logoalt Hacker News

woodrowbarlowyesterday at 8:33 PM1 replyview on HN

by putting secrets in your environment instead of in your files, and running AI tools in a dedicated environment that has its own set of limited and revocable secrets.


Replies

sailfasttoday at 5:04 AM

Yes - separate secrets always - but you've still got local or dev secrets. Seems like the above permissions are the right way to go in the end. Thanks.