Lesson 19 / 25
Secrets and Private Code
Keep credentials and sensitive data out of prompts and understand data-handling policies.
Assume prompts are sent out
Most assistants send your prompt and selected code to a remote service. Never paste passwords, API keys, tokens, private keys, customer data or personal information. Check your tool's data policy: is your code used to train models, how long is it stored, and does your employer allow this tool for this project? Keep secrets in environment variables or a secrets manager, and exclude files like .env from what the tool can read.
What goes in, what comes out
Your prompts may leave your machine, and the code you accept carries legal and security consequences.
A quick secret check before pasting
I ran this regex check: it flags text that looks like an AWS access key ID and ignores ordinary text. Dedicated tools such as gitleaks are far more thorough; treat this as an illustration.
import re
pat = re.compile(r"AKIA[0-9A-Z]{16}")
print(bool(pat.search("key = 'AKIAABCDEFGHIJKLMNOP'")),
bool(pat.search("key = 'hello'")))
Output:
True False
If you pasted a secret, rotate it
Treat any secret that went into a prompt as exposed. Revoke or rotate it immediately; deleting the chat does not undo where it may have been logged.
Quick check: You pasted an API key into an assistant chat. What is the right response?
- Delete the chat and hope
- Paste it again to check
- Do nothing
- Rotate or revoke the key
Answer
Rotate or revoke the key — Once sent, you cannot be sure where it was stored, so the key must be replaced.