Skip to content

Build1 publisher3 min readPublished Updated

Your Coding Agent Reads .env, And .gitignore Was Never The Control

A dev.to writeup makes a point worth stealing: the secret leaves your machine in a prompt, not a commit. The proposed fix is a local proxy that masks values before egress.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Your Coding Agent Reads .env, And .gitignore Was Never The Control
Generated illustration

What happened

  • Tools such as Claude Code, Codex, Cursor, Aider and Cline can read files, inspect directory trees, execute terminal commands, and feed the results back into a model; that context is what makes them useful but also creates a new path for accidental data exposure.
  • An agent asked to debug a failing deployment may run `cat .env`, whose output contains values such as DATABASE_URL with an embedded password, GITHUB_TOKEN and INTERNAL_API_KEY.
  • The agent may include that command output in its next model request, at which point the values become part of the outbound prompt and are no longer only on the local machine.
  • .gitignore does not prevent this exposure and secret scanning at commit time does not prevent it either; the secret does not have to enter Git history to leave the workstation.
  • The author built Anonmyz, an open-source local DLP proxy for AI coding agents that runs on the developer's machine between the AI client and the model provider.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

A writeup on dev.to lays out a leak path that most secret hygiene does not cover: agents such as Claude Code, Codex, Cursor, Aider and Cline can read files, walk directory trees and run terminal commands, then feed the output back to a model [1]. Ask one to debug a failing deployment, it runs `cat .env`, and the database URL, GitHub token and internal API key in that file can land in the next outbound request [2][3].

The load-bearing observation is about where your existing controls sit. According to the author, `.gitignore` does not prevent this and neither does commit-time secret scanning, because the credential never has to enter Git history to leave the workstation [4]. Repo-boundary tooling was built for a world where the exfiltration route was `git push`. The route now is an HTTPS request your agent makes on your behalf, several hundred times a day.

The author's response is Anonmyz, an open-source local data-loss-prevention proxy that sits on the developer machine between the AI client and the model provider [5]. Per the writeup, it intercepts the outbound request, scans the JSON body for supported secret patterns, swaps detected values for cryptographically random placeholders, keeps the placeholder-to-value mapping in a request-scoped in-memory vault, forwards only the sanitized request, restores the real values locally when the response comes back, then clears the vault [6]. A token becomes something like `GITHUB_TOKEN=[[GITHUB_TOKEN_7F3A9C2D]]` on the wire [7]. Unique placeholders rather than a flat `[REDACTED]` are deliberate: the model can tell two different values apart without learning either, and the return path stays coherent [8].

The interesting engineering is in streaming, which is where naive implementations of this idea fail. Coding agents mostly stream via Server-Sent Events, and a placeholder or a raw secret can be split across arbitrary network chunks, so scanning each chunk independently misses it [9]. The author says the proxy holds a bounded look-behind window, delays emitting bytes that might be the start of a supported secret or placeholder, scans the boundary, and fails closed if a response cannot be handled safely [10], with split-position tests rather than an assumption that one network read equals one logical token [11]. That is the correct instinct, and it is also the part where any competing implementation should be interrogated first.

On architecture, the argument for keeping this local is straightforward: routing prompts through a cloud DLP service adds another party that receives the sensitive prompt [12]. What ships is a loopback reverse-proxy mode, an optional transparent interception mode restricted to allowlisted AI domains, standard and SSE responses, provider adapters, allowlisted header forwarding, metadata-only local audit and metrics, a Codex Safe Session launcher, VS Code integration and a beta JetBrains integration [13]. The core is Go standard library, one binary, no Python or Node runtime, Docker optional [14]. For a thing you want in the path of every agent request, that dependency profile matters more than the feature list.

Two limits to hold onto. Detection is pattern-based, covering categories such as API keys and provider tokens and GitHub tokens [15], so any credential shape that matches no supported pattern crosses the wire intact [16]. And this does not stop the agent reading `.env`; it stops the value crossing the network in cleartext [17]. Everything here is one author describing their own tool.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories