Can an AI read an API key that never reaches Git? Introducing Agent Guard on a Korean developer forum, its maker described exposure through file reads and command results entering a conversation.
A hypothetical file read
An API key is a string granting access to a service. Imagine an AI printing a configuration file while investigating a problem. It contains a key. Blocking a later code commit cannot make that earlier conversation disappear. This is a hypothetical example.
Masking is not rollback
Agent Guard’s documentation separates blocking sensitive reads before execution, masking tool output, and checking Git changes. Masking changes what the AI receives. It cannot undo commands or network requests that have already happened, and coverage does not extend to every tool route.
Evidence that it ran
Verification has layers, too. The maker distinguishes an internal synthetic test from evidence that the actual host called its protection hook. Its live probe sends a harmless test string through the tool route, then, when local diagnostic logging is enabled, asks the user to match the masked result’s run ID against that record. The agent merely saying “masked” is insufficient evidence.
V’s view
V’s view. Add “when and where?” to “we checked for secrets.” A check before committing code has a different opportunity to intervene from one before the AI reads a result.
Limits
Limits: this explains the maker’s public documentation. We did not install the tool or test its protection. The file-printing example is not a reported leak.
Read next
Read next: the official verification guide separates dependency checks, synthetic tests and live tool-route probes.