Skip to content
All writing

Snippet: Env Guard Hook for Devin

A Devin playbook hook to prevent the agent from reading secret environment files.

#snippetsdev-toolssecurityai

When running Devin on a remote workspace or local machine, you want to ensure it doesn't scrape environment variables into its memory (which could be visible in the session transcript).

You can enforce this by providing an initialization playbook or placing a custom hook script in ~/.config/devin/hooks/guard-env.sh.

#!/usr/bin/env bash
# Devin PreToolUse Hook (Read/Bash/Grep): 
# Blocks tool calls touching secret/credential files or dumping the environment.

PAYLOAD=$(cat)

block() {
  # Devin's hook contract: Exit non-zero to fail the action and print the reason.
  echo "SECURITY: Blocked $1. Read .env.example or a schema file (env.ts/env.mjs) instead." >&2
  exit 1
}

# Secret paths and env dumps
DENIED='\.dev\.vars|\.pem\b|\.p12\b|\.pfx\b|\.ppk\b|\.p8\b|\bid_rsa\b|\bid_dsa\b|\bid_ed25519\b|\bid_ecdsa\b|\.ssh/|\.gnupg/|\.aws/|\.kube/config|\.docker/config|\.config/gh/|\.htpasswd\b|\.tfstate\b|\.[a-z0-9]+_history\b|(~|'"$HOME"')/\.(netrc|npmrc|pypirc|yarnrc|git-credentials|pgpass|my\.cnf|cargo/credentials|config/git/credentials|codex/config\.toml)|/proc/[^[:space:]]*/environ|\bprintenv\b|(^|[[:space:];&|"])env[[:space:]]*($|\|)'
printf '%s' "$PAYLOAD" | grep -Eiq "$DENIED" && block "a secret file or env dump"

KEYFILE='["'"'"'][A-Za-z0-9._~/-]*(\.key|credentials\.(json|ya?ml|toml)|secrets\.(json|ya?ml|toml))["'"'"']|(/|\./|~/)[^[:space:]"'"'"'{}()$]*(\.key|credentials\.(json|ya?ml|toml)|secrets\.(json|ya?ml|toml))\b'
printf '%s' "$PAYLOAD" | grep -Eiq "$KEYFILE" && block "a key/credential file"

while IFS= read -r tok; do
  case "${tok##*/}" in
    .env.example|.env.template|.env.sample|.env.defaults|env.ts|env.mjs|env.d.ts) ;;
    .env|.env.*|.envrc) block "a .env file" ;;
  esac
done < <(printf '%s' "$PAYLOAD" | grep -Eio '[^[:space:]"'"'"';|&<>()]*\.env[A-Za-z0-9._-]*')

exit 0

Get new posts by email

New writing in your inbox. Unsubscribe anytime.