dayzero.run Blogs
News 8 October 2026

The key that must never reach the browser.

Claude Code 2.1.292 spent 6 October closing holes in its own sandbox. The lesson for a published page is older than that release, and easier to get wrong when an agent is writing the HTML.

What shipped

Version 2.1.292 added an effort setting on the Agent tool, so a parent session can ask for a lighter sub-agent on a simple search and a heavier one on a hard edit. It also added a shorter path for installing a plugin from a marketplace. The security notes are the part worth reading slowly.

The release closed several ways a command could slip past the permission check. One of them involved network paths, the Windows-style UNC form, skipping the file-read prompt. Others involved staged upload copies, a tampered settings cache, and delete commands written with alternate path spellings so they no longer looked like rm of a home folder. A hotfix, 2.1.291, had landed the same day to repair regressions from the releases just before.

If you let an agent run while you are away from the desk, that changelog is the weekly reminder. The sandbox is a product that changes. Read the permission notes before you trust an unattended session with a folder that contains secrets.

Two different keys

A published page has a quieter version of the same mistake. Agents like to “make the form work” by pasting whatever credential they can see into the frontend. There are two kinds of keys, and they do not have the same job.

If the page only needs to store a waitlist email, the browser key is the one that goes in the JavaScript. The account token stays on your machine. Mixing them up means anyone who can view source can act as you.

A two-minute check

Before you send the link, search the folder you are about to publish. Include the built output, not only the source. Agents often inject the secret at build time.

  1. Search for the account token, for Bearer, and for any variable named TOKEN, SECRET, or API_KEY inside index.html and the script files next to it.
  2. Confirm the value in the page is the public project key, and that the requests it makes are the ones a visitor should be allowed to make. Saving a row is reasonable. Changing the table definition is not.
  3. If a secret did land in the files, rotate it. Removing the line from the next deploy does not undo the copy already on someone else’s screen.
A rule you can paste into the agent brief. Never put an account token, password, or dashboard session in frontend code. A public project key may go in the page. Schema changes happen from the terminal, not from the browser.

Effort settings do not replace this

The new effort dial is a cost and quality control. It does not decide which secrets are safe to publish. A cheap sub-agent can still copy a token into a script if the brief is vague and the token is sitting in the chat. Tell the agent which key is public. Then check the built files yourself. The sandbox vendors are closing their holes. The hole in a page you already shipped is yours to close.