The agent process holds no secrets
Credentials are encrypted at rest in the proxy and referenced by name in team sheets, logs, and errors. The proxy injects them into the outbound call and scrubs known secret values out of the result before it crosses back. Compromise the agent — prompt injection, a bad skill, a misbehaving model — and you get zero credentials.