Your AI Coding Agent Can Exfiltrate Your Credentials. You Would Never Know.
I spent last night configuring Claude Code's security and realized something uncomfortable: for months, I had been running an LLM with unrestricted access to my terminal. It could read my SSH keys, browse my AWS credentials, curl data to any endpoint, and push code to production. I just never thought about it because the tool was helpful and nothing bad had happened yet.
That is exactly the kind of reasoning that gets production databases dropped.