Block API keys from leaking via a UserPromptSubmit hook
A pre-submit hook can grep your prompt for secret patterns and refuse to send if it finds one — safer than relying on memory.
- Type: Prompt
- Tags: Coding Agent Hacks, Intermediate, Codex
- Updated: 2026-10-01
Prompt
A pre-submit hook can grep your prompt for secret patterns and refuse to send if it finds one — safer than relying on memory. Codex sends prompts directly to the model, so accidentally pasting a secret means it leaves your machine. Add a `UserPromptSubmit` hook that scans for OpenAI, GitHub, and AWS key patterns. If a match is found, the prompt is blocked with a `stopReason` instead of being sent. Implementation example: // Codex config (format may vary by setup) { "hooks": { "UserPromptSubmit": [{ "hooks": [{ "type": "command", "command": "jq -r .prompt | grep -qE 'sk-[A-Za-z0-9]{20,}|ghp_[A-Za-z0-9]{36}|AKIA[0-9A-Z]{16}' && printf '{\"continue\":false,\"stopReason\":\"possible secret detected\"}' || true" }] }] } }
More prompts
- Expense Report Automation System — Save More Time
- Meeting Scheduling Link Standardization — Save More Time
- Invoice Generation and Delivery Automation — Save More Time
- Document Template Automation Library — Save More Time
- Calendar Management Automation Rules — Save More Time
- File Organization and Naming System — Save More Time
- Recurring Payment Automation Setup — Save More Time
- Data Entry Elimination Framework — Save More Time