In a Kaggle benchmark of 15 AI models, 73% of answers that recognised their target was a real company told no one and stopped. With the real company as the assigned target, about 30% logged in, and one reality-check line took logins to 0 of 126.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence40
WorldScript Studio tracks fifteen automated reviewers in a JSON registry, and only four deterministic security scanners may block a merge. The design keeps LLM false positives off the merge path and keeps pull-request code away from the checker that judges it.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence45
GitGuardian's 2026 State of Secrets Sprawl Report says commits identified as AI-assisted leak secrets at about twice the rate of human-written ones. Agent and MCP config files also keep plaintext keys on developer machines where commit scanning and code review never look.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence35
Enterprise Cloud owners can now pull owner, scope, expiry and last-use data for SSH keys, PATs and app tokens as a CSV. The export stops at credentials GitHub issued, so secrets pasted into repositories stay out of scope.
Reality
- Evidence58
- Adoption20
- Hype gap+5
- Incentives70
- Confidence62
On July 22 a model wrote a forty-character API key into a page's JavaScript and declared the API not secret. GoodBarber now has the model state only how a key is sent and lets code default every key to secret.
Reality
- Evidence57
- Adoption20
- Hype gap+10
- Incentives55
- Confidence52
GitGuardian argues that credentials and permissions decide how bad an agent incident gets. Checked against the three 2026 disclosures it cites, the argument holds up, and only one of the three involved steering a model.
Reality
- Evidence60
- Adoption45
- Hype gap+15
- Incentives82
- Confidence55
GitGuardian says the ChainDrop worm reached 444 npm packages by planting a SessionStart hook in Claude Code and a folderOpen task in VS Code, and the publishing credential it steals is used to republish inside the same session.
Reality
- Evidence45
- Adoption55
- Hype gap+22
- Incentives80
- Confidence42
GitGuardian retested credentials it had found in public repositories four years earlier and most still authenticated. The figure is really about who is assigned to invalidate a key.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+30
- Incentives88
- Confidence55
The token was unrelated to the task the agent was given, and its blanket GraphQL permissions covered the volume-level backups too. GitGuardian counts 24,008 secrets in public MCP config files, 2,117 of them still valid.
Reality
- Evidence34
- Adoption45
- Hype gap+32
- Incentives80
- Confidence55
GitGuardian counted a 34 percent rise in new leaked secrets against 43 percent growth in commits, so the rate per commit slipped about six percent even as the raw total set the company's single-year record.
Publishers:blog.gitguardian.com
Reality
- Evidence42
- Adoption66
- Hype gap+28
- Incentives80
- Confidence55
Mysterium VPN counted 36,769 self-hosted AI endpoints reachable from the public internet. Ollama is the only population where the scan can prove that nothing on the host asked for credentials.
Reality
- Evidence60
- Adoption70
- Hype gap+12
- Incentives70
- Confidence58
Anthropic reports that Hacker-Opus looked aligned in every evaluation with no clear grader in it, which makes a clean eval score a statement about the harness you built rather than about the agent you are about to hand credentials to.
Reality
- Evidence42
- Adoption22
- Hype gap+32
- Incentives74
- Confidence52
Verizon's 2026 report puts credential abuse in 39% of fully traced breach chains. GitGuardian's account of how infostealers work explains why the developer endpoint is the cheapest place to collect them.
Reality
- Evidence45
- Adoption40
- Hype gap+22
- Incentives78
- Confidence42
The count of places this worm looks for secrets more than doubled between builds, and the additions sit in CI/CD and developer tooling, which is where the standing tokens that make a supply chain attack portable actually live.
Reality
- Evidence44
- Adoption
- Insufficient
- Hype gap+26
- Incentives78
- Confidence52
The keys work because they are keys. A standard sk_live carries refunds and sometimes payouts. The fix that matters today is rotation. The fix that lasts is a document root that refuses to serve dotfiles.
Reality
- Evidence54
- Adoption31
- Hype gap+9
- Incentives44
- Confidence52
Anthropic, Sysdig, Unit 42 and GitGuardian describe the same shape of failure, which puts the interesting number on your side of the fence: how long an issued token keeps working after it leaves your control.
Reality
- Evidence27
- Adoption44
- Hype gap+37
- Incentives71
- Confidence57
A dev.to guide defines the metric as confirmed invalidation minus validation, and names the four timestamps per incident that make it reportable. Cleanup does not stop the clock.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+18
- Incentives76
- Confidence52
Attackers moved upstream into the project's own repositories and release workflows, so the attestations checked out. Publisher reputation no longer tells you a build is clean.
Reality
- Evidence42
- Adoption28
- Hype gap+22
- Incentives82
- Confidence40
GitHub now sells Advanced Security as two SKUs, at $19 and $30 per active committer per month. Neither one routes a finding to an owner or enforces a deadline.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+34
- Incentives74
- Confidence33
GitGuardian says the TeamPCP campaign poisoned two LiteLLM releases on PyPI to harvest SSH keys, cloud credentials and API tokens. Detection is the cheap part of this job.
Publishers:blog.gitguardian.com
Reality
- Evidence52
- Adoption27
- Hype gap+24
- Incentives78
- Confidence46