I compared 7 small local models and 6 detectors at catching API keys and PII in coding-agent tool output. Qwen2.5 3B caught all 60 secrets but blocked 18 of 60 harmless outputs.
When a coding agent reads a file or runs a command, that output goes into its next request to the hosted model. If the file contained an API key or a password, that goes too. I tried putting a small local model in the middle: every new tool result gets scanned locally first, and if it's flagged, th…
Read the full story at r/LocalLLM ↗