2026-10-06 18:26 UTC
DANGMUAAI & Developer Tools, Decoded
BackDev Tools

Your Developers Are Pasting Secrets Into Claude Code and Cursor

GitGuardian says AI-service secret leaks jumped 81% in 2025, and the worst channel is prompt traffic that never touches a git repository at all.

DangMua EditorialOct 06, 20264 min read
Your Developers Are Pasting Secrets Into Claude Code and Cursor

GitGuardian says it detected "over 1.27 million leaked secrets tied to AI services in 2025, an 81% jump from the previous year" — and the channel it considers worst is the one almost nobody scans: the prompt itself.

The figures come from the vendor's own detection data and from its own product pitch, so weigh them accordingly. The mechanism it describes, though, is the part worth checking against your own setup.

The leak that never touches a repo

In the same write-up, GitGuardian reports that "one customer deployed GitGuardian behind their internal AI gateway and surfaced hundreds of secret incidents within weeks, a significant share valid at detection, none of which ever touched a git repository." Those credentials, it says, "went straight from a developer's terminal or IDE into a prompt or a tool call, and out to a third-party model provider."

The behaviour is mundane, which is exactly why repo scanning misses it. The company's examples: "A developer debugs a failing request and pastes the whole curl command, headers included. Someone drops a .env file into a chat window and asks the model to explain a variable. An agent reads a config file and forwards it as context on a tool call."

Two properties make this worse than the equivalent paste into a team chat. First, per GitGuardian, "the content leaves your perimeter immediately. It goes to a third party, under that provider's retention terms, not yours." Second, agents are bulkier than humans: "An agent ships whole files as context. A human question ships a sentence."

GitGuardian also claims AI-assisted code leaked secrets "at roughly twice the GitHub-wide rate" across 2025 — again, its own measurement, on code it can see.

Two places to catch it

The vendor's recommended pattern has two layers, and the analogy to git is the clearest part of it.

Closest to the developer are client-side hooks. GitGuardian says "ggshield AI Hooks scan prompts, tool calls, and tool output inside Cursor, Claude Code, Codex, and VS Code with Copilot, and block the action before it reaches the model." That is the pre-commit equivalent — best remediation experience, but only on machines where you actually deployed it.

Further out sits the AI gateway, the pre-receive equivalent, which sees every request that crosses it including CI agents and batch jobs. The described flow is four steps: the gateway "forwards the payload to GitGuardian's scan API, tagged with your Custom Source UUID," the content is scanned "in memory" and "not stored," run through "600+ detectors," and incidents are created in the dashboard.

One point here is architecturally sound independent of the vendor: a gateway is the only place this traffic is already in cleartext and already yours, and the latency budget is forgiving because a model call already takes seconds.

Blocking or not

The deployment choice is a real trade-off, not a default.

Non-blocking lets the request through and logs the incident. GitGuardian's framing: "The credential reached the provider, so revoke every valid finding. In exchange, you get measurement: two weeks tells you how much you are actually leaking." Blocking rejects the request before the provider is called — "the developer removes the credential and retries. That costs a minute and saves you a rotation."

Its own recommendation is to "start non-blocking to size the problem, then switch once you trust the signal," and to settle how developers report false positives before turning anything on. That sequencing is sensible whoever supplies the scanner: you cannot calibrate a block list against a leak rate you have never measured.

What to do this week

You do not need to buy anything to get the first answer. Ask whether your LLM traffic crosses a gateway you control at all — if every developer holds a provider key directly, there is no chokepoint to scan and no cost attribution either. Then check whether your agent tooling forwards whole files as context, because that is the volume problem the vendor's examples keep returning to.

If both answers are bad, the scanner is the second fix, not the first.

More from DangMua