
Audit Env Variables
Audit JavaScript/TypeScript environment variables and safely remove unused configs
4.7(51 reviews)1,000+ downloadsUpdated Sep 2026Verified SafeSecurity VerifiedThis skill was analyzed by our AI security scanner for harmful content including data exfiltration, system manipulation, credential theft, and prompt injection. No threats were detected.
What You Can Do
You can perform a complete audit of your project's environment variables to discover unused configurations, identify which services are integrated (Stripe, AWS, Supabase, etc.), and understand permission scopes. The skill maps exactly where each variable is used in your codebase, then optionally removes unused variables with automatic regression detection to prevent breaking changes.
Features
Discovers all .env files and detects environment variable patterns across the codebase
Identifies unused variables and cross-references declared vs. used configurations
Recognizes specific service integrations (Stripe, AWS, Supabase) and infers permission implications
Maps code paths to show exactly where each environment variable is referenced
Generates structured markdown audit reports with categorized findings
Safely removes unused variables with user confirmation and automatic backups
Validates cleanups by running builds/tests and auto-rolls back if regressions detected
Detects dynamic access patterns that might hide variable usage
Example Output
Example 1: Audit Report
code
# Environment Variables Audit
## Summary
- Total Variables: 12
- Used: 9
- Unused: 3
- Services Detected: 2
## Services Detected
### Stripe (Production)
- STRIPE_SECRET_KEY (used in /src/payments/checkout.ts)
- STRIPE_PUBLISHABLE_KEY (used in /src/client/stripe.ts)
- Permissions: Payment processing, customer data access
## Unused Variables
- DEPRECATED_API_URL (last referenced in deleted file)
- TEST_WEBHOOK_SECRET (no references found)
- OLD_DB_HOST (superseded by DATABASE_URL)
Example 2: Cleanup Output
code
✓ Backup created: .env.backup.1703001234
✓ Removed 3 unused variables
✓ Build validation: PASSED
✓ Test suite: PASSED (98 tests)
✓ No regressions detected
What's Included
- audit-env-variables SKILL.md: Complete instruction file with discovery, analysis, and cleanup logic
- Audit Report Template: Structured markdown template with sections for summary, services detected, usage mapping, and recommendations
- Service Detection Database: Pre-configured patterns for Stripe, AWS, Supabase, Firebase, and other common services
- Cleanup Checklist: Step-by-step validation workflow for safe variable removal with rollback procedures
- Regression Test Framework: Build and test validation scripts to catch breaking changes
Who It's For
- Backend engineers auditing project configuration and security
- DevOps engineers managing environment variable sprawl across services
- Tech leads reviewing onboarding and reducing configuration complexity
- Security teams identifying unused service integrations and permission scope risks
- Full-stack developers migrating between services and cleaning up legacy configs
Best For
- Auditing environment variable usage before refactoring or service migrations
- Identifying and removing unused API keys and credentials
- Documenting which services are integrated and their permission levels
- Cleaning up legacy configurations with safe rollback protection
- Onboarding new developers by mapping all active environment variables
You might also like
$40.00







