Your LLM should never see a secret
Keeping a credential out of an LLM's context is necessary but not sufficient. The design I am building toward, the boundary that already holds, and the harder one that is still open: keeping the secret away from code the model can run.