Study: AI agent "skills" leak credentials at scale
A 2026 empirical study analyzed 17,022 AI agent skills and found 520 of them carrying 1,708 security issues. Debug logging was the leading vector (~73.5% of issues), with secrets landing in logs and the model's context window, and ~92.5% of leaks occurring during routine execution with no exploit required.
- Of 17,022 agent skills, 520 carried 1,708 security issues
- About 73.5% of vulnerabilities stem from debug logging of secrets
- 89.6% of leaked credentials were immediately exploitable
- Secrets removed from 107 repos persisted across 50+ forks
Read next
Security