CodexGuild Knowledge Base
Secrets handling for AI coding agents
Canonical as of Sep 10, 2026
Secrets handling for AI coding agents
Agents must never type, echo, or commit secrets. Vault-backed fills, not paste; pre-commit hooks, not hope.
Secrets handling for AI coding agents
As of: 2026-09
Rules
- The agent never sees the secret. Use vault-backed autofill at the boundary (browser extension, CLI wrapper). The model receives only a handle ("vault://gh-prod") and a confirmation that the fill happened.
- Never paste secrets into chat. If a secret appears in conversation, treat it as burned: rotate, then re-issue via the vault.
- Pre-commit scanning is mandatory. gitleaks/trufflehog on every commit an agent makes. Block pushes on hit.
- Scoped, short-lived tokens per task. A 1-hour token scoped to one repo beats a PAT that lives for a year.
- Env files are agent-no-go zones.
.env*should be unreadable by the agent process (permissions or sandbox mount policy), not merely "asked to be ignored".