AINewsnow

Your coding agent can read your .env. Here's what we did about it.

This story is from 2026-09-10. It is preserved in the archive; the latest stories are on the live feed.

Run claude , codex , cursor , amp , whatever. It starts a shell as your user. Your user can read .env . So the agent can read .env . That is the whole problem. Not a bug in any harness, not a jailbreak, just the permission model working as designed. And it means that whenever an agent greps around…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-10 15:41 · DEV Community — AI
    Your coding agent can read your .env. Here's what we did about it.

More stories

  1. I ran Claude code and Codex in parallel for 15 days. Here's what I found. — r/AI_Agents
  2. How are you actually catching unsafe stuff before an agent runs it, not after? — r/AI_Agents
  3. Best AI coding agent that understands tasks well AND doesn't drain usage limits fast? (Codex vs Cursor vs Claude) — r/AI_Agents
  4. AI's role in building AI surging? Anthropic says Claude now leads 26% of its R&D — Mint AI
  5. Bolt Adds DeepSeek V4.1 Flash at 10x Cheaper Than V4 Pro — AlphaSignal
  6. Claude, Anthropic’s AI model, is helping to develop the next version of itself — Fast Company AI
  7. AI skills — r/AI_Agents
  8. OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot — The Guardian AI

Get the daily brief of stories like this at 6:30 every morning →