Recommended Free Tools
To reduce the risk of secrets leaking through an AI coding tool, keep credentials out of prompts and project context, use the tool’s own file-access exclusions, limit the agent’s permissions, and scan repository changes before pushing. If a credential is exposed, revoke and replace it promptly; deleting the file does not remove it from Git history.
Why an AI coding tool may see more than the active file
A coding assistant or agent may use project context beyond the file you are editing. OWASP’s Secure Coding with AI Cheat Sheet cautions: “Assume that AI coding assistants only send the current file. Many send broader project context.” The precise context and data flow depend on the tool and feature, so a short prompt or a focused edit is not proof that only that text is processed.
Review the documentation for the specific assistant, model, and deployment you use. Find out what prompts and code context are sent, which providers receive them, and what the relevant retention and training terms are. Cursor, for example, says its AI features send prompts and code context to model providers. Its Privacy Mode says code is not used for training; that is a data-use setting, not a guarantee that sensitive files cannot be read or transmitted.
Does .gitignore stop an AI agent from reading a file?
No. .gitignore tells Git which untracked files to ignore; it is not a general filesystem access control. An AI agent that can read the workspace may be able to read a file whether or not Git ignores it. OWASP specifically warns that AI tools can access files directly from the filesystem.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Keep secrets out of the workspace when practical. If they must be present locally, configure exclusions in the AI tool itself and verify what the exclusions block. OWASP gives these examples of sensitive paths to exclude:
.envand.env.**.pemand*.keycredentials.jsonandserviceAccountKey.json
Exclusion behavior can vary: check whether the setting blocks file reading, indexing, or only some requests. Cursor’s Agent Security documentation recommends .cursorignore to block access to files; it also says file reading does not require approval by default. Do not assume an approval prompt for sensitive actions protects files from being read.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How to reduce what an agent can do
Limit the consequences of a mistake as well as the information available to the agent. OWASP advises against granting broad credentials without sandboxing and cautions against auto-accepting actions on unfamiliar codebases.
- Do not place production credentials, deployment keys, broad cloud tokens, or full developer credentials in an agent’s environment unless the task genuinely requires them.
- Grant only the permissions needed for the task, and retain approval gates for sensitive actions.
- Use a sandbox where appropriate, especially when an agent can run commands or interact with a broad local or cloud environment.
These safeguards address different risks: file exclusions can limit what the tool reads, while least privilege and isolation can limit what it can do with its access. Neither should be treated as a substitute for the other.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How to provide a credential when an agent genuinely needs one
Avoid pasting secrets into prompts or terminals while an agent can inspect that context. If a task requires a credential—for example, access to a private package registry—use the platform’s dedicated secret mechanism when available. Scope the credential to the relevant repository or task, expose only the value needed, and avoid placing per-session secrets in logs.
These capabilities are platform-specific, not guarantees shared by all AI tools:
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- GitHub documents dedicated Agents secrets for Copilot cloud agent. They become environment variables in its development environment, and their values are masked in session logs.
- For self-hosted Anthropic managed-agent sandboxes, Anthropic advises storing the environment service key in a secrets manager rather than in environment files or sandbox images. Its guidance also calls for scoping workloads and credentials to trust boundaries, mounting only necessary directories, and never logging per-session secrets.
How to catch secrets before they reach a repository
Repository scanning is a second line of defense, not a way to prevent every prompt or context leak. Enable secret scanning and push protection where available, and configure relevant secret types for your organization. GitHub says push protection scans during git push and blocks detected secrets before they enter the repository, but not all secret types are push-protected by default. Secret scanning can also help identify credentials already in repository history.
GitHub’s remote MCP server supports secret scans initiated from Copilot agent mode, Copilot CLI, and MCP-compatible tools including VS Code, JetBrains, Claude Code, Cursor, and Windsurf. Its findings are ephemeral: they appear in the current agent session and are not persisted as alerts in the Security tab or alert APIs. Treat an agent-invoked scan as a pre-commit check, not as a durable record or replacement for repository-level scanning.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
GitHub documents prompts such as these for an agent-triggered scan:
Scan my current changes for exposed secrets and show me the files and lines I should update before I commit.
Run secret scanning on the files I’ve changed since my last commit and summarize any high-confidence findings.
Review scan findings and remediate them before pushing. A clean scan does not prove that no secret was exposed through a prompt, file context, terminal output, or another channel.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Which control addresses which risk?
| Control | What it helps address | Important limit |
|---|---|---|
| Tool-specific file exclusions | Reading or using sensitive workspace paths, depending on how the tool implements exclusions. | Verify whether the setting blocks reading, indexing, or only a subset of requests. |
| Privacy or no-training setting | How code is used under the provider’s stated data-use terms. | It does not by itself establish that a secret file cannot be read or transmitted. |
| Least-privilege credentials and sandboxing | The actions and resources available to the agent if it runs commands or makes requests. | These controls do not prevent a secret from entering the assistant’s context. |
| Agent-triggered secret scan | Finding potential secrets in the scanned changes before a commit or push. | GitHub MCP scan findings are session-only, not persistent Security tab alerts. |
| Repository secret scanning and push protection | Detecting repository secrets and, for supported types, blocking them during a push. | Push protection does not cover every secret type by default and cannot prevent all context leakage. |
Settings and data handling can differ by plan, model, feature, and deployment. Check the current documentation for the exact tool and configuration you use.
What to do if a secret is exposed
- Revoke and replace the credential promptly. Treat it as compromised even if you remove it from the current file.
- Investigate where it may have propagated. Depending on your environment, review branches, forks, backups, and logs, and investigate possible use of the credential.
- Remove it from current code and strengthen the relevant controls. Add or verify tool-specific exclusions, reduce agent permissions, and use scanning or push protection where available.
A secret committed to Git remains in earlier commits after it is deleted from the latest version. GitHub’s remediation guidance prioritizes revoking and replacing the credential; rewriting history can be time-intensive and is often unnecessary once revocation is complete.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

