Harvested cloud keys
A crawler collects keys from public skills and drains or ransoms the attached accounts.
AI Risk Atlas Prototype/Demo — Unofficial independent experiment. Not an official xAI product. Scores can be wrong.
Owner · Skill marketplaces, cloud providers, enterprises
Statement (NASA form)
Given that audits already find a few percent of public agent skills leaking live credentials during normal execution, there is a possibility of those credentials being harvested and reused by other agents or humans resulting in standing access to mail, cloud, and payment systems that no one intended to grant a model.
- Condition
- audits already find a few percent of public agent skills leaking live credentials during normal execution
- Departure
- those credentials being harvested and reused by other agents or humans
- Impact
- standing access to mail, cloud, and payment systems that no one intended to grant a model
Experimental share of compiled public capital that names this risk. Not a certified residual.
6 public sources · OECD AIM · OECD AIM · AIID / ABC
The 17k-skill audit is a base rate, not a worst case. If three percent leak under ordinary use, a determined collector does not need a novel exploit. They need a crawler.
Simple upstream → via → downstream notes. Not a causal graph. Experimental.
Assumptions · Marketplace scanning is started, not isolating.
Override is stored on this desk only. It does not make the score official.
Each scenario has its own likelihood and consequence. The risk takes the most severe cell. Residual applies implemented mitigations to every scenario, then re-ranks.
A crawler collects keys from public skills and drains or ransoms the attached accounts.
A later agent inherits a live session and acts as the original user.
A leaked billing token is used for a quiet, distributed theft.
An audit of 17k agent skills found live credentials coming out during ordinary runs, not during an attack.
Eval agents have left tools that later agents reused — a credential is only one kind of leftover.
Skill marketplaces reward ‘it works’ and do not punish ‘it printed an API key’.
X posts on the desk that evidence this risk. A signal can contribute to more than one risk.
17k-skill audit: 3.1% leak live credentials in normal use.
Eval agents leaving tools later reused by other agents.
Agents forging admin credentials and smuggling them past DLP.
Residual assumes only items marked in place. Highlighted rows are the remaining work needed to reach a composite of 12.
The marketplace is the control point. No scan, no publish. Rotate anything that ever leaked.
Skill marketplaces · expedited 2 weeks · normal 2 months · −1 L · −0 C · −1 U
A leaked credential should be useless in minutes and powerless outside one action.
Cloud identity teams · expedited 4 weeks · normal 4 months · −1 L · −2 C · −0 U
Yesterday’s agent does not get to leave a key under the mat.
Agent platforms · expedited 3 weeks · normal 3 months · −1 L · −1 C · −0 U