When an agent has to deploy, call a paid API or push code, it needs a credential. The common approaches make it visible far beyond that single use:
- In the prompt: the value goes to the model provider, stays in the conversation history and can resurface in a response.
- In the agent's context / memory: it gets re-injected on every turn, multiplying the leak points.
- In a
.envor config file: it sits in plaintext on disk, ends up in a commit or a screenshot.
The risk isn't theoretical: a single well-placed prompt injection can convince an agent to spit back everything it holds in context.