Keep secrets out of agent workspaces: proxy-swapped tokens for safe AI coding

lucasmeijer · x · 2026-10-09

Developer Lucas Meijer shares his security setup for running AI agents: never co-locate agents with family photos, credit cards, or email. The core trick is that secrets never enter the workspace—a proxy swaps in the real GitHub token, API key, or SSH key on the way out, so the agent itself never holds credentials.

In a follow-up he adds that he now does at least half of his coding from his phone with this setup.

Related event: Developer Shares AI Agent Security Practices and Custom Workbench(3 posts)→

Original post →

More from coding & agent

coding & agent channel →