a9a8a3fa2e
`hermes config get providers`, `config get providers.<p>.api_key`, `config get <PROVIDER>_API_KEY` (the .env-routed branch) and `config get mcp_servers.<s>.env.X_API_KEY` all printed the full credential. The agent runs this command from sessions whose transcripts persist and get forwarded (a Gemini key surfaced in a Discord DM log), so `print` output is a leak path the logging redactor never sees. `get_config_value` now applies the structural masker used by `config show` before printing, honouring `security.redact_secrets` (default on), with a `--raw` flag for operators/scripts that need the real value. `_is_secret_config_key` extends the exact-name set with the same `*_API_KEY / *_TOKEN / *_SECRET / *_PASSWORD` suffixes `_is_env_config_key` already routes to .env, so env-map leaves under `mcp_servers.*.env` mask too, and the `config set` echo uses the same predicate. Slim redo of #84153 by @webtecnica (same direction: mask in get_config_value; dropped the redact_url_query_params re-export and the separate redaction-enabled reader in favour of agent.redact._redact_enabled, which already resolves the profile-scoped policy). Fixes #110758 Fixes #84106