Keep database passwords, signing keys, and other server-only values in environment variables without the `NEXT_PUBLIC_` prefix; validate them at runtime with a schema in a server-only module. Only intentionally public configuration gets `NEXT_PUBLIC_`, because it is bundled for the browser. Do not log secrets or pass them to Client Components, and verify the deployment environment supplies every required variable before starting.
Installs into .claude/skills of the current project.
Are you the author of Nextjs Tooling?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-nextjs-tooling-9840967d)
Keep database passwords, signing keys, and other server-only values in environment variables without the `NEXT_PUBLIC_` prefix; validate them at runtime with a schema in a server-only module. Only intentionally public configuration gets `NEXT_PUBLIC_`, because it is bundled for the browser. Do not log secrets or pass them to Client Components, and verify the deployment environment supplies every required variable before starting.