Part of the AI coding agent security checklist
Developer OPSEC: what your laptop and your AI agents give away
Operations security, OPSEC, is knowing which of your information would help an attacker and keeping it out of their reach. For a developer, that information is mostly credentials. A laptop keeps many of them in plaintext, and AI coding agents add copies of their own.
Checked against NIST, OWASP, the Claude Code, AWS, npm, Docker, GitHub CLI, OpenSSH and 1Password documentation, and the research under Sources. Published .
What OPSEC means for a developer
NIST's glossary defines OPSEC as a process that denies potential adversaries information about your capabilities and intentions, in five steps. On one laptop, they look like this.
Where credentials sit on a developer laptop
The usual places. Unless a tool keeps its secret in the system keychain, any process running as you can read it.
| Where | What it holds |
|---|---|
~/.aws/ |
The AWS access keys you gave aws configure, for each profile. |
~/.ssh/ |
Private keys. A key with no passphrase works for whoever copies the file; ssh-keygen -p sets one on an existing key. |
~/.npmrc |
Registry tokens, as _authToken lines scoped to each registry. |
~/.docker/ |
Registry credentials, base64-encoded rather than encrypted, unless a credential store is set up. |
| GitHub CLI | Its token goes to the system credential store, or to a plain text file when it cannot use one or you pass --insecure-storage. gh auth status says which. |
.env |
Each project's application secrets, in plaintext beside the code. |
~/.bash_history, ~/.zsh_history |
Any token typed or pasted into a command line. |
~/.claude.json, .mcp.json |
MCP servers, with any API key written into their configuration. A project's .mcp.json is meant to be committed. |
The last row is not hypothetical. GitGuardian's State of Secrets Sprawl 2026 found 24,008 unique secrets in public MCP configuration files, 2,117 of them valid. And on 8 September 2026 Gen Digital reported that infostealers have added AI tools to what they collect: access tokens, MCP configurations and prompt histories. One of them, CallbackBeaver, added Cursor and Claude to its collection scope, and Gen Digital saw more than 5,000 samples of it in 30 days.
ls -la ~/.aws ~/.ssh ~/.docker what is there, and who can read it grep -l _authToken ~/.npmrc an npm token on disk gh auth status where the GitHub CLI keeps its token
What AI coding agents add
An agent runs commands as you, so it can read every file above. And it keeps its own record of what it read.
Claude Code writes every message, tool call and tool result to a transcript under ~/.claude/projects. Its documentation is plain about it: transcripts are not encrypted at rest, file permissions are the only protection, and if a tool reads a .env file or a command prints a credential, that value is written to the transcript. Claude Code deletes them after 30 days by default. Codex, Gemini CLI, GitHub Copilot CLI and others keep their own, each in its own folder: the history guide lists where.
So one cat .env leaves the value in two places it was not before: the model's context, and a file in your home folder. The OWASP AI Agent Security Cheat Sheet lists this among its key risks, as credentials included in agent context or logs. Claude Code's Bash commands also inherit the environment it was started in, secrets included, so a token exported in that shell is in reach of every command it runs.
Agents leak into commits too. GitGuardian measured a 3.2% secret-leak rate in public commits made with Claude Code's help, against 1.5% across all public GitHub commits, and says the figure does not put the cause on the tool alone.
See what is already there
Start with what takes a minute: which agents kept history here, what they ran, and which credentials they left in it.
ranwhat sources which agents left history on this machine ranwhat check what they ran, and the secrets they left; changes nothing ranwhat clean --no-interactive the secrets alone, with what to rotate
ranwhat reads the agents' history only. For your code and the rest of your home folder, run a general secret scanner as well: gitleaks dir scans a directory, and trufflehog filesystem scans files and directories. TruffleHog tests what it finds against each provider's API to mark it verified; --no-verification turns that off.
gitleaks dir -v ~/code trufflehog filesystem ~/code --no-verification
Rotate first, then clean up
A credential found in a transcript or a history file has already been readable. Masking the copy does not change that.
Keep secrets out of files the agent can read
Every plaintext copy you do not make is one less to find, rotate and mask later.
AWS_ACCESS_KEY_ID="op://development/aws/Access Keys/access_key_id" AWS_SECRET_ACCESS_KEY="op://development/aws/Access Keys/secret_access_key"
op run --env-file="./app.env" -- aws s3 ls the values exist only for this commandShrink what each token can do
A credential you cannot keep secret should at least be worth little to whoever copies it.
The OWASP Non-Human Identities Top 10 names the failures: secret leakage (NHI2), over-privileged identities (NHI5) and long-lived secrets (NHI7). Give each agent its own tokens, scoped to its task and with an expiry, rather than your own. ranwhat scan scores what a set of credentials allows, read-only, and marks the grants that were never used wherever the provider keeps a record.
The checklist.
One line each, in the order worth doing them. Each points back to its section.
- 01 Run uvx ranwhat sources to see which agents kept history here. Check
- 02 Run uvx ranwhat check, and rotate anything it finds before you mask it. Rotate
- 03 Scan your code and home folder with Gitleaks or TruffleHog. Check
- 04 Look through ~/.aws, ~/.ssh, ~/.npmrc, ~/.docker and your MCP configs: what is in plaintext, and who can read it. Laptop
- 05 Put a passphrase on every SSH private key. Laptop
- 06 Replace .env values with secret references, and inline MCP keys with ${VAR}. Keep out
- 07 Deny agent reads of .env and turn on the sandbox. Keep out
- 08 Set how long Claude Code keeps history on purpose. Agents
- 09 Give each agent its own scoped, expiring tokens. Tokens
- 10 After any suspected malware, rotate from a clean device, AI-service sessions and MCP credentials included. Rotate
What ranwhat covers, and what it does not.
ranwhat covers the agents' side of the laptop, after the fact.
Where each fact comes from.
- NIST: operations security (OPSEC)the definition and its five steps
- OWASP Non-Human Identities Top 10NHI2, NHI5, NHI7
- OWASP: AI Agent Security Cheat Sheetkey risks
- Claude Code: The .claude directoryplaintext storage, retention, ~/.claude.json
- Claude Code: Sandboxed Bash toolinherited environment, sandbox.credentials
- Claude Code: MCPvariable expansion in .mcp.json
- AWS CLI: configuration and credential files~/.aws/credentials
- npm: npmrc_authToken, scoped to a registry
- Docker: docker logincredential stores, base64 in config.json
- GitHub CLI: gh auth logincredential store, plain text fallback
- OpenSSH: ssh-keygen-p
- 1Password CLI: load secrets into the environmentop run, secret references
- Gitleaksgitleaks dir
- TruffleHogfilesystem, verification
- GitGuardian: AI coding agents are leaking credentials on endpoints25 September 2026
- Gen Digital: infostealers and your AI agent8 September 2026
- ranwhat sourcesources/, watch.py, clean.py