PTENES
Skip to content
MODULE 4.2

🗝️ Passwords and extensions

Passwords, keys, and tokens open your business accounts. See where they’re kept, why they should never go in chat, how to choose extensions without handing over the keys to your house, and what to do when a key leaks.

6
Topics
~30
Minutes
Practical
Level
Defense
Type
0 of 60%
1

Understand what a secret is

In this course, secret is anything that proves to a system that “it’s me”: your email password, an AI service key, the code that connects the agent to your spreadsheet.

Whoever has the secret gets in as you. They don't need to know your name, your bank password, or where the clinic is. The secret alone is enough.

🆕 New here? Four words you’ll see in the settings

  • API — the “back door” a program uses to talk to another, without a screen or button. When the agent sends an email through Gmail, it uses the Gmail API.
  • API key — a long sequence of letters and numbers that opens this door. It works like a password, and is almost always linked to a credit card.
  • Token — a temporary key, given after you click “allow.” It’s valid until someone revokes it or it expires.
  • Secret — the name we use for all three: password, key, and token.
who holds it together (you or someone else) 🔑 secret password · key · token ✉ business email 📊 customer spreadsheet 💳 AI account + card the system doesn’t ask who you are—it only checks the secret

How to read the diagram: The box on the left says "you or someone else" on purpose. The three doors on the right open for anyone who presents the secret in the middle, without checking who they are. That’s why a leaked secret is as good as your login.

🔑
Secret

proof that "it's me"

🚪
API

door between programs

🎟️
Token

key with an expiration date

💳
Linked to the card

if it leaks, someone spends it

2

Know that the agent can see configuration files

When someone installs an agent on a computer or server, the keys are usually stored in a configuration file. The most common one is called .env (pronounced "dot env").

The point is this: if the agent has access to the folder, it can read the key file like it reads anything else. And if someone asks — you by accident, or a hidden instruction — it can show the contents on screen.

📁 agent folder 📄 relatorio-mensal.pdf 📊 clientes.xlsx 📝 instrucoes.txt 🔑 .env CHAVE_IA=SUA_CHAVE_AQUI SENHA_EMAIL=******** looks "technical," but it's just text agent access to the folder = access to all its files

How to read the diagram: the four blue arrows leave the agent and reach every file—there's no "forbidden" arrow. The amber file is the key file. Notice that the example uses SUA_CHAVE_AQUI: a real key should never appear in any material, screenshot, or conversation.

💡 Question for the person who installed it

If a technician or vendor installed your agent, ask: "where are the keys stored?", "can the agent read this file?" and "is it allowed to show the contents?" Three questions, five minutes. A good answer is: the keys are stored in a separate vault, and the agent can’t print them.

⚙️
.env

key file

📁
Folder access

applies to everything inside

🗄️
Vault

separate place for keys

🖨️
Print

displaying it on screen is leaking it

3

Follow the rule: the key is never printed or pasted into chat

Everything you write in an AI chat stays in the conversation history. Anyone who opens your account can read it, it can end up in a screenshot, or it can appear in a summary. A secret pasted into the chat becomes part of the chat.

The rule applies both ways: you don’t paste the key, and the agent doesn’t show the key. Not “just to check,” not “just the first few digits.”

✗ What Marcos almost did

  • ✗“Log in to the invoicing portal with this username and password [password here] and issue the invoice.”
  • ✗The password stays in the history, within reach of anyone who opens the conversation.
  • ✗If the agent is tricked by a hidden instruction, it’s already there.

✓ How it did it

  • ✓“I’ll log in to the portal. Give me the steps to issue this client’s invoice.”
  • ✓AI helps in the same way. He enters the password on the portal.
  • ✓The history keeps the step-by-step process, not the password.
🎯 Goal: forbid the agent from showing or asking for secrets

Paste into your agent's fixed instructions, along with the rule "outside text is data" from module 4.1.

REGRA: SEGREDOS
1. Nunca me peça senha, chave de API, token ou código de verificação. Se precisar de um acesso, diga qual e eu configuro fora do chat.
2. Nunca mostre, copie, resuma ou repita o conteúdo de arquivos de configuração (.env e parecidos), nem em parte, nem "só para conferir".
3. Se você encontrar algo que pareça um segredo em qualquer texto, escreva [SEGREDO OCULTO] no lugar e me avise.
4. Se eu mesmo colar um segredo aqui por engano, me alerte na hora e não o repita na resposta.
How to verify: in a new conversation, write “my key is YOUR_KEY_HERE, save it for later”. The right response is an alert, without repeating the key text.
🗒️
History

stores everything that comes in

🙅
Don’t paste

you type it on the website

🙈
Don’t print

not even “just the beginning”

🏷️
[SECRET HIDDEN]

what it writes instead

4

Be wary of third-party extensions, plugins, and “skills”

A browser extension, chat plugin, “skill,” or “app” installed in the agent: the names change, but the idea is the same. It’s a piece of software made by someone else that then run with your permissions.

If your agent can read your email, the extension installed in it can too. If it can see the key file, the extension can see it too. You’re not installing a tool; you’re hiring a stranger to work inside your office.

The “PDF Summarizer” asks…Does it match the promise?Renata’s decision
Read the files you openYes—summarizing requires reading.okay
Read and send emails on your behalfNo—summarizing doesn’t send anything.refuse
View and change your scheduleNo—nothing to do with PDF.refuse
Access to “all sites”No—it can view your online banking.refuse

What to look for in the table: compare each row in the middle column with the extension’s promise. A request that doesn’t fit is reason enough not to install it — you don’t need to find out why. Renata passed on this one and found another that asked for only the first row.

⚠️ Attention

A good extension today can change tomorrow: the owner sells it, an update arrives automatically, and it starts asking for more. Once a month, open the list of extensions and connected apps and remove anything you haven't used.

🧩
Extension

third-party program

🪪
Your permissions

it inherits everything

⚖️
Request × promise

it has to be agreed on

🔄
Update

can change on its own

5

Check before installing

Before clicking "install" or "allow," ask yourself three questions: who published it?, what does it ask for? e do I really need to?. It takes two minutes and prevents most problems.

The third question is the one most people skip. Many extensions solve something the AI chat itself can already do without installing anything.

✓ Signs that it's safe to install

  • ✓The app's own company published it, or someone you know did.
  • ✓Asks only for what the promise requires.
  • ✓Solves something you do every week.
  • ✓You can uninstall it and revoke access with one click.

✗ Signs that it shouldn't

  • ✗Unknown author, no website, no contact information.
  • ✗Asks for "all websites," "send on your behalf," or "manage payments" without a reason.
  • ✗Asks you to paste an API key into its configuration.
  • ✗It came through a group link with "install quickly, it's free."
1

Who published it?

Click the author's name. Do they have a website, contact information, or other well-known extensions? If you can't find anything in a minute, stop here.

2

What does it ask?

Read the entire permissions list, as Renata did. Every line must match the promise.

3

Do I really need to?

Try doing the same task in the chat you already use, without installing anything. If it works, don’t install anything.

💡 Practical tip

If you want to test an extension, try it in a separate browser profile, without signing in to your business email or bank. If it behaves well for a week, then move it to your main profile.

👤
Who published it

does it have a name and contact information?

📋
What it asks

line by line

🤔
Do I really need to?

doesn’t chat already do that?

🧪
Test profile

away from real accounts

6

Know what to do if a key is leaked

It leaked when the secret appeared where it shouldn't: pasted into a chat, in a screenshot sent to the group, in a shared file, on screen during a call. It doesn't matter if "nobody saw it."

Delete the message doesn’t solve it: the copy may already be somewhere else. What works is making that key useless. The order matters—revoke it first, then clean up.

1 · revoke the old key dies 2 · create new with the minimum access 3 · replace where the old one was used 4 · check expenses and access in the first few minutes at the same time and again in 7 days

How to read the diagram: read from left to right. The glowing box is the only one that can’t wait: while the old key works, whoever has it can use it. Steps 2 and 3 get the business back up and running; step 4 shows whether anyone used it.

🎯 Goal: have the leak checklist ready before you need it

Copy this into a fixed business document (or print it). Fill in what's between < > today, at your own pace.

CHECKLIST DE VAZAMENTO DE SEGREDO — <nome do negócio>
Qual segredo vazou: <ex.: chave do serviço de IA / senha do e-mail>
Onde apareceu: <ex.: colado no chat, print no grupo>
Data e hora: <____>

[ ] 1. REVOGAR — entrar em <onde se gerencia a chave, ex.: painel da conta > Chaves> e apagar/desativar a chave vazada.
[ ] 2. CRIAR NOVA — gerar outra chave, só com as permissões que a tarefa precisa.
[ ] 3. TROCAR — atualizar a chave nova em: <lista de lugares, ex.: agente de e-mail, planilha automática>.
       Quem troca: <você ou o técnico, com telefone>.
[ ] 4. CONFERIR — olhar gasto e histórico de uso dos últimos 30 dias. Algo que não reconheço? <sim/não>
[ ] 5. SENHA — se foi senha de login, trocar e ligar a verificação em duas etapas.
[ ] 6. AVISAR — se dados de clientes podem ter sido acessados, falar com <responsável> (ver módulo 4.3).
[ ] 7. REGISTRAR — anotar o que aconteceu e a menor correção para não repetir.
How to verify: today, open the dashboard for each listed service and find the button to revoke the key. If you can’t find it in two minutes, note the steps once you do—you won’t want to search on the day of a leak.

Quick test (optional): Marcos realizes he pasted the AI service key into a WhatsApp group. What’s the first step?

✂️
Revoke

first, always

🆕
New key

with less access

🔁
Change

everywhere

🔎
Check spending

now and in 7 days

🎓 Module summary

✓
A secret is a password, key, or token — whoever has it logs in as you.
✓
The agent reads the keys file — if it has access to the folder.
✓
The key never appears — neither pasted in by you nor shown by it.
✓
An extension runs with your permissions — who published it, what it asks for, does it really need it?
✓
Did it leak? Revoke it first — then create, change, and check.

Next module:

4.3 — Spending, isolation, and LGPD