AI Agent Hub
Back to skills
Agent Credential Security and Sandbox Isolation icon

Agent Credential Security and Sandbox Isolation

IT Ops & Security Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md to install @user_a2c1a186/agent-credential-sandbox into your AI assistant.

About this skill

Problem

When an Agent calls APIs, queries databases, executes code, or connects to cloud services, it may directly expose sensitive material such as API keys, OAuth tokens, and database passwords. The risk is not only sloppy code; if the model misbehaves or is manipulated by prompt injection, credentials can leak through tool arguments, logs, or output.

This skill focuses on a stronger property: even if the model were replaced by a malicious LLM, it should not be able to obtain any credential. The core principle is that an Agent should have capabilities, not secrets. Credential lookup, injection, rotation, and revocation should happen outside the model’s visible boundary.

How It Works

The skill organizes Agent security into executable phases:

  • Credential audit: enumerate all tokens, keys, passwords, and certificates accessible to the Agent, then mark exposure paths such as hardcoding, environment variables, and configuration files.
  • Five defense layers: start with the mandatory L1 Proxy Pattern, where the Agent only calls internal tool APIs while a gateway reads credentials from a vault and injects them; optionally add OAuth delegation, STS temporary credentials, tool output redaction, and TEE trusted execution.
  • Sandbox isolation assessment: evaluate coverage for code execution, outbound network access, supply-chain pollution, and filesystem attacks, while explicitly noting that sandboxing does not cover privileged queries, prompt injection, or business authorization.
  • Confused deputy defense: add user context propagation, database RLS, purpose-based access control, and a unified policy engine to close authorization gaps.

Boundaries

This skill is useful for Agent architecture review, security hardening, and permission boundary design. It enforces never trust the model, meaning credential-related decisions must be made by the gateway or policy engine. A key limitation is that sandboxing is runtime security, not authorization control; output redaction, least privilege, and automated credential lifecycle management are still required.

Use Cases

  • Design an Agent API gateway that moves keys out of the model environment into a vault, then injects credentials before forwarding calls.
  • Audit tokens, database passwords, and cloud credentials accessible to an Agent, marking hard-coded, environment, and config exposure.
  • Before shipping Agent code execution, assess whether the sandbox covers filesystem, network, and supply-chain risks, then identify uncovered authorization gaps.
  • Prevent confused deputy attacks in Agent database queries by adding user context propagation, RLS, and purpose-based access control.

Best For

  • Backend engineers owning Agent gateway security who need to move credential lookup and injection outside the model environment.
  • Platform security architects who need to distinguish sandbox coverage from authorization controls and prompt-injection defenses.
  • IT operations leads who need to audit API key exposure and plan rotation, revocation, and configuration rollback.
  • Data platform engineers who need to add RLS, user context propagation, and purpose-based access control to Agent queries.