# Redacting Secrets — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/en/coding-agent-guardrails/sec-redaction

> Scrub secret-looking text from tool output and logs as a last line of defence.

## A safety net, not a wall

A **redaction filter** scans text on its way into logs, prompts or chat and replaces known secret formats (cloud key IDs, GitHub tokens, `password=...`) with a placeholder. It catches accidents but cannot recognise every secret, and it can over-match harmless text. Use it **in addition to** keeping secrets away, never instead.

## A redactor, run

I ran this. The key and the password are replaced and ordinary text is untouched. Note that the broad `password=...` pattern also swallows whatever follows it on the same token.

```python
import re
PATTERNS = [re.compile(r"AKIA[0-9A-Z]{16}"),
            re.compile(r"ghp_[A-Za-z0-9]{36}"),
            re.compile(r"(?i)(password|secret|token)\s*[=:]\s*\S+")]

def redact(text):
    for p in PATTERNS:
        text = p.sub("[REDACTED]", text)
    return text

print(redact("aws=AKIAABCDEFGHIJKLMNOP password=hunter2 note=ok"))
```

Output:

```
aws=[REDACTED] [REDACTED] note=ok
```

## Rotate anything that leaked

Redaction cannot un-send a secret that already reached a model provider or a log. If a real credential appears in output, treat it as exposed and rotate it.

**Quiz:** What is the right role of a redaction filter?

- [ ] A replacement for access control
- [x] A last-line safety net in addition to keeping secrets away
- [ ] A way to share secrets safely
- [ ] A guarantee that nothing leaks

*Answer:* A last-line safety net in addition to keeping secrets away. It catches mistakes but is imperfect, so prevention comes first.
