Developer tools · Syntax converters
Config files hold secrets: convert YAML and TOML without uploading them
· Why it matters
privacy browser-processing developer-workflow
Configuration files are where credentials live, so an online converter is exactly the wrong place to send them. This post explains the risk, how to verify a tool's network behaviour, and why in-browser conversion removes the question.
The Compose file with the database password in it — a routine conversion and a secret that leaves the machine
A Compose file may contain a database password beside ordinary service settings. Pasting it into any page expands the set of components that can observe it, but source review is required before claiming that it leaves the machine. In ToolAcre’s conversion path, parsing and serialization happen in imported browser modules with no conversion endpoint.
The safer default is still redaction. Replace live credentials, hostnames and identifiers with harmless markers before testing. A local engine reduces one data flow; it does not erase clipboard history, browser extensions, screen recording or later sharing of the downloaded output.
A pasted secret creates exposure only if the surrounding page or workflow transmits it
Configuration commonly includes connection strings, API keys, private hosts, internal addresses and fixture records. Even values that are not individually secret can disclose topology when combined. None of that context is necessary to test indentation, aliases, tables or XML attributes.
Create a minimal structural specimen that preserves types and nesting while removing operational values. Keep the original in its approved environment. This also makes worked examples reproducible: another reviewer can inspect the same shape without receiving production access data.
Where uploaded text can end up — request logs, error trackers, analytics events and third-party scripts on the converter's own page
A server-side converter could place submitted text in access logs, error reports or application telemetry. Third-party scripts on a page could create other request paths. These are possibilities to investigate, not facts to assert about every service. HTTPS protects transport but does not mean the receiver never sees the payload.
Evidence should identify the actual request. Search URLs, request bodies and form data for a distinctive harmless marker. Asset or analytics traffic alone does not prove document transmission, while a payload-bearing request proves receipt but not its retention period. Policy and runtime observation answer different questions.
Possible remote retention paths must be verified for the specific service
Open developer tools after load, clear Network, enter a unique redacted marker and run one conversion. Inspect requests created after the action. Then read the conversion source: `convert` dynamically imports local parsers and serializers and returns text to the output panel; the handler contains no fetch or XHR call.
One session can miss conditional deployment behaviour, and source can differ from a deployed bundle. Combining both supports a narrow statement about the observed action. Record browser, route and time if the result matters to an audit, and avoid using a real secret as the marker.
How ToolAcre removes the question — conversion in the browser, no account or e-mail list, no third-party script or analytics, and a strict Content Security Policy
The repository supports browser-side conversion for nine pairs. That does not justify the outline’s claims of no account, no analytics, no third-party scripts and strict CSP without separately auditing the full built page. The site documentation itself warns that eligible production pages may load disclosed Google scripts.
The defensible wording is that the converter engine reads and writes in the tab and does not call a conversion server. Page delivery, consent-managed resources, extensions and browser services remain separate surfaces. Precision is more useful than saying “nothing leaves your device,” which would be broader than the implementation files establish.
ToolAcre’s conversion engine is local; broader page claims require separate evidence
Copy a redacted Compose fragment containing `DB_PASSWORD: marker-not-a-secret-47`, anchors for shared limits and one null. Convert YAML to JSON, inspect the expanded aliases and scalar types, and search new requests for the marker. Preserve screenshots only if the sample truly contains no sensitive context.
Warnings may be as important as network evidence. A null interpreted under Core differs from the strict schema; aliases expand; comments disappear. Privacy-safe conversion can still produce semantically wrong configuration if the wrong schema is selected, so review the result before treating local execution as correctness.
What this does not cover — secrets committed to version control or shared via chat, which no converter can protect
No converter can remove a secret already committed to version control, pasted into chat or captured in an issue. Rotate exposed credentials through the owning system and remove them according to repository policy. Rewriting history or deleting a message does not automatically invalidate the value.
Downloaded converted files also contain whatever values survived. Store, share and delete them under the same controls as the source. Local processing changes where computation occurs; it does not downgrade the sensitivity of the artifact produced.
Takeaway: treat every config as sensitive — and how the Syntax converters panel handles YAML, TOML, JSON, XML and CSV without a single upload
Treat configs as sensitive, minimize input and verify data flow. ToolAcre’s browser engine is inspectable evidence for local parsing and serialization, while the Network panel checks the deployed session. Neither should be stretched into a universal claim about every browser component or future build.
Use a redacted specimen for routine work and an approved offline tool when the threat model excludes any loaded web page. The practical gain is not a slogan; it is removing an unnecessary conversion server while keeping remaining risks explicit.
Document the verification result narrowly: which marker was used, which requests were inspected and which source path performs conversion. Repeat after deployment changes that alter scripts or page composition. Evidence expires when the implementation or delivery surface changes, so a past clean network trace should not become a permanent guarantee pasted into policy without revalidation.