Three quiet leaks in agent work, and one fix for each
Most agent trouble isn't dramatic. It's three small leaks that sit there until one turns into a leaked key or a surprise bill. 1. Prompts that only live in a vendor dashboard If a prompt only exists in a dash
Most agent trouble isn't dramatic. It's three small leaks that sit there until one turns into a leaked key or a surprise bill.
1. Prompts that only live in a vendor dashboard
If a prompt only exists in a dashboard, you can't diff it, review it, or roll it back.
- Put prompts in a
prompts/folder in git and review changes like code. - Never put secrets in prompt files.
- Run a secret scan on every commit (gitleaks, detect-secrets, or git-secrets with pre-commit).
2. Agent runs with no ceiling
A run with no token or dollar cap can loop all night.
- Give every session or run a hard total-token (or dollar) ceiling.
- When it hits the ceiling, stop. Don't soft-retry.
- Your own run budget is not the same thing as a model's per-response output limit. Set both.
3. Keys passed around by copy-paste
A clipboard isn't a vault. A key pasted into a chat is a key that leaked.
- Keep keys in a secret manager or env vars.
- Rotate anything that's ever been pasted into a chat or ticket.
Copy/paste
[ ] Prompts in git, reviewed, secret scan on commit
[ ] Every agent run has a hard token or cost ceiling that stops it
[ ] No keys in chats, tickets, or prompt files; pasted keys rotated
This is the short version of Pocket Lint, a free keep-forever checklist pack from Weekstart with templates and a 9-item checklist. It's free for subscribers today. Sign up free to get the next drop: https://stackyard.fyi/store
Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.