How does a credential end up in my agent's output?

Usually because a tool call hands the agent something raw and it repeats that back. An agent that reads a .env file to check a setting, prints a debug log, or calls a tool that returns headers and environment variables now has that content in its context, and the next thing it writes often quotes it verbatim, in an explanation, a retry, or a line it logs.

The common paths are reading config or env files directly, verbose debug output, a credential passed into a tool call itself (an MCP server configured with a key, an HTTP parameter carrying a token), generated code that hardcodes a key it just saw, and child processes inheriting the same environment variables the agent has. All of them end in the same place, the output, which is where secret_leak reads for the shape of a live credential. None of it needs a bug in the model. The agent is doing what a language model does with whatever sits in its context: repeating what’s relevant to the answer.

sources

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y