How do you deal with secrets when an agent writes your configuration files?

by•

It was last week when I saw an agent create an operational Stripe API integration within four minutes. I spotted the presence of the testing secret embedded into a file destined for being committed to the open repository, thanks to my luck, as I was looking at the diff.

The model did not do anything foolish; on the contrary, it took the most straightforward path to writing functioning code.

Since then, I have introduced three policies, including using a .env.example file which the agent needs to replicate, scanning the commits before they occur via gitleaks, and a policy for prompts, telling the tool that there can be no secrets in the code.

My guess would be that this is just one of the possible measures which should be introduced. So for those who create real applications with agents, how is your workflow?

6 views

Add a comment

Replies

Be the first to reply

Have a question or a thought to share? Add a comment above to start the conversation.