There's ways to make sure env vars get only injected at runtime and arent easily accessible otherwise or to even make them inaccessible to the user your agent is running on, and for you to manually run the code with the right permissions when the keys actually need to be used. Almost nobody bothers doing it though.
Tenoke
https://svilentodorov.xyz/
sviltodorov[at]gmail.com
https://twitter.com/Tenoke_
Posts97
Comments1,868