---
title: "Secrets do not belong in the process list"
description: "How to automate the handling of keys and credentials without exposing them along the way."
canonical: "https://simosphereai.com/en/field-reports/secrets-out-of-the-process-list"
lang: en
---

# Secrets do not belong in the process list

How to automate the handling of keys and credentials without exposing them along the way.

- Published: 2026-10-06
- Updated: 2026-10-06
- Status: praxis
- Publisher: SIMO GmbH

## Starting question

How do we automate the handling of keys and credentials without exposing them?

## Result: works

Works through the API with input passed via standard input. As an argument, keys would have shown up in the process list.

Through the API designed for machines, passing secrets via standard input. A command-line argument would be visible in the process list and the shell history. A finding like this is a reason to check similar scripts deliberately.

## What we experienced

While automating a secrets vault, passing the value through standard input failed. The tool only knows two ways: interactive input or a command-line argument. The argument would have been visible in the process list and the shell history.

A review found the same weakness in a second script. The fix was the direct programming interface, with the value passed through standard input.

## What it means for business architecture

Security tools are built for people or for machines, rarely for both. Automation needs the route designed for machines.

## Lessons learned

- Familiar patterns from other tools do not apply everywhere. Assumptions need checking.
- One finding is a reason to check similar places on purpose.
- A leak without symptoms is still a leak.

Rendered version: https://simosphereai.com/en/field-reports/secrets-out-of-the-process-list
