GitGuardian Deploys AI Agents to Tackle 1.27M Exposed Credentials in Public Code

Exposed credentials in public code surged 81% to 1.27 million last year, driven largely by AI-assisted development spreading secrets across source code, CI/CD pipelines, and AI tool configuration files. GitGuardian found that 64% of secrets it confirmed valid in 2022 were still unrevoked as of January 2026, highlighting how long leaked credentials remain exploitable. To address the growing triage burden, GitGuardian has added two AI agents to its Public Secrets Monitoring product, covering incidents across GitHub and Docker Hub. A triage agent performs an initial assessment of each incident, escalating stronger candidates to a deeper analysis agent that returns an organizational verdict, a risk score, and visible reasoning. New workspaces receive the feature by default, with a gradual rollout to existing ones, while human reviewers retain final oversight of every incident.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in