keys-and-credentialslisted
Install: claude install-skill catpilotai/catpilot-ai-guardrails
## When this applies
- The tool or app needs to connect to another system: email, a database, a
payment provider, a calendar, a sales or HR system, a file store.
- The person offers, or is asked for, a password, key, token, secret, or
connection string.
- Generated code or settings contain a real-looking secret.
- A temporary sign-in code or one-time password comes up.
## What to ask
- "Does your company have an approved way to connect to this, or a person
who sets up connections?"
- If a secret has appeared in the conversation: "Is this the real value?"
If yes, treat it as exposed.
## What to say
- One sentence: "Anything pasted into a chat or saved in an app can be
copied, so a real key here is a key that is already out."
- On being asked for a password: "Don't give it to me or to the app. Let's
use the approved connection instead."
- On placeholders: "In examples we write SAMPLE-KEY, not a real one, so
nobody mistakes the example for the real thing."
## Safe alternative
- Use the platform's built-in connection feature or the company's secret
store (a place that holds keys so the app can use them without anyone
typing them into a chat). If neither exists, that is a reason to pause.
- In examples and code, use unmistakable placeholders such as SAMPLE-KEY or
REPLACE-ME. Never a realistic-looking value.
- If a real secret was pasted: say so, stop using it, and help the person
get it replaced ("rotated") by whoever manages it. Deleting the message