It's not a perfect fix but it keeps secrets out of env with (so far for me) minimal inconvenience.
I'll take security by inconvenience over building what becomes the primary reason for a security incident.
If you have allowed an agent to access any kind of credential, you should assume it is no longer private.