Put secrets and database logic in modules marked `import 'server-only'`, and keep those modules out of Client Component import graphs. Pass only minimal, serializable DTOs to client leaves; never pass raw database objects, tokens, or secret environment values. Use Server Actions or Route Handlers as explicit bridges for client-triggered operations and keep secret environment variables unprefixed by `NEXT_PUBLIC_`.
Installs into .claude/skills of the current project.
Are you the author of Nextjs Server Components?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-nextjs-server-components-f4af51fc)
Put secrets and database logic in modules marked `import 'server-only'`, and keep those modules out of Client Component import graphs. Pass only minimal, serializable DTOs to client leaves; never pass raw database objects, tokens, or secret environment values. Use Server Actions or Route Handlers as explicit bridges for client-triggered operations and keep secret environment variables unprefixed by `NEXT_PUBLIC_`.