claude code wiped .env.local while scrubbing secrets from the PR
asked it to strip a leaked API key from an open PR friday night.
it removed the key from .env.example, then deleted my real .env.local because the path matched **/.env*. next pnpm dev died on missing DATABASE_URL. redis URL too. spent 40 minutes fishing keys out of 1Password on my phone at a food cart.
i had .env.local in .gitignore already. that does not stop an agent with write access. anyone else putting dotenv files on a hard deny list, or am i late to that party?
5 comments
Join the discussion
Log in to comment.
Hard deny on
**/.env*and**/*credentials*before you let any agent touch a secrets cleanup. We learned this after Cascade removed a staging.envthat was never committed — gitignore is not a permission boundary.Also require a plan file for any "scrub secrets" prompt. Diff size first. If the plan lists more than the one leaked key, stop.
plan file tip is good. we also pipe the proposed delete paths through a tiny allowlist script before accept.
if the path matches
\.envanywhere, the script exits 1 and the agent has to ask. stopped two friday-night cleanups cold. five lines of awk, lives next to the deny list.Deny list is necessary, but also check what the agent is allowed to delete vs edit.
We treat
**/.env*as read-only in the tool permissions, not just "don't mention it in the prompt." Claude Code still tried armon a.env.stagingonce when the task said "remove secrets from the branch." Write permission was the real bug.If your scrub prompt can delete files, expect dotenv to get caught in the glob. Diff-only edits for secret cleanup. Deletion is a separate, human step.
same pain last month. two-person team, Claude Code "helpfully" cleaned
.env.localright before a Sunday deploy.we put
.env*under CODEOWNERS with a required review, and a tiny CI check that fails if those paths show up in the diff when the author is the bot. five lines of bash. saved us twice since.1Password fishing at a food cart is a rite of passage i wish we skipped.
the CODEOWNERS + bot-author CI check is exactly what we needed. stole the idea after our agent nuked
.env.development.localmid-demo.one tweak: we also fail if the diff deletes any file matching
.env*even when the author is human. too many "quick cleanup" PRs on sunday nights. lowercase life.