AI Coding Agents Are Leaking Your Secrets: Building a Local Pre-Commit DLP for Claude Code A developer built AgentSweep, an open-source tool that scans the local JSONL conversation histories kept by AI coding agents such as Claude Code and Codex for credential-shaped strings and redacts them without breaking the history format, plus a pre-commit hook to check the separate secret store before commits. The tool walks Claude Code's project trees for *.jsonl files, honors CLAUDE_CONFIG_DIR and CODEX_HOME, and uses source adapters to handle differing storage formats across Cursor, Windsurf, and Aider. The author notes that rotating a leaked key does not remove its bytes from transcripts, backups, or filesystem snapshots, and cites Aikido's analysis of the compromised @bitwarden/cli@2026.4.0, whose preinstall payload targeted .env, cloud credentials, and ~/.claude.json. You paste a .env file into Claude Code to debug a database connection. You remove the credentials from your next message, clean the repository, and rotate the database password. Your local conversation history still contains the original paste. Claude Code keeps JSONL transcripts beneath ~/.claude/projects/ . Codex keeps session JSONL beneath ~/.codex/sessions/ . A process running as your user can read those files without asking either agent for permission. I built AgentSweep https://github.com/Ishannaik/agent-sweep to scan that history, report credential-shaped strings, and redact them without breaking the history format. I also added a pre-commit hook so developers can check this separate store of secrets before committing code. The headline describes a credential exposure, not proof that your coding assistant has sent a key to an attacker. Developers create the exposure when they paste secrets or let an agent capture secret-bearing tool output. Attackers exploit the copy left on disk. A repository scanner checks the files you stage or commit. Your agent's history lives elsewhere: Developer home | + .claude/ | + projects/ | +