To each their own.
To each their own.
.env files or injecting secrets at startup via a secret manager still risks leaking keys.
I vaguely recall an implementation that substitutes secret placeholders with real secrets only during outgoing calls to approved domains which sounds better. However, you're still trusting an agent on your machine with command execution.
I’m kind of curious what you do with it. I feel like the real value is integrating it with everything but then even if it’s nanoclaw or simpler majority of the worthy things are on the unsafe side.
Would love to hear your experience as I’m planning to do the exactly same.
So... the real value so far is I find it fun? It isn't the "life changing need to go make a tweet!!" level for me.
The real lesson is if you ignore security and data disasters agentic AI is easier than anyone expected.