The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Keep credentials out of an agent’s prompts, memory, and retrieved context, and enforce access limits in the tools, identities, and runtime around the model. A system prompt can guide an agent, but it cannot reliably authorize sensitive actions or protect secrets.
Start by removing secrets from what the agent can see
Do not put API keys, passwords, connection strings, or access tokens in system prompts, user prompts, retrieved documents, tool descriptions, or persistent agent memory. Send the model only the information needed for its task. If a secret is required to perform an operation, keep it in a credential store and let a policy-enforcing component use it without exposing its value to the model.
For coding agents, exclude sensitive files such as .env files, private keys, cloud credential files, and deployment credentials from the agent’s context. Do not rely on .gitignore to prevent access: it governs Git behavior, not whether a tool can read a file. Check the actual files and content the agent’s product sends to the model, including retrieved material, logs, and tool output.
OWASP’s Gen AI Security Project advises that a system prompt should not be treated as a secret or as a security control. The core issue is not simply that an agent might learn an instruction; it is allowing sensitive data onto a model-visible surface or relying on that instruction instead of enforcing access checks.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Enforce authorization outside the model
Place a deterministic policy layer between the model and any sensitive operation. For each protected call, check the authenticated user, session, requested resource, and operation. The model may propose an action, but application code should decide whether that action is permitted.
Expose narrow tools, not broad access
Prefer task-specific operations with strict input schemas over unrestricted shell access, generic database access, or broad APIs. Validate arguments, reject unexpected parameters, and grant only the operations and resources required for the task. Use read-only access when it is enough. Keep high-impact actions separate from routine ones.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Bind approvals to the action
When a consequential action requires human approval, bind approval to the exact operation and parameters being approved, and make it expire. Do not let a general approval or the model’s claim of approval authorize a different action.
Secure MCP integrations
For Model Context Protocol (MCP) integrations, approve known servers and tools, inspect their descriptions and schemas, and monitor for changes. Validate arguments before execution. A server may hold credentials or permissions broader than those of the user who requested an action; prevent those server-side privileges from silently expanding the user’s access. Check the applicable MCP specification and the versions of the host and server you deploy, since protocol-specific behavior depends on the implementation.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Choose credentials and storage that limit blast radius
Do not reuse a developer’s broad token or a service-wide credential for every agent and tool. Create separate credentials where practical, and scope each to the appropriate server, resource, and operation. Prefer narrow OAuth scopes and read-only rights when sufficient. Where supported, use task-scoped ephemeral credentials or dynamic secrets generated for a session; otherwise, automate rotation of static credentials.
Keep secret values in a secrets manager, vault, or secure operating-system credential store with fine-grained access controls. Avoid plaintext OAuth tokens in MCP configuration files or application settings. Check that a token is intended for the server that receives it, and do not forward an MCP access token to an unrelated upstream API.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Choice | What it helps with | Trade-off to assess |
|---|---|---|
| Static credential | Can be straightforward to integrate and reuse for a defined service. | It remains valid until revoked or rotated; narrow permissions and automated rotation reduce, but do not remove, exposure if it leaks. |
| Task-scoped or session-dynamic credential | Can limit duration and scope to a task or session, reducing the window and blast radius of exposure. | Requires a system that can issue, scope, and revoke credentials reliably. |
| Plaintext file or configuration | Easy for a process to load. | Can expose secrets to any process or tool able to read that file; it offers weaker control over access and audit than a protected credential store. |
| Secrets manager or secure OS credential store | Can provide fine-grained access controls and support lifecycle management and auditing. | Access must still be scoped carefully: the component retrieving a secret becomes part of the trusted boundary. |
OWASP’s Secrets Management guidance emphasizes fine-grained access controls for individual secret objects and components. A secret manager does not make a broadly authorized agent safe by itself; control which identity can retrieve each secret, and which component can use it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Isolate agents that can run code or commands
A code-capable agent on an unrestricted developer machine can inherit the developer’s access to local files and credentials. Run it instead in a low-privilege restricted shell, dev container, virtual machine, or ephemeral workspace appropriate to the task.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Block access to host credential stores, SSH keys, cloud CLI configuration, production credentials, deployment keys, and unrelated sensitive directories.
- Restrict outbound network traffic to destinations the task requires.
- Apply resource limits and avoid mounting sensitive host paths into the agent’s environment.
- Use a separate environment or identity when tasks have different trust levels or permission needs.
Isolation boundaries vary by implementation. Verify what files, host resources, and network destinations the agent can actually reach rather than assuming that a container, shell restriction, or product setting provides the boundary you need.
Protect the full path through inputs, memory, tools, and logs
Treat user content, retrieved documents, websites, email, API responses, tool descriptions, and tool results as untrusted. They may contain instructions designed to redirect the agent or provoke an unauthorized action. Preserve the distinction between trusted instructions and untrusted data, and validate data before passing it to sensitive tools.
Avoid retaining sensitive information in shared or long-lived memory. Do not log credential values in plaintext. Record enough structured metadata about high-risk actions to investigate them—such as the identity, tool, resource, decision, and outcome—without turning logs into another secret store. Monitor tool calls and outputs for unusual access or possible exfiltration.
Verify denials, not just the agent’s stated behavior
Maintain repeatable adversarial tests and check the application’s actual authorization decisions and runtime behavior. A model saying it followed the rules is not evidence that the controls worked.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors- Attempt prompt overrides and requests to read excluded files or retrieve secrets.
- Try unauthorized tools, resources, and operations, including privilege escalation through a tool or server.
- Test secret leakage through responses, logs, memory, and outbound network traffic.
- Test approval bypass, unexpected tool arguments, memory poisoning, recursive tool use, and propagation across agents.
- Confirm that test fixtures contain no live credentials and that denied actions are recorded without exposing secret values.
Record the agent and tool-policy versions, test cases, expected and observed approvals or denials, timeouts, and accepted residual risks. Repeat the tests after meaningful changes to prompts, tools, memory, retrieval, policies, or model providers. OWASP’s guidance is a set of security recommendations, not a guarantee that any single control eliminates prompt injection or credential exposure.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

