I have gotten a lot of responses to this with "use the CLI" or something something.
Here is the deal. An LLM or harness should never ever have access to your password. Ever. The way this works is that there is a proxy layer that sits outside your harness and injects the password into any network or API call that needs it. You treat the harness as untrusted.
@Muse does this right