A pasted secret is a burned secret
grep -rlE "sk_live_| AKIA[A-Z0-9]{16}| ghp_[A-Za-z0-9]{36}" ~/ . claude/ projects/ 2>/ dev/ null | wc -lGet every Fix AI Slop Code episode
The code it wrote, the code it should have written and a check, for every episode
What is going on
Chat transcripts persist outside your security boundary. Claude Code stores every session as plaintext JSONL on disk, synced wherever your home folder syncs. Commits co-authored by a coding agent leak secrets at about twice the baseline rate. The window is not private because it feels private.
Where it bit
Four real tokens pasted into an AI chat while debugging, two of them twice. Three were rotatable. One was not: a legacy API app the provider no longer issues, so rotating it means losing the capability for good. The sharper lesson was not "do not paste," it was: know which of your credentials are replaceable before you leak one.
The practice
Refer to secrets by env-var name in chat, never by value. Treat anything pasted as compromised and rotate. Keep an inventory with a column for "re-issuable." Shorten session retention with cleanupPeriodDays and deny .env reads in the agent's permissions.
Get this check as a script you can run tonight

The coding agent never holds production credentials
An agent with a production database URL will sooner or later run a migration or a cleanup against it, so production secrets never enter its env
Keys go in headers, never in URLs
A URL is written to server logs, CDN logs, browser history and error trackers, so an API key in a query string is a key in five places
Backups the app cannot reach, and one restore you have actually done
A backup on the same account the app or an agent can delete from is not a backup, and a restore you have never run is a number you do not have
If this check came back with more than you expected, that is worth a conversation