risk

Credential and secret leakage through AI inputs, outputs, logs and generated code

API keys, tokens, private keys, and connection strings pasted into prompts, returned in outputs, hardcoded in generated code, or captured in conversation logs are exposed to unauthorized parties or persisted outside secret management, enabling account takeover and lateral movement.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

category
ai_governance
domain
  • AI Governance
  • Data Protection & Privacy
  • Cryptography & Key Management
taxonomy
  • owasp-llm-top10-2025
  • nist-ai-rmf-risk
inherent_rating
high

Details

risk_id
ai-secrets-credential-leakage
category
ai_governance
likelihood
medium
impact
high
inherent_rating
high
treatment
mitigate
taxonomies
  • owasp-llm-top10-2025
  • nist-ai-rmf-risk

Source

No record-specific source URL is provided.

Connections