I vibecoded a secrets proxy to keep credentials out of cloud coding agents
andersonbcdefg · x · 2026-10-11
Developer Benjamin Anderson details his homebrewed secrets proxy for cloud coding agents:
- Context: open-weights models are too good to ignore; he previously built a 'guardian' between GLM and his CLI to prevent data exfiltration or destructive commands. But workloads are moving to the cloud, making secrets management the next paranoia.
- The problem: agents need secrets to work, but once a secret enters the context window it goes to a provider you may not trust — and agents risk leaking it publicly ('LOOT' files).
- Architectures: he contrasts agent-in-the-sandbox vs sandbox-as-a-tool, arguing the debate is settled until harnesses support truly remote bash execution.
- Solution: a self-built secrets proxy acting as a middle layer between agents and real credentials, keeping secrets out of agent context. The whole proxy was generated by Claude as 6,000 lines of Go in one shot.
Related event: Dev Gets Claude to Write 6,000 Lines of Bug-Free Go for Secrets Proxy(2 posts)→
More from coding & agent
- Karpathy Distills 8 Years at OpenAI and Tesla Into Free 2-Hour Lecture — NandoDF · 2026-10-11
- Dev Says Opus 5.5 Makes Vibe Coding Finally Keep Pace With His Imagination — mrjonfinger · 2026-10-11
- Jeremy Howard: AI coding is a slot machine with 'losses disguised as wins' — Machine Learning Street Talk · 2026-10-11
- Agent evals: valid permission and approval can't catch stale facts before execution — jylusdev · 2026-10-11
- Reddit debate: AI agents are bringing back the Silo Engineer, only faster and more reckless — erwinalp5 · 2026-10-11
- "Micro Managers Anonymous": a free seven-step programme for your agentic software factory — intellectronica · 2026-10-11