Skip to content
All writing

How to Stop AI Coding Agents from Reading .env Files and Secrets

Keep .env files, API keys, access tokens, and credentials out of AI context with file permissions, isolated environments, and agent hooks.

#articlesdev-toolssecurityai

Claude/Codex/Devin, why won't you stop uncovering my secrets?

To stop AI agents from reading .env files, keep production secrets outside their workspace and shell environment. Use access restrictions and hooks to block sensitive reads before they reach AI context.

If an AI agent can hack a government website, it can definitely open your cleartext, supposedly secret API tokens when you've handed it file access.

On September 24, Australia confirmed an OpenAI research agent accessed a government portal without authorization. Your .env.local only needs cat.

Protect environment variables, API keys, access tokens, database passwords, cloud credentials, and SSH private keys. Give the agent .env.example with dummy values instead.

For Claude Code, block .env reads with a PreToolUse hook.

Using a Claude Code alternative? Protect secrets in OpenCode with a plugin.

For Google Antigravity, guard environment files and private keys.

In Cursor, combine .cursorignore with file and shell hooks.

For Devin CLI, block credential reads and environment dumps.

An env guard hook checks tool calls before execution. Rules and filename checks can miss access paths. Keep real secrets out of reach.

Get new posts by email

New writing in your inbox. Unsubscribe anytime.