Dev.to AI πŸ€– Ai πŸ‘ 0 πŸ“– 1 min read

Three quiet leaks in agent work, and one fix for each

Most agent trouble isn't dramatic. It's three small leaks that sit there until one turns into a leaked key or a surprise bill. 1. Prompts that only live in a vendor dashboard If a prompt only exists in a dash

Most agent trouble isn't dramatic. It's three small leaks that sit there until one turns into a leaked key or a surprise bill.

1. Prompts that only live in a vendor dashboard

If a prompt only exists in a dashboard, you can't diff it, review it, or roll it back.

  • Put prompts in a prompts/ folder in git and review changes like code.
  • Never put secrets in prompt files.
  • Run a secret scan on every commit (gitleaks, detect-secrets, or git-secrets with pre-commit).

2. Agent runs with no ceiling

A run with no token or dollar cap can loop all night.

  • Give every session or run a hard total-token (or dollar) ceiling.
  • When it hits the ceiling, stop. Don't soft-retry.
  • Your own run budget is not the same thing as a model's per-response output limit. Set both.

3. Keys passed around by copy-paste

A clipboard isn't a vault. A key pasted into a chat is a key that leaked.

  • Keep keys in a secret manager or env vars.
  • Rotate anything that's ever been pasted into a chat or ticket.

Copy/paste

[ ] Prompts in git, reviewed, secret scan on commit
[ ] Every agent run has a hard token or cost ceiling that stops it
[ ] No keys in chats, tickets, or prompt files; pasted keys rotated

This is the short version of Pocket Lint, a free keep-forever checklist pack from Weekstart with templates and a 9-item checklist. It's free for subscribers today. Sign up free to get the next drop: https://stackyard.fyi/store

πŸ“° Read the original article on Dev.to AI

Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.