logoalt Hacker News

Tenokeyesterday at 8:33 AM0 repliesview on HN

There's ways to make sure env vars get only injected at runtime and arent easily accessible otherwise or to even make them inaccessible to the user your agent is running on, and for you to manually run the code with the right permissions when the keys actually need to be used. Almost nobody bothers doing it though.