upvote
what's to stop an agent creating an outbound call with the var to a malicious endpoint? (unless you whitelist what it has access to)
reply
or an outbound call to a trusted endpoint with the env var in a way that can get exposed to the agent via a subsequent call?
reply
It's possible reflected instances are masked too, like GitHub Actions. But I don't know.
reply