# Secrets and Private Code — AI Coding Assistants: Use Them Well and Review Them Hard

Source: https://www.geekswithgeeks.com/en/ai-coding-assistants/safe-secrets-privacy

> Keep credentials and sensitive data out of prompts and understand data-handling policies.

## Assume prompts are sent out

Most assistants send your prompt and selected code to a remote service. Never paste **passwords, API keys, tokens, private keys, customer data or personal information**. Check your tool's data policy: is your code used to train models, how long is it stored, and does your employer allow this tool for this project? Keep secrets in environment variables or a secrets manager, and exclude files like `.env` from what the tool can read.

## What goes in, what comes out

Your prompts may leave your machine, and the code you accept carries legal and security consequences.

![Three checkpoints: input, output, environment.](assets/figures/ai-coding-assistants/section-6-map.svg) — Figure 6.1 — Input, output and environment.

## A quick secret check before pasting

I ran this regex check: it flags text that looks like an AWS access key ID and ignores ordinary text. Dedicated tools such as gitleaks are far more thorough; treat this as an illustration.

```python
import re
pat = re.compile(r"AKIA[0-9A-Z]{16}")
print(bool(pat.search("key = 'AKIAABCDEFGHIJKLMNOP'")),
      bool(pat.search("key = 'hello'")))
```

Output:

```
True False
```

## If you pasted a secret, rotate it

Treat any secret that went into a prompt as exposed. Revoke or rotate it immediately; deleting the chat does not undo where it may have been logged.

**Quiz:** You pasted an API key into an assistant chat. What is the right response?

- [ ] Delete the chat and hope
- [ ] Paste it again to check
- [ ] Do nothing
- [x] Rotate or revoke the key

*Answer:* Rotate or revoke the key. Once sent, you cannot be sure where it was stored, so the key must be replaced.
