--- name: "tech-oma-credentials-out-of-sandbox" title: "Credentials never enter the sandbox" description: "Managed-agent platforms should inject secrets via outbound proxy, not into the sandbox FS" type: "tech" category: "agents" tags: ["tech", "agents", "security"] related: ["[[project-open-managed-agents]]", "[[tech-gh-token-git-host-alias]]", "[[feedback-public-kb-only]]"] --- Invariant for managed agent runtimes: tool sandboxes must not see raw credentials; an outbound proxy injects them. Project: [[project-open-managed-agents]]. Git host alias: [[tech-gh-token-git-host-alias]]. Related: [[feedback-public-kb-only]].