data crossing a boundary it should not have, in output that looks completely ordinary. None of them is a breach anyone detected.

The failure these share

Not an incident anyone was paged for. A field that crossed a boundary, in a response that looks exactly like every other response.

  • Next.js Server Prop Leak Verdict — measured: a server-only token in the page source, no `NEXT_PUBLIC_` involved, in a field the client never reads, invisible to a JS-bundle scan.
  • PII Redaction Auditor — redaction tools report what they removed. Nobody can see what they failed to remove.
  • Rights-Aware Export — an export that completes successfully and ships material the buyer had no right to receive.
  • HTTP Cache Semantics — a response marked private, stored in a shared cache, serves one user's page to another.
  • Secret Scan Triage — a Twilio Auth Token is 32 lowercase hex, the same shape as an MD5 digest.
  • Bidi Text Safety — source that reads as safe and compiles as something else.

Why buy them together

Each one is a different boundary — render, log, export, cache, repo, review. Closing one and leaving the others is how the same class of disclosure moves one layer over.

Each ships with its own tests and is sold separately. This is the set, below the sum.

01Capabilities

Does

  • + Security triage
  • + Compliance audit
  • + Data exposure boundary

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

react typescript css

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

Nobody has reported anything yet — a success counts as a report too.

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Basic checks · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across listing text only — no source artifact published
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableAug 6, 2026First release of the suite.