Home / Companies / Sonar / Blog / Post Details
Content Deep Dive

Your secrets are leaking to AI coding agents (and how to stop it)

Blog post from Sonar

Post Details
Company
Date Published
Author
Taylor Luttrell-Williams
Word Count
1,010
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

AI coding agents can improve development productivity by reading project files, configurations, terminal errors, and other context, but this broad access can inadvertently expose credentials stored in files such as .env or pasted into prompts. Secrets sent as agent context may be retained in model-provider and intermediary gateway logs, making them difficult to locate or remove even after keys are rotated. The risk is compounded by supply-chain attacks designed to exploit agent sessions and collect environment variables, cloud credentials, SSH files, database strings, and wallet data, while leaked repository secrets can remain unremediated for months. The text argues that secret detection should occur locally and independently of the AI model at multiple stages, including while developers type, before commits, before agents read files or submit prompts, and during pull-request review. It presents SonarQube’s IDE, CLI, agent plugins, Cloud, and Server offerings as a layered scanning approach that identifies secret patterns, blocks exposed data before it reaches models, and enforces repository-level quality gates.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 13 1,985 445 125 -23%
AI Coding Assistant 5 1,400 436 132 -25%
Zero Trust 1 194 58 26 -23%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.