Your AI Agents Are Using Your Credentials
Blog post from GitGuardian
AI agents often operate with reused API keys, tokens, and other long-lived credentials rather than distinct, governable identities, creating visibility and accountability gaps that enterprise identity providers may not detect. The risk is growing as developers and citizen developers connect agents to internal systems through configuration files, environment variables, password managers, logs, and automation platforms, while leaked credentials can remain valid for years and enable broad unauthorized access. The recommended approach is to first discover where agent-accessible credentials exist, attribute each credential to an accountable owner, and prevent new exposures while migrating existing ones. Organizations are encouraged to replace standing secrets with agent-specific, delegated, or non-human identities using scoped, short-lived credentials, and to use monitoring mechanisms such as decoy credentials to detect misuse. The text highlights GitGuardian products for endpoint scanning, AI coding-tool checks, credential governance, and prioritizing remediation, while arguing that the longer-term goal should be runtime access models in which agents receive temporary permissions without storing reusable secret values.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 8 | 8,729 | 854 | 211 | -20% |
| Secrets Management | 8 | 2,244 | 480 | 132 | -13% |
| AI Agents | 7 | 5,780 | 1,243 | 245 | -15% |
| Platform Engineering | 5 | 1,191 | 259 | 79 | -17% |
| AI Coding Assistant | 3 | 1,513 | 470 | 139 | -19% |
| Observability | 1 | 3,175 | 737 | 186 | -24% |
| Real-time | 1 | 4,432 | 1,050 | 222 | -31% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.