DEV Community

stackyard.weekstart
stackyard.weekstart

Posted on

Three quiet leaks in agent work, and one fix for each

Most agent trouble isn't dramatic. It's three small leaks that sit there until one turns into a leaked key or a surprise bill.

1. Prompts that only live in a vendor dashboard

If a prompt only exists in a dashboard, you can't diff it, review it, or roll it back.

  • Put prompts in a prompts/ folder in git and review changes like code.
  • Never put secrets in prompt files.
  • Run a secret scan on every commit (gitleaks, detect-secrets, or git-secrets with pre-commit).

2. Agent runs with no ceiling

A run with no token or dollar cap can loop all night.

  • Give every session or run a hard total-token (or dollar) ceiling.
  • When it hits the ceiling, stop. Don't soft-retry.
  • Your own run budget is not the same thing as a model's per-response output limit. Set both.

3. Keys passed around by copy-paste

A clipboard isn't a vault. A key pasted into a chat is a key that leaked.

  • Keep keys in a secret manager or env vars.
  • Rotate anything that's ever been pasted into a chat or ticket.

Copy/paste

[ ] Prompts in git, reviewed, secret scan on commit
[ ] Every agent run has a hard token or cost ceiling that stops it
[ ] No keys in chats, tickets, or prompt files; pasted keys rotated
Enter fullscreen mode Exit fullscreen mode

This is the short version of Pocket Lint, a free keep-forever checklist pack from Weekstart with templates and a 9-item checklist. It's free for subscribers today. Sign up free to get the next drop: https://stackyard.fyi/store

Top comments (0)