AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to signals
high84% confidenceseed

Audit of 17k agent skills finds 3.1% leaking live credentials during normal execution.

CapabilityDomain knowledgeAffordanceImpact domainCap-adjacent
Quoted from XIhtesham Ali@ihteshamali6 Apr 2026, 15:00

Quoted text

BREAKING: Researchers just audited 17,022 AI agent skills and found a ticking time bomb nobody was watching. 3.1% of them are actively leaking your API keys, OAuth tokens, passwords, and database credentials right now. During normal execution. No hacking required. 73.5% of all vulnerabilities came from a single pattern: console.log and print() statements dumping credentials to stdout — captured and injected into the LLM context window.

Read and engage with the original on X. This desk is not a republication feed.

Analyst rationale

A measured supply-chain failure in the agent-skill ecosystem: secrets printed to stdout become model-accessible facts. No exploit required — just install and run.

Related signals

Contributes to