AI Secrets
Overview
Section titled “Overview”Evidence: AI Secrets
Description: Hunt credentials exposed in AI prompts, responses, tool output, and configs
Category: AI
Platform: macos
Short Name: aisec
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No
Background
Section titled “Background”Developers paste tokens, keys, and credentials into AI prompts. Agents can also echo secrets back or receive them from tool output and config stores. Those findings are a credential-exposure lead, not proof of theft.
Data Collected
Section titled “Data Collected”This collector gathers structured data about redacted credential findings, including detector, category, surface, location, and links back to the originating session or event. Cleartext is not stored in Case.db.
Collection Method
Section titled “Collection Method”This collector reuses the AI artifact scanner and transcript/config parsers. A two-stage detector emits redacted findings with their surface and location. Cleartext is never written to Case.db.
Forensic Value
Section titled “Forensic Value”Reveals secrets a developer pasted into an AI tool, that an agent echoed back, or that a tool returned. Findings link to the originating session, event, and preserved raw source for follow-up.