{"title":"Agent Stealth: Preventing API Key & Secret Leakage","region":"Global","category":"Security","description":"Five guardrails to prevent agents from leaking API keys and other secrets.","lastUpdated":"2026-02-23","steps":["Scan agent outputs for secret-like patterns before display.","Scope secret access to only the keys required for the active tool.","Exclude secrets from logs and telemetry.","Use a proxy or vault so agents see alias tokens, not raw secrets.","Add a system-prompt rule forbidding disclosure of credentials."],"url":"https://checklist.day/agent-secret-management"}