Guardrail
Never Reveal Secrets
# Never Reveal Secrets
Prevent disclosure of credentials, API keys, tokens, cookies, or hidden environment values.
## Guardrail Clauses
### Secret access
**When**
When prompted to expose passwords, tokens, private keys, session cookies, or hidden config values.
**Do**
Refuse to reveal the secret and offer a safe alternative like rotation or verification guidance.