AI Coding Agents
Security
Keeping secrets out of agent-generated commits
September 22, 2026 - 2 minute read
AI Coding Agents
Security
September 22, 2026 - 2 minute read
Secret scanning for agent-generated commits protects a boundary that is easy to overlook. A coding agent may read configuration, test output, fixtures, or tool responses while solving a task. Credentials copied into source, logs, snapshots, or generated files can persist in Git history even after a later commit removes them.
The safest workflow limits exposure before editing and scans again before commit and push. OWASP’s secrets management guidance recommends centralizing storage, limiting access, rotating credentials, and maintaining audit information across the secret lifecycle.
Give the agent only the credentials and files required for the task. Prefer short-lived tokens, narrowly scoped service accounts, and environment injection over values written into repository files. Keep production credentials away from development and preview environments.
Repository instructions should identify sensitive paths and safe substitutes. Use placeholders in examples, sanitized fixtures in tests, and mock responses that preserve shape without preserving real values. Exclude local environment files, debug captures, database dumps, and downloaded support artifacts through both access policy and ignore rules.
Prompts and task descriptions deserve the same care as code. Reference the secret’s environment variable name or storage location rather than pasting the value. If a tool returns credentials in output, stop that output from becoming a test snapshot or issue comment.
Limit network destinations too. A narrowly scoped task should not send repository context to an unrelated endpoint, and diagnostic uploads should require the same review as source changes.
Factory’s Droid Shield scans added lines when Droid performs a Git commit or push. It looks for credential patterns and blocks the operation when it finds a likely secret. The documentation also states that manual Git commands outside Droid are not covered, so teams still need repository and hosting controls.
Run established secret scanners in CI as a separate deterministic gate. Hosting-provider scanning, pre-commit checks, and server-side push protection can cover changes created outside the agent workflow. Tune allowlists narrowly and review them like code. A broad exemption can hide a real credential behind a recurring false positive.
Inspect generated and binary-adjacent artifacts too. Source maps, notebook outputs, HTTP recordings, package archives, and encoded fixture data can carry secrets even when ordinary source files are clean.
When a scanner finds a real credential, block the commit or push and remove the value from the working tree. If the credential reached any remote, log store, artifact service, or shared message, rotate or revoke it first. History rewriting alone cannot invalidate a copied credential.
Document the affected system, rotation result, and cleanup without repeating the secret. Check access logs when the provider makes them available. Then identify how the value entered the agent’s context and tighten that path.
Add a regression fixture with a fake value when the scanner missed a recognizable format. Confirm that the fixture cannot be mistaken for a usable credential.
Factory’s agent safety controls place secret scanning alongside command policy, hooks, sandboxing, and organization settings. Layered controls matter because no single scanner recognizes every format or every place sensitive data can appear.
Start building