Agent Blast Radiusby Kloudle

Answers / Can an AI Agent Read Secrets From Shell History?

Answer

Can an AI agent read secrets from my shell history?

Yes. Bash and zsh write every command you run to ~/.bash_history or ~/.zsh_history, including secrets typed inline — export FOO=sk-..., curl -H "Authorization: Bearer ...". An AI coding agent runs as your own user account, so it can open and read those history files exactly like any other text file in your home directory. The fix is prevention (HISTCONTROL, HISTIGNORE) plus rotating anything already exposed. Agent Blast Radius reports only a count of secret-bearing history lines, never the command text.

Updated · Kloudle

How do secrets end up in shell history?

Bash and zsh keep a running log of commands in your home directory — ~/.bash_history for bash, ~/.zsh_history (or wherever HISTFILE points) for zsh. Every line typed at an interactive prompt is appended by default, secrets included. Common patterns that land credentials straight into history: exporting a token before running a tool (export OPENAI_API_KEY=sk-...), passing a secret as a command-line argument (curl -H "Authorization: Bearer eyJ..." https://api.example.com), or embedding a password in a connection string (psql "postgres://user:pw@host/db").

None of this is careless by normal standards — it's how most CLI tools expect secrets to be supplied. But it means a plaintext secret sits in a file that persists long after the command finished, often for months.

Can an AI coding agent actually read that file?

Yes. History files are ordinary text files owned by your user, with no protection beyond normal file permissions. An AI coding agent running in a terminal, shell tool, or editor extension on your machine executes with your account's own permissions — the same ones you'd use to open the file in a text editor.

If the agent has any way to read files or run shell commands, it can read your shell history the same way it could read any other file you can see. This isn't a flaw in a particular agent; it's a consequence of the agent inheriting your account's standing access, a pattern described in general terms by third-party write-ups on agent permissions.

How do I stop bash from logging secrets in the first place?

Bash gives you two built-in variables for this, documented in the GNU Bash Reference Manual. Setting HISTCONTROL=ignorespace tells bash to skip saving any line that starts with a leading space, so prefixing a sensitive command with a space keeps it out of history. HISTCONTROL=ignoreboth adds ignoredups on top, skipping repeated lines too. HISTIGNORE takes a colon-separated list of glob patterns and skips any line that matches one — for example HISTIGNORE="export *:curl -H*".

Add either setting to ~/.bashrc so it applies to every new shell, not just the current session.

  • HISTCONTROL=ignorespace (or ignoreboth) — skip lines starting with a space
  • HISTIGNORE="export *:*Authorization*:*api_key*" — skip lines matching a pattern

What's the equivalent in zsh?

zsh has a comparable option, HIST_IGNORE_SPACE, enabled with setopt HIST_IGNORE_SPACE in ~/.zshrc. Per the zsh documentation, it removes a command line from the history list when the first character on the line is a space — the same convention bash uses with ignorespace.

As with bash, the setting only prevents future commands from being logged — it does nothing about history that already exists.

What do I do about secrets already in my history, and what does blast report?

If a secret is already in your history file, rotate it — revoke the key with the issuing provider and issue a new one — rather than relying on deleting the line, since you can't be sure the old value wasn't already copied elsewhere (history-sync tools, backups, terminal scrollback logs). You can still edit or truncate the history file afterward to reduce future exposure.

Agent Blast Radius's local scan looks at your shell history files and reports only a count of lines that look like they contain a secret. It does not print, store, or transmit the command text itself, so the result tells you there's cleanup to do without becoming one more place the secret gets written down.

Check your own machine

See what an agent running as you can reach. Offline, read-only, never prints values:

$npx -y @kloudle/agent-blast-radius@0.3.0

Inside your agent: install guides for Claude Code, Codex, Cursor, Claude Desktop and more. Which keys are live? npx -y @kloudle/agent-blast-radius@0.3.0 verify (paid per check).

Frequently asked

Does deleting my shell history remove the risk?

Deleting the file stops an agent from reading it going forward, but it doesn't un-expose a secret that was already there. If a value was ever written to history, treat it as potentially seen and rotate it with the issuing provider.

Does Agent Blast Radius show me which secrets are in my history?

No. It reports a count of secret-bearing lines in your shell history files, never the line content, the secret value, or which service it belongs to.

Will HISTCONTROL protect a command I already ran?

No. HISTCONTROL and HISTIGNORE only change what gets written to history going forward; they don't retroactively remove lines that are already saved.

Does this only apply to curl and export?

No — any command where you type a secret as an argument, environment assignment, or part of a URL gets logged the same way, including database clients, cloud CLIs, and API testing tools.

Sources

  1. Bash Reference Manual — GNU Project (Chet Ramey's reference copy)
  2. zsh Options — HIST_IGNORE_SPACE — zsh.sourceforge.io
  3. AI coding agent permissions: files, shell, git, cloud — Aurascape

Related