Research Reveals: Public AI Agent Trajectories Leak Over 315k Secrets
matthew_d_green · x · 2026-08-11
Researchers scraped public AI agent trajectories from GitHub and Hugging Face, successfully decoding 315,320 reasoning blocks.
Although the visible text was sanitized, the underlying reasoning processes still exposed sensitive credentials and data, including API keys, passwords, access tokens, and personal emails.
More from coding & agent
- Viral Claude Code Skill Decompiles Android APKs to Extract APIs — tom_doerr · 2026-08-11
- Agent Swarms Turn pass@k into pass@1: OpenAI Security Incident Post-Mortem — ricklamers · 2026-08-11
- Kill Image Subscriptions: A Claude Skill to Use GPT Image 2 at 6x Lower Cost — PrajwalTomar_ · 2026-08-11
- Developer Hands Over Twitter Account to an Autonomous RL Agent During Vacation — ben_burtenshaw · 2026-08-11
- Osseus (YC S26) Launches Agentic Platform to 10x Robot Development — ycombinator · 2026-08-11
- Real Bill Comparison: Claude Code Costs $6.7k/mo, 18x More Than Codex — iannuttall · 2026-08-11