Understand what a secret is
In this course, secret is anything that proves to a system that “it’s me”: your email password, an AI service key, the code that connects the agent to your spreadsheet.
Whoever has the secret gets in as you. They don't need to know your name, your bank password, or where the clinic is. The secret alone is enough.
🆕 New here? Four words you’ll see in the settings
- API — the “back door” a program uses to talk to another, without a screen or button. When the agent sends an email through Gmail, it uses the Gmail API.
- API key — a long sequence of letters and numbers that opens this door. It works like a password, and is almost always linked to a credit card.
- Token — a temporary key, given after you click “allow.” It’s valid until someone revokes it or it expires.
- Secret — the name we use for all three: password, key, and token.
How to read the diagram: The box on the left says "you or someone else" on purpose. The three doors on the right open for anyone who presents the secret in the middle, without checking who they are. That’s why a leaked secret is as good as your login.
proof that "it's me"
door between programs
key with an expiration date
if it leaks, someone spends it
Know that the agent can see configuration files
When someone installs an agent on a computer or server, the keys are usually stored in a configuration file. The most common one is called .env (pronounced "dot env").
The point is this: if the agent has access to the folder, it can read the key file like it reads anything else. And if someone asks — you by accident, or a hidden instruction — it can show the contents on screen.
How to read the diagram: the four blue arrows leave the agent and reach every file—there's no "forbidden" arrow. The amber file is the key file. Notice that the example uses SUA_CHAVE_AQUI: a real key should never appear in any material, screenshot, or conversation.
💡 Question for the person who installed it
If a technician or vendor installed your agent, ask: "where are the keys stored?", "can the agent read this file?" and "is it allowed to show the contents?" Three questions, five minutes. A good answer is: the keys are stored in a separate vault, and the agent can’t print them.
key file
applies to everything inside
separate place for keys
displaying it on screen is leaking it
Follow the rule: the key is never printed or pasted into chat
Everything you write in an AI chat stays in the conversation history. Anyone who opens your account can read it, it can end up in a screenshot, or it can appear in a summary. A secret pasted into the chat becomes part of the chat.
The rule applies both ways: you don’t paste the key, and the agent doesn’t show the key. Not “just to check,” not “just the first few digits.”
✗ What Marcos almost did
- ✗“Log in to the invoicing portal with this username and password [password here] and issue the invoice.”
- ✗The password stays in the history, within reach of anyone who opens the conversation.
- ✗If the agent is tricked by a hidden instruction, it’s already there.
✓ How it did it
- ✓“I’ll log in to the portal. Give me the steps to issue this client’s invoice.”
- ✓AI helps in the same way. He enters the password on the portal.
- ✓The history keeps the step-by-step process, not the password.
Paste into your agent's fixed instructions, along with the rule "outside text is data" from module 4.1.
REGRA: SEGREDOS 1. Nunca me peça senha, chave de API, token ou código de verificação. Se precisar de um acesso, diga qual e eu configuro fora do chat. 2. Nunca mostre, copie, resuma ou repita o conteúdo de arquivos de configuração (.env e parecidos), nem em parte, nem "só para conferir". 3. Se você encontrar algo que pareça um segredo em qualquer texto, escreva [SEGREDO OCULTO] no lugar e me avise. 4. Se eu mesmo colar um segredo aqui por engano, me alerte na hora e não o repita na resposta.
stores everything that comes in
you type it on the website
not even “just the beginning”
what it writes instead
Be wary of third-party extensions, plugins, and “skills”
A browser extension, chat plugin, “skill,” or “app” installed in the agent: the names change, but the idea is the same. It’s a piece of software made by someone else that then run with your permissions.
If your agent can read your email, the extension installed in it can too. If it can see the key file, the extension can see it too. You’re not installing a tool; you’re hiring a stranger to work inside your office.
| The “PDF Summarizer” asks… | Does it match the promise? | Renata’s decision |
|---|---|---|
| Read the files you open | Yes—summarizing requires reading. | okay |
| Read and send emails on your behalf | No—summarizing doesn’t send anything. | refuse |
| View and change your schedule | No—nothing to do with PDF. | refuse |
| Access to “all sites” | No—it can view your online banking. | refuse |
What to look for in the table: compare each row in the middle column with the extension’s promise. A request that doesn’t fit is reason enough not to install it — you don’t need to find out why. Renata passed on this one and found another that asked for only the first row.
⚠️ Attention
A good extension today can change tomorrow: the owner sells it, an update arrives automatically, and it starts asking for more. Once a month, open the list of extensions and connected apps and remove anything you haven't used.
third-party program
it inherits everything
it has to be agreed on
can change on its own
Check before installing
Before clicking "install" or "allow," ask yourself three questions: who published it?, what does it ask for? e do I really need to?. It takes two minutes and prevents most problems.
The third question is the one most people skip. Many extensions solve something the AI chat itself can already do without installing anything.
✓ Signs that it's safe to install
- ✓The app's own company published it, or someone you know did.
- ✓Asks only for what the promise requires.
- ✓Solves something you do every week.
- ✓You can uninstall it and revoke access with one click.
✗ Signs that it shouldn't
- ✗Unknown author, no website, no contact information.
- ✗Asks for "all websites," "send on your behalf," or "manage payments" without a reason.
- ✗Asks you to paste an API key into its configuration.
- ✗It came through a group link with "install quickly, it's free."
Who published it?
Click the author's name. Do they have a website, contact information, or other well-known extensions? If you can't find anything in a minute, stop here.
What does it ask?
Read the entire permissions list, as Renata did. Every line must match the promise.
Do I really need to?
Try doing the same task in the chat you already use, without installing anything. If it works, don’t install anything.
💡 Practical tip
If you want to test an extension, try it in a separate browser profile, without signing in to your business email or bank. If it behaves well for a week, then move it to your main profile.
does it have a name and contact information?
line by line
doesn’t chat already do that?
away from real accounts
Know what to do if a key is leaked
It leaked when the secret appeared where it shouldn't: pasted into a chat, in a screenshot sent to the group, in a shared file, on screen during a call. It doesn't matter if "nobody saw it."
Delete the message doesn’t solve it: the copy may already be somewhere else. What works is making that key useless. The order matters—revoke it first, then clean up.
How to read the diagram: read from left to right. The glowing box is the only one that can’t wait: while the old key works, whoever has it can use it. Steps 2 and 3 get the business back up and running; step 4 shows whether anyone used it.
Copy this into a fixed business document (or print it). Fill in what's between < > today, at your own pace.
CHECKLIST DE VAZAMENTO DE SEGREDO — <nome do negócio>
Qual segredo vazou: <ex.: chave do serviço de IA / senha do e-mail>
Onde apareceu: <ex.: colado no chat, print no grupo>
Data e hora: <____>
[ ] 1. REVOGAR — entrar em <onde se gerencia a chave, ex.: painel da conta > Chaves> e apagar/desativar a chave vazada.
[ ] 2. CRIAR NOVA — gerar outra chave, só com as permissões que a tarefa precisa.
[ ] 3. TROCAR — atualizar a chave nova em: <lista de lugares, ex.: agente de e-mail, planilha automática>.
Quem troca: <você ou o técnico, com telefone>.
[ ] 4. CONFERIR — olhar gasto e histórico de uso dos últimos 30 dias. Algo que não reconheço? <sim/não>
[ ] 5. SENHA — se foi senha de login, trocar e ligar a verificação em duas etapas.
[ ] 6. AVISAR — se dados de clientes podem ter sido acessados, falar com <responsável> (ver módulo 4.3).
[ ] 7. REGISTRAR — anotar o que aconteceu e a menor correção para não repetir.
Quick test (optional): Marcos realizes he pasted the AI service key into a WhatsApp group. What’s the first step?
first, always
with less access
everywhere
now and in 7 days
🎓 Module summary
Next module:
4.3 — Spending, isolation, and LGPD