Claude/Codex/Devin, why won't you stop uncovering my secrets?
To stop AI agents from reading .env files, keep production secrets outside their workspace and shell environment. Use access restrictions and hooks to block sensitive reads before they reach AI context.
If an AI agent can hack a government website, it can definitely open your cleartext, supposedly secret API tokens when you've handed it file access.
On September 24, Australia confirmed an OpenAI research agent accessed a government portal without authorization. Your .env.local only needs cat.
Protect environment variables, API keys, access tokens, database passwords, cloud credentials, and SSH private keys. Give the agent .env.example with dummy values instead.
For Claude Code, block .env reads with a PreToolUse hook.
Using a Claude Code alternative? Protect secrets in OpenCode with a plugin.
For Google Antigravity, guard environment files and private keys.
In Cursor, combine .cursorignore with file and shell hooks.
For Devin CLI, block credential reads and environment dumps.
An env guard hook checks tool calls before execution. Rules and filename checks can miss access paths. Keep real secrets out of reach.