Tag
The author expresses concern about granting coding agents shell access, noting they can read sensitive files like .env and credentials, and asks the community for practical secret-handling patterns before letting agents touch real repositories.
An open-source agent is given shell access and the ability to rewrite its own skills, but a governance kernel is introduced to prevent catastrophic actions.