Skip to main content
API keys, tokens, or passwords hardcoded in agent source or config files

How to resolve

Load credentials from environment variables or a secrets manager (e.g., AWS Secrets Manager, HashiCorp Vault). Never store API keys, tokens, or passwords in source code.

Risk

Governance/Compliance This vulnerability falls under ASI03:2026 — Identity and Privilege Abuse in the OWASP Top 10 for Agentic Applications. Agents inherit, reuse, or escalate identities and credentials beyond their functional scope. Security API keys, tokens, or passwords hardcoded in agent source or config files. If exploited, this can compromise the agent’s integrity, confidentiality, or availability, potentially affecting downstream systems and data.

Explanation

API keys, tokens, or passwords hardcoded in agent source or config files. This falls under ASI03 (Identity and Privilege Abuse): Agents inherit, reuse, or escalate identities and credentials beyond their functional scope.

Specifications

Trigger
  • Agent scan detects aPI keys, tokens, or passwords hardcoded in agent source or config files
The scanner looks for patterns such as:
  • api_key= literal string assignment
  • OPENAI_API_KEY = ’…’ hardcoded
  • sk- prefix in source file
  • password or secret literal in config
Severity
  • CRITICAL
Applies to: Agent