Control
Secrets, credentials or authorization rules placed in prompts or hidden context
No API key, token, password, private key or other credential is placed in a system prompt, agent instruction, task string or other model context, and no authorization decision (who may see or do what) is left to instructions in the prompt; credentials stay in tool code and authorization is enforced in code outside the model.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Reach
Trust and provenance
How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.
- This control
- Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
- Lanes
- TwinEthos recommendation (not law) 1
- Data release
- Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
- Legal review
- None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice.
- Audit standard
- 1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
- 2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
The guard to add
Keep credentials in tool code and enforce authorization in code; never put either in a prompt.
In prompt builders, agent instructions and task strings, include no credential and no secret environment variable: the tool function that needs a key reads it itself, and agents that must log in to a site receive placeholders (a browser-agent framework's sensitive-data option, which puts the real value in only when the action runs) rather than the value. Replace instructions such as 'only reveal balances if the user is an admin' with a check in the route or tool (the user's role or entitlement checked in code before the data is fetched or the action runs), and keep the prompt free of anything whose disclosure would matter, on the assumption that the whole context can be extracted.
Where it goes: 7 prompt construction, 1 application source code, 15 agent action surface.
What reviewers look for: prompt, instruction and task strings with no key patterns (sk-, AKIA, ghp_, xoxb-, PEM private keys) and no os.environ / process.env secret interpolation; tools that read their own credentials; role or permission checks in code on the paths the prompt used to describe.
Example (Python + OpenAI), before:
SYSTEM_PROMPT = f"""You are the billing assistant. Use API key {os.environ['BILLING_API_KEY']} with the billing tool.
Only reveal invoice totals if the user is an admin."""After:
SYSTEM_PROMPT = "You are the billing assistant. Use the get_invoice tool for invoice questions."
def get_invoice(invoice_id: str, user: User):
if not user.can_view_invoice(invoice_id): # authorization in code
raise PermissionError('not allowed')
return billing.get(invoice_id, api_key=os.environ['BILLING_API_KEY']) # key stays in the toolEngineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
TwinEthos recommendation (not law) (1)
- Everywhere (*)
- Keep secrets, credentials and authorization rules out of prompts TwinEthos derivation — guardrail.sec-no-secrets-or-access-rules-in-prompts
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.