Dogfooded daily in this monorepo. No .env files were harmed.
ax
ax CLI preview — real usage via your terminal or MCP
THE INVISIBLE CRISIS
Your agents can read everything.
Cursor, Claude Code, Aider — they have full filesystem access. They autocomplete your Stripe keys. They leak them in prompts. .env files were never designed for this world. dotenvx helps, but agents still get the keys eventually.
Prompt injection = instant exfil
One bad webpage or RAG doc and the agent happily dumps every secret it can access.
Worktrees multiply the disaster
New worktree? Copy every .env again. Share with coworker? Slack the keys. Per-env? Pure chaos.