Stackmark › Prompts

Block API keys from leaking via a UserPromptSubmit hook

A pre-submit hook can grep your prompt for secret patterns and refuse to send if it finds one — safer than relying on memory.

  • Type: Prompt
  • Tags: Coding Agent Hacks, Intermediate, Codex
  • Updated: 2026-10-01

Prompt

A pre-submit hook can grep your prompt for secret patterns and refuse to send if it finds one — safer than relying on memory. Codex sends prompts directly to the model, so accidentally pasting a secret means it leaves your machine. Add a `UserPromptSubmit` hook that scans for OpenAI, GitHub, and AWS key patterns. If a match is found, the prompt is blocked with a `stopReason` instead of being sent. Implementation example: // Codex config (format may vary by setup) { "hooks": { "UserPromptSubmit": [{ "hooks": [{ "type": "command", "command": "jq -r .prompt | grep -qE 'sk-[A-Za-z0-9]{20,}|ghp_[A-Za-z0-9]{36}|AKIA[0-9A-Z]{16}' && printf '{\"continue\":false,\"stopReason\":\"possible secret detected\"}' || true" }] }] } }

More prompts

Privacy · Terms · llms.txt