Ask HN: How to protect your dotfiles from being stolen by nefarious scripts?
For example, the recent eslint NPM virus had full access to the local user's dotfiles, and uploaded their .npmrc file to a remote server. The virus could have accessed anything under the user's account, including ~/.aws/credentials, ~/.bashrc (often contains a lot of API keys and access tokens), ~/.ssh, etc.
What are some ways to protect yourself from illicit access by rogue installer scripts (npm, pip, gem, homebrew, etc.)?