Beware of Coding Agents Leaking API Keys in Local Logs

AccomplishedLab3697 · reddit · 2026-07-14

When using coding agents like Claude Code or Cursor, all conversation logs are permanently saved locally (e.g., `~/.claude`). If users paste API keys or print environment variables, this sensitive data remains in plaintext, highly vulnerable to leaks via backups or screen sharing. To address this, a dedicated cleanup tool was introduced. It scans local histories for about 29 types of agents and matches hundreds of key patterns. The tool runs fully offline, defaults to scan-only without auto-modifying, and supports backups and undo. Users are advised to have their agent perform a security review on the tool's repository before use.

Original post →

More from coding & agent

coding & agent channel →