Protect your account, credentials, workspaces, and connected services when using Qoder CN.
Qoder CN can work with local code, installed extensions, remote connections, and external services. Use the following checks to keep the account and data scope clear before a task begins and before its result is shared.
Do not paste passwords, API keys, access tokens, private keys, or production connection strings into task instructions. Use the authentication flow or environment mechanism supported by the service.
If a credential appears in a file, task output, screenshot, or exported record, remove it from shared artifacts and rotate it through the issuing service.
Before installing or importing a Skill, Plugin, or Connector:
Inspect generated code, commands, files, screenshots, and exported task records before sharing them. Remove customer data, internal addresses, repository details, and credentials that are not required by the recipient.
Use Code security to scan code changes for security risks. Security scans help review code, while account, credential, and external-service authorization still require separate checks.
Stop the task, disconnect the affected service, and rotate exposed credentials. Preserve the relevant time, task, error, and service logs without copying secrets into a report. Contact the account or organization administrator when access may have crossed the intended boundary.
Protect your account and device
- Sign in only on devices you control, and sign out before handing a device to another person.
- Keep Qoder CN and the operating system updated.
- Lock the device when unattended. A running task can continue to use resources available on that device.
- Review the account shown under Settings → Profile before working with organization data.
Keep credentials out of tasks
Do not paste passwords, API keys, access tokens, private keys, or production connection strings into task instructions. Use the authentication flow or environment mechanism supported by the service.
If a credential appears in a file, task output, screenshot, or exported record, remove it from shared artifacts and rotate it through the issuing service.
Review extensions and connections
Before installing or importing a Skill, Plugin, or Connector:
- Confirm the publisher and intended capability.
- Review scripts, Hooks, commands, endpoints, and external dependencies.
- Check which account and workspace an external service will access.
- Test with a small read-only operation.
- Remove the extension or revoke its authorization when it is no longer needed.
~/.qoder/settings.json.