Developers

Claude Code, Cursor: protecting your secrets (.env, API keys) with coding assistants

A coding assistant reads your files and runs commands: that is its strength, and it is also how an API key or a database password can end up in its context. The concrete risks, the settings provided by Claude Code and Cursor, and what they do not cover.

Published on Updated on 7 min readBy the Tacite-IA editorial team

Contents
  1. How a secret ends up in an assistant’s context
  2. Claude Code: permissions and hooks
  3. Cursor: the .cursorignore file
  4. What the built-in settings do not cover
  5. The Tacite-IA layer: block the read and offer a copy
  6. Good practice at project level
  7. Frequently asked questions
  8. Sources

Coding assistants such as Claude Code or Cursor do more than suggest lines of code: they browse the project, open files, run commands and read their output. That is what makes them useful. It is also why a .env file, an API key or a database password can end up in their context, and then be sent to the model provider’s service. This guide describes the concrete risks, the settings the vendors provide in their official documentation, and what a local layer of control can add.

How a secret ends up in an assistant’s context

No spectacular mistake is needed. Most of the time, the secret arrives through an ordinary action:

  • Reading a configuration file. To understand why a connection fails, the assistant opens the .env file, appsettings.json or a configuration file containing the full connection string.
  • A terminal command. A “cat”, a “grep” across the whole project, printing the environment variables or an application’s logs can bring sensitive values into the output that the assistant reads.
  • Pasting into the conversation. The developer pastes an error message or a configuration excerpt that contains the key.
  • Connected tools. An MCP server or an upload command can send data out to a third-party service.

Once in the context, the secret is part of what is sent to the model. The assistant may also copy it into a file, a commit or an answer. Exposed secrets remain a massive problem: in its report published on 17 March 2026, GitGuardian counted 28.65 million new secrets hardcoded in public commits on GitHub in 2025, 34% more than a year earlier. The same report counts 24,008 secrets exposed in MCP server configuration files.6 OWASP, for its part, recommends managing secrets centrally (storage, access, rotation) rather than leaving them in plain text in code or configuration.5

.envAnonymised version

DB_PASSWORD=Xk92!pLmQ7[SECRET_1]

PAYMENT_API_KEY=a8F3kq0W…Zt[SECRET_2]

SMTP_PASSWORD=mT4#vR8w[SECRET_3]

3 items replaced on the device
A .env file before and after anonymisation: the structure remains readable for the assistant, the values are not sent. Fictitious values.

Claude Code: permissions and hooks

The Claude Code documentation describes a permission system that can be configured in settings files. To stop the tool from reading a file or folder, it says to add a read deny rule for its path, for example Read(./.env) or Read(./secrets/**).1 The settings reference page provides a ready-to-copy example for excluding files that contain API keys, secrets or environment variables.3 The documentation also notes that a .claudeignore file has no effect: its entries must be rewritten as deny rules.1

These rules apply to the built-in read tools, but also to the terminal commands that Claude Code recognises, such as cat, head or tail. The documentation itself states their limit: they do not apply to a command that reads files without naming them, such as a recursive search run from the folder, or to a script that opens files on its own. For system-level protection, it points to the Claude Code sandbox.1

For organisations, Anthropic provides managed settings, deployed by administrators, which user and project settings cannot override, with a few exceptions.1 Finally, Claude Code offers hooks: commands run automatically at specific points. The one that runs before a tool is called (PreToolUse) can block it.2 Additional controls, including Tacite-IA’s, are built on this official mechanism.

Cursor: the .cursorignore file

Cursor lets you declare, in a .cursorignore file placed at the root of the project, the folders and files that the editor must not access for its AI features. According to its documentation, .env* files are already in the list of files ignored by default.4

The same page clearly states two limits: the terminal and MCP server tools used by the agent cannot block access to files covered by .cursorignore, and, while Cursor blocks ignored files, complete protection is not guaranteed because of the unpredictable nature of language models.4 These points belong in the risk analysis of any team using the tool.

What the built-in settings do not cover

Built-in settings are an essential first layer. They do, however, rely on lists of paths: a secret stored in an innocuously named file (config.local.json, notes.txt), copied into a log or printed by a command slips past a rule written for “.env”. They also have to be configured project by project, or centralised by the organisation, otherwise every developer starts from scratch.

CriterionDeny rulesIgnore fileLocal control
Prevents a .env file from being read directlyYesYesYes
Covers terminal commandsPartlyNoPartly
Spots a secret in an innocuously named fileNoNoYes
Offers an anonymised copyNoNoYes
Indicative comparison drawn up by the editorial team from the documentation cited (sources 1 and 4). “Partly”: Claude Code’s deny rules cover the commands it recognises (cat, head…); a local control covers the commands it can analyse. The Claude Code sandbox, not shown here, works at system level.

France’s national cybersecurity agency (ANSSI) recommends a cautious approach when deploying generative AI.7 Applied to coding assistants, this means keeping secrets off the computer where possible, deny rules where they remain, and a check that looks at the content itself. On the repository side, the secret scanning offered by platforms, such as GitHub’s secret scanning, which goes through the entire Git history, catches some mistakes after the fact.8

The Tacite-IA layer: block the read and offer a copy

Tacite-IA is installed on the computer and relies on the coding assistants’ official hooks. In Claude Code, every action is examined before it happens:

  • Reading a sensitive file (.env, SSH keys, cloud credentials, private keys, configuration files containing secrets): the read is paused and confirmation is requested, or it is refused if the organisation has decided so.
  • Content analysed, not just the name: a file read by the read tool or by a command such as cat or grep is analysed on the computer. If it contains secrets or personal data, Tacite-IA writes an anonymised copy and gives its location: the assistant can work on the structure without seeing the values.
  • Upload commands: sending a file to an external destination (curl, scp…) or an attempt to disable the protection triggers a confirmation.
  • Typed messages: a key pasted into the conversation is detected before sending, and the anonymised version is offered.

The controls extend to the other supported coding assistants (Cursor, Windsurf, OpenAI Codex, Gemini CLI, Copilot CLI), to the extent their own hooks allow. Like any command analysis, Tacite-IA’s cannot see what a script opens on its own: the sandbox and sound secrets management remain necessary. The analysis is carried out without AI and nothing is sent to our servers: the console receives only data types and decisions, never the content.

Good practice at project level

  1. Keep secrets out of the repository.env file ignored by git, .env.example template with no values.
  2. Prefer a secrets managerA vault or variables injected at launch rather than a plain-text file.
  3. Limit the scope of keysDevelopment keys, minimal permissions, test environment.
  4. Plan for rotationAn exposed key is revoked and replaced, without delay.
  5. Configure the assistantDeny rules or ignore files for sensitive paths.
  6. Add an on-device checkFor the cases the settings do not cover.
Six measures, from secrets management to configuring the assistant (sources 1, 4 and 5).

These rules deserve a place in the organisation’s policy, alongside those covering chat assistants: our AI policy template lists access codes among the data never to be entered. For other types of data, see our guide to anonymising data before ChatGPT.

Frequently asked questions

Can Claude Code read my .env file?

Yes, if it has permission: the tool reads the project’s files to carry out its tasks. The Claude Code documentation explains how to prevent this with read deny rules, for example Read(./.env) and Read(./secrets/**), and states that a .claudeignore file has no effect.

Is a .cursorignore file enough to protect my secrets?

It is a useful protection, and .env* files are ignored by default. But the Cursor documentation states that the agent’s terminal and MCP tools cannot block access to ignored files, and that complete protection is not guaranteed. It is better not to keep secrets in plain text in the project and to add a complementary check.

What should you do if an API key has been sent to a coding assistant?

Treat it as exposed: revoke it, create a new one and check the usage logs of the service concerned. If the key gave access to personal data, assess whether this amounts to a personal data breach under the GDPR.

Can secrets leak through a terminal command?

Yes. Printing a file, searching the whole project or listing environment variables produces output that the assistant reads. Rules based on file names do not cover all these cases, as the Claude Code and Cursor documentation acknowledges; the sandbox and a check that analyses the command and its content reduce this risk.

Sources

  1. Configure permissions. Claude Code documentation, Anthropic. Accessed on 8 October 2026.
  2. Hooks reference. Claude Code documentation, Anthropic. Accessed on 8 October 2026.
  3. Settings reference: exclude sensitive files. Claude Code documentation, Anthropic. Accessed on 8 October 2026.
  4. Ignore file. Cursor documentation (Anysphere). Accessed on 8 October 2026.
  5. Secrets Management Cheat Sheet. OWASP Cheat Sheet Series. Accessed on 8 October 2026.
  6. The State of Secrets Sprawl 2026. GitGuardian, 17 March 2026. Accessed on 8 October 2026.
  7. Recommandations de sécurité pour un système d’IA générative. ANSSI (France’s national cybersecurity agency), 29 April 2024. In French. Accessed on 5 October 2026.
  8. About secret scanning. GitHub Docs. Accessed on 8 October 2026.
One measure among others

Govern AI use without slowing your teams down

Tacite-IA detects sensitive data in messages and files before they are sent to AI assistants in Chrome and Edge, and in coding assistants (Claude Code, Cursor, Windsurf, Codex, Gemini CLI, Copilot CLI). Analysis runs 100% on the device, with no AI, and comes with an admin console and an audit mode. Desktop apps (the ChatGPT desktop app, the Chat tab in Claude Desktop, Copilot in Windows) are not covered.

€6 excl. VAT per user per month billed annually, €8 excl. VAT billed monthly. 3-month trial.

Further reading