Challenge 73 ☆

Welcome to challenge Challenge 73.

Challenge 73: Find the Secret in the Agent Instruction Files

AI coding agents load instruction and context files from the repository on every session: AGENTS.md, CLAUDE.md, .cursor/rules/*.mdc, .windsurfrules and similar. Because these files are "just documentation", they rarely get the same review as source code, yet they are read by a model, copied to every developer machine and committed to version control.

This repository ships such instruction files with its Dev Container. They live in the .devcontainer folder:

  • .devcontainer/AGENTS.md

  • .devcontainer/CLAUDE.md

  • .devcontainer/.cursor/rules/project.mdc

  • .devcontainer/.windsurfrules

One of them inlines a shared credential so that every agent reuses the same value "for convenience". Read the files and submit the exposed staging token.

Note

Nothing is encoded or encrypted here: this is exactly what a leaked agent context file looks like in the wild.

💡 Tip: Secrets are often strings, numbers, or encoded values. Copy and paste exactly what you find.

The agent instruction files are shipped with the Dev Container in the .devcontainer folder:

  • .devcontainer/AGENTS.md

  • .devcontainer/CLAUDE.md

  • .devcontainer/.cursor/rules/project.mdc

  • .devcontainer/.windsurfrules

Three of them only point at where the shared credential lives. One of them inlines the value of STAGING_DEPLOY_TOKEN in a shell snippet. That value is the answer.

If you are not using the Dev Container, you can also read the same files straight from the repository in the .devcontainer folder.

Why you should never put a secret in an agent instruction file

AGENTS.md, CLAUDE.md, .cursor/rules/*.mdc, .windsurfrules and the many other agent context formats are loaded automatically by coding agents. That makes them convenient, and that convenience is exactly what turns them into a secret management problem:

  • They are committed to the repository, so the secret is in the git history forever and has to be rotated the moment it appears.

  • They are copied to every machine that checks out the repository, including forks, CI runners and personal laptops.

  • They are loaded into the model context, so the value can end up in chat transcripts, telemetry and logs owned by third parties.

  • They usually carry a shared credential, which is rarely scoped down and even more rarely rotated.

  • Many secret scanners treat documentation files as low priority, so the leak survives review for a long time.

What to do instead:

- Keep credentials out of the instruction files and let the agent read them
  from the environment, for example `$STAGING_DEPLOY_TOKEN`.
- Document *which* variable is required and *where* to obtain it, never the
  value itself.
- Give every consumer a short-lived, least-privilege credential instead of one
  shared token.
- Scan agent instruction files with a secret scanner in pre-commit and CI, just
  like you scan source code.
- Treat any secret that ever appeared in agent context as compromised and
  rotate it.
Note

Skills, rules, prompts, MCP server configurations and agent instruction files are all code as far as your secret management is concerned. If you would not hardcode a token in a .java file, do not hardcode it in a CLAUDE.md either.