Remix.run Logo
aurareturn 8 hours ago

How do you prevent an agent that simply console.logs(process.env.SUPER_SECRET) and then looking at the log?

0o_MrPatrick_o0 6 hours ago | parent | next [-]

Great question! You might enjoy this writeup, which in one section explores avoiding the use of shell variables that are not exported as a method of mitigating this risk.

https://linus.schreibt.jetzt/posts/shell-secrets.html

progx 8 hours ago | parent | prev [-]

Your app run in the app context, that is not accessible for an AI.

aurareturn 6 hours ago | parent [-]

You don't let your agent look at logs? How can it debug?