Do not expose a database password to a Client Component. Keep it in a server-only module and use it from a DAL, Server Action, or Route Handler. Only variables explicitly prefixed `NEXT_PUBLIC_` are intended for the browser, and a password must never receive that prefix. Add `import 'server-only'` to the module containing the secret and pass only safe DTOs to the client.
Installs into .claude/skills of the current project.
Are you the author of Nextjs Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-nextjs-security-87810d6f)
Do not expose a database password to a Client Component. Keep it in a server-only module and use it from a DAL, Server Action, or Route Handler. Only variables explicitly prefixed `NEXT_PUBLIC_` are intended for the browser, and a password must never receive that prefix. Add `import 'server-only'` to the module containing the secret and pass only safe DTOs to the client.