AI洩漏機密評測:GitGuardian報告寫code風險翻倍 | AI Secrets Leak Review: GitGuardian Finds 2x Risk
By Kit 小克 | AI Tool Observer | 2026-10-02
🇹🇼 AI洩漏機密評測:GitGuardian報告寫code風險翻倍
AI洩漏機密的問題,現在有了具體數字佐證。資安公司 GitGuardian 發布的《2026 機密外洩現況報告》指出,2025 年全球公開 GitHub commit 中新偵測到的機密(API Key、密碼、Token)高達 2865 萬筆,年增 34%,創下該報告 2021 年發布以來最高紀錄。更值得開發者注意的是:用 Claude Code 等 AI 編碼工具輔助寫出來的 commit,洩漏機密的機率是一般人工 commit 的兩倍。
GitGuardian報告:洩漏規模有多大
報告指出幾個關鍵數字:
- 2025 年新增洩漏機密 2865 萬筆,比 2024 年多 34%
- 自 2021 年以來,洩漏機密總量成長 152%,但開發者人數只成長 98%——換句話說,洩漏速度比開發者成長速度快了 1.6 倍
- AI 服務相關的憑證洩漏年增 81%,單一年就暴增超過 127 萬筆,是所有類別中成長最快的
為什麼AI寫code特別容易洩漏機密
GitGuardian 的數據顯示,Claude Code 輔助的公開 commit,洩漏機密的比例大約是基準值的兩倍。原因不難想像:AI 編碼代理為了快速跑通測試,常常直接把範例金鑰、資料庫連線字串寫進程式碼;開發者在快速編碼的節奏下,少了人工 code review 那道把關,環境變數和設定檔就這樣被一起 commit 上去。報告也提到,這個落差在 Claude Sonnet 4.5 推出後的 2025 年 9 月左右開始收斂,顯示廠商也在調整模型行為,但風險仍然存在。
MCP設定檔是新破口
這次報告特別點名 MCP(Model Context Protocol)設定檔是新的高風險區域,因為開發者常把 API Key 直接寫死在 JSON 設定檔裡面,而不是引用環境變數。最常洩漏的機密類型依序是:
- Google API Key(佔 19.2%)
- PostgreSQL 資料庫連線字串(14%)
- Firecrawl API Key(11.9%)
- Perplexity.ai API Key(11.2%)
- Brave Search API Key(11%)
開發者該怎麼辦:實際防護建議
- MCP 設定檔一律用環境變數引用,不要把真實金鑰寫進 JSON 範例或 commit 裡
- 在 repo 裝 pre-commit 掃描工具(如 gitleaks 或 GitGuardian 自家的 ggshield),在 commit 前就擋下機密
- 發現洩漏後第一件事是立刻撤銷並輪替金鑰,不要只刪 commit——git 歷史還是找得到
- 用 AI 工具生成的程式碼,把「有沒有硬寫金鑰」當成 code review 的固定檢查項目,不要假設 AI 會自己避開
這份報告沒有要你別用 AI 寫程式——Claude Code、Cursor 這類工具的生產力提升是真實的。但「AI 幫你寫得快」不等於「AI 幫你寫得安全」,機密管理這塊,終究還是要靠人為流程補上。
好不好用,試了才知道。
🇺🇸 AI Secrets Leak Review: GitGuardian Finds 2x Risk
AI secrets leak risk now has hard numbers behind it. Security firm GitGuardian’s State of Secrets Sprawl 2026 report found that 28.65 million new secrets (API keys, passwords, tokens) were detected in public GitHub commits in 2025 — a 34% year-over-year jump and the highest ever recorded since the report launched in 2021. The number that should worry developers most: public commits assisted by Claude Code leak secrets at roughly twice the baseline rate of ordinary human commits.
GitGuardian's Report: How Big Is the Problem
Key figures from the report:
- 28.65 million new secrets leaked in 2025, up 34% from 2024
- Since 2021, leaked secrets have grown 152% while the developer population grew only 98% — meaning secrets are leaking 1.6x faster than the developer population is growing
- AI-service credential leaks grew 81% year-over-year, with over 1.27 million exposed in a single year — the fastest-growing category by far
Why AI Coding Tools Leak More Secrets
GitGuardian's data shows that public commits co-authored by Claude Code leak secrets at about 2x the baseline rate. The reason isn't mysterious: coding agents optimizing for a quick working build often hardcode sample keys and database connection strings directly into code, and the speed of AI-assisted coding removes the manual review step that used to catch committed env files and config secrets. The report notes this gap started narrowing around September 2025, after Claude Sonnet 4.5 shipped — suggesting vendors are adjusting model behavior, though the risk hasn't gone away.
MCP Config Files: The New Weak Point
The report specifically flags MCP (Model Context Protocol) config files as a new high-risk surface, since developers frequently hardcode API keys directly into JSON config instead of referencing environment variables. The most commonly leaked secret types in MCP configs:
- Google API Keys (19.2%)
- PostgreSQL connection strings (14%)
- Firecrawl API Keys (11.9%)
- Perplexity.ai API Keys (11.2%)
- Brave Search API Keys (11%)
What Developers Should Actually Do
- Always reference environment variables in MCP config files — never hardcode real keys in JSON examples or commits
- Add pre-commit scanning (gitleaks or GitGuardian's own ggshield) to catch secrets before they ever get committed
- If a secret leaks, revoke and rotate it immediately — deleting the commit isn't enough, it's still in git history
- Make "did the AI hardcode a key" a standard item in code review for AI-generated code — don't assume the model will avoid it on its own
This isn't a case against AI coding tools — the productivity gains from Claude Code, Cursor, and similar tools are real. But faster code isn't the same as safer code. Secrets management still needs a human process backstop.
You won't know until you try it.
Sources / 資料來源
- GitGuardian: State of Secrets Sprawl 2026
- SC World: AI coding assistants twice as likely to leak secrets
- DEV Community: 29 Million Secrets Leaked on GitHub Last Year
延伸閱讀 / Related Articles
- Moonshot AI蒸餾風波評測:OpenAI控Kimi抄襲推理鏈 | Moonshot AI Review: OpenAI Accuses Kimi of Copying
- Codex Agent失控評測:一句提示燒掉7.8萬美元 | Codex Agent Runaway Review: One Prompt, $78K Gone
- Oracle AI裁員評測:砸557億美元基建,仍裁員2.1萬人 | Oracle AI Layoffs Review: $55.7B Infra Bet, 21K Cut
AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends
留言
張貼留言