Hacker News
new
top
best
ask
show
job
After the Mercor breach, I built a local secret scanner for AI-generated code
(
aigate-landing.onrender.com
)
3 points
by
jricramc
8 hours ago
4 comments
JSR_FDED
6 hours ago
What is the exact threat being addressed here? If the proxy detects a sensitive key and then places it in a .env file, Claude code would pull the value from the env file and then still send it to Anthropic servers wouldn’t it?
jricramc
6 hours ago
Correct, it doesn't protect against a malicious LLM actor, but rather places guardrails on the developer as well as the agent.
jricramc
8 hours ago
Here's a walkthrough of how it works:
https://screen.studio/share/kfozpfSg
jeremie_strand
8 hours ago
[dead]
jricramc
8 hours ago
[dead]