Lesson 12 / 25

Keeping Secrets Out of Reach

Remove secrets from the agent's environment, files and logs.

If it cannot see it, it cannot leak it

An agent's shell inherits your environment variables, which often hold cloud keys and tokens. Start it with a clean environment containing only what the task needs. Deny reading .env*, key files and credential folders. For tasks that truly need a credential, use a scoped, short-lived one for a test environment, never your personal admin keys. Anything the agent reads may end up in a model request or a log.

Nothing to steal, nowhere to send

Keep secrets out of reach and restrict where data can go, so a leak needs two failures, not one.

Three controls: hide, redact, restrict.
Figure 4.1 — Hide, redact and restrict.

Start with a clean environment

env -i starts a process with an empty environment; then pass only chosen variables. Adjust the list for your tools.

env -i HOME="$PWD/.agent-home" PATH="/usr/local/bin:/usr/bin:/bin" \
    NODE_ENV=test \
    my-agent --project .

# compare: your normal shell may expose AWS_*, GITHUB_TOKEN, OPENAI_API_KEY ...
env | grep -E 'KEY|TOKEN|SECRET' | cut -d= -f1

Use a separate low-privilege identity

If the agent needs Git or cloud access, give it its own account or token with the minimum rights, so its actions are attributable and revocable without touching your own access.

Quick check: What is a good way to limit the secrets an agent shell can see?

  • Copy all your variables into it
  • Start it with a clean environment
  • Share your admin keys
  • Print the environment in chat
Answer

Start it with a clean environment — An empty starting environment means inherited tokens cannot be read or leaked.