> ## Documentation Index
> Fetch the complete documentation index at: https://envtrap.vercel.app/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# AI-Safe Design & Redaction

> How envtrap protects credentials from leaking into AI assistants, log aggregators, and LLM agent pipelines.

# AI-Safe Design & Redaction

Modern developer workflows increasingly involve AI coding assistants, automated log analyzers, and LLM-powered application runtimes. These technologies introduce two distinct security challenges:

1. **Developer Tool Leaks**: Cleartext crash dumps or terminal outputs being ingested into AI context windows and remote training datasets.
2. **LLM Runtime Exfiltration**: AI agents or code interpreters generating malicious egress calls that exfiltrate environment credentials.

`envtrap` is designed from the ground up to neutralize both risks.

***

## Non-Reversible SHA-256 Fingerprints

Whenever `envtrap` detects a secret value in `stdout`, `stderr`, or network payloads, it **never prints or logs the raw secret value**.

Instead, the value is hashed using SHA-256 and replaced with a non-reversible truncated fingerprint:

```text theme={null}
[REDACTED: SHA256:56018fa5]
```

### Why This Matters:

* **Safe for AI Coding Assistants**: Developers can safely paste full terminal sessions, error logs, and stack traces into AI chat tools (Cursor, Copilot, ChatGPT) without exposing raw API keys or database passwords.
* **Safe for Centralized Log Aggregators**: If logs are piped to Datadog, CloudWatch, or Splunk, secrets remain hashed.
* **Deterministic Auditing**: Because SHA-256 is deterministic, the same credential always produces the same hash prefix. Security teams can correlate incidents across channels without revealing the underlying credential.

***

## Protecting LLM-Powered Applications

Node.js applications that execute LLM workflows (such as LangChain, LlamaIndex, or autonomous agents) are uniquely vulnerable to prompt injection and unauthorized tool use:

<CardGroup cols={2}>
  <Card title="Prompt Injection Exfiltration" icon="user-secret">
    If an attacker tricks an LLM into dumping `process.env.OPENAI_API_KEY` into output streams or logging functions, envtrap redacts the secret before it reaches the terminal or log storage.
  </Card>

  <Card title="Unauthorized Agent Tool Calls" icon="robot">
    If an autonomous agent is hijacked to execute arbitrary HTTP requests or invoke shell utilities (`curl`, `wget`), envtrap severs the network socket or aborts the subprocess invocation.
  </Card>
</CardGroup>

***

## Recommended Configuration for AI / Agent Applications

For LLM applications connecting to AI providers like OpenAI or Anthropic, configure trusted domains under `exclusions.domains` while keeping strict blocking enabled on all other channels:

```json envtrap.json theme={null}
{
  "channels": {
    "stdout": "warn",
    "stderr": "warn",
    "network": "block",
    "child_process": "block",
    "dns": "block"
  },
  "exclusions": {
    "domains": [
      "api.openai.com",
      "api.anthropic.com"
    ]
  },
  "logFile": "logs/envtrap-ai-audit.jsonl"
}
```

***

## Defense in Depth

`envtrap` serves as the runtime egress firewall in a comprehensive defense-in-depth security posture:

| Security Layer | Tooling | What It Covers |
| :- | :- | :- |
| **Runtime Egress** | **envtrap** | Intercepts secrets leaving the live Node.js process |
| **Dependency Auditing** | `npm audit`, Socket.dev | Flags known CVEs and malicious package behaviors |
| **VPC / Network Rules** | AWS Security Groups, Cloud Firewalls | Restricts network interfaces to allowed IP ranges |
| **Secrets Management** | AWS Secrets Manager, HashiCorp Vault | Injects short-lived, rotated credentials |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.