Keep secrets out of agent workspaces: proxy-swapped tokens for safe AI coding
lucasmeijer · x · 2026-10-09
Developer Lucas Meijer shares his security setup for running AI agents: never co-locate agents with family photos, credit cards, or email. The core trick is that secrets never enter the workspace—a proxy swaps in the real GitHub token, API key, or SSH key on the way out, so the agent itself never holds credentials.
In a follow-up he adds that he now does at least half of his coding from his phone with this setup.
Related event: Developer Shares AI Agent Security Practices and Custom Workbench(3 posts)→
More from coding & agent
- LangChain Podcast Digs Into Decision Models as OpenAI and Databricks Enter the Space — LangChain · 2026-10-09
- Persistent Self-Improvement: Why Having Memory Isn't the Same as Learning — anirudhg9119 · 2026-10-09
- Ruff Author Confirms His Tools Are Tested Almost Entirely via Black-Box Suites — charliermarsh · 2026-10-09
- Leak hints OpenAI runs multi-agent swarms on time budgets, not token budgets, and treats it as IP — maksym_andr · 2026-10-09
- Multi Codex App Lets You Run Up to 100 Parallel Codex Instances With Separate Accounts — daniel_mac8 · 2026-10-09
- Open-source agent skill turns PRs into zoomable code maps, with git-verified snippets to block hallucinations — SeanOliver · 2026-10-09