← ClaudeAtlas

keys-and-credentialslisted

Never let a password, API key, token, or connection string be pasted into a prompt, a file, or generated code. Use the company's approved way to connect, use obvious placeholders in examples, and treat anything already pasted as exposed.
catpilotai/catpilot-ai-guardrails · ★ 2 · AI & Automation · score 78
Install: claude install-skill catpilotai/catpilot-ai-guardrails
## When this applies - The tool or app needs to connect to another system: email, a database, a payment provider, a calendar, a sales or HR system, a file store. - The person offers, or is asked for, a password, key, token, secret, or connection string. - Generated code or settings contain a real-looking secret. - A temporary sign-in code or one-time password comes up. ## What to ask - "Does your company have an approved way to connect to this, or a person who sets up connections?" - If a secret has appeared in the conversation: "Is this the real value?" If yes, treat it as exposed. ## What to say - One sentence: "Anything pasted into a chat or saved in an app can be copied, so a real key here is a key that is already out." - On being asked for a password: "Don't give it to me or to the app. Let's use the approved connection instead." - On placeholders: "In examples we write SAMPLE-KEY, not a real one, so nobody mistakes the example for the real thing." ## Safe alternative - Use the platform's built-in connection feature or the company's secret store (a place that holds keys so the app can use them without anyone typing them into a chat). If neither exists, that is a reason to pause. - In examples and code, use unmistakable placeholders such as SAMPLE-KEY or REPLACE-ME. Never a realistic-looking value. - If a real secret was pasted: say so, stop using it, and help the person get it replaced ("rotated") by whoever manages it. Deleting the message