Generative AI Security: Are Your Developers Pasting Secrets Into LLMs?
TL;DR 81% jump in AI-service leaks : GitGuardian detected over 1.27 million leaked secrets tied to AI services in 2025, an 81% jump from the previous year, with AI-assisted code leaking secrets at roughly twice the GitHub-wide rate. Hundreds of incidents in weeks : One customer deployed GitGuardian behind their internal AI gateway and surfaced hundreds of secret incidents within weeks, a…
The number of leaked secrets tied to AI services jumped 81% in 2025, with GitGuardian detecting over 1.27 million such secrets, compared to an 18% increase across all GitHub repositories. This jump comes as AI-assisted code leaks secrets at roughly twice the rate of traditional code. One customer deployed GitGuardian behind their internal AI gateway and uncovered hundreds of secret incidents in just weeks, all occurring before the secrets ever reached a git repository.
These incidents came from developers pasting curl commands, .env files, and config files into AI prompts or tools without reviewing the full content. While prompt traffic is newer and less covered, secrets detection for code has matured, with tools like ggshield AI Hooks scanning prompts and blocking leaks. However, AI prompts remain a weak spot, needing both pre-commit (AI Hooks) and pre-receive (AI gateway) controls.
AI prompts pose unique challenges: they leave the organization's perimeter immediately, go to a third party with retention terms beyond the organization's control, and are gone as soon as sent unless captured. An internal AI gateway, acting as an LLM proxy or gateway, sees every prompt and response and is the ideal place to scan this traffic.
By forwarding payloads to GitGuardian's scan API and blocking or non-blocking requests based on findings, organizations can measure exposure and enforce security.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.