A cross-session leak · step by step

AgentSaw is cross-session security for AI coding agents. Here's the leak it's built to catch.

Your secret, read in one session.
Leaked in another.

One coding session reads one of your secrets. A later session, days apart, sometimes a different agent entirely, writes it into a public doc. Each step is in policy, so your scanners, DLP and EDR see nothing. AgentSaw follows the value across sessions and agents, and catches the leak none of them can connect.

5
In-policy steps,
all approved
0
Alerts raised
by your stack
14 mo
That AWS key
stays valid
4,200
People who can
now read it
3 days
From secret read
to public leak
Watch it happen

Three cross-session leaks, caught.

Each one: a value read by one AI coding agent, found and shipped out by another in a later session, and the AgentSaw timeline and alert that connect them. The story's on screen, no sound needed.

Live credential → internal wikiA live AWS key, published where 4,200 people can read it
0:00 / 0:58
Customer PII → public API docsClaude Code pulls prod data · Codex bakes it into Swagger
0:00 / 0:58
Unannounced launch → customer emailA confidential codename, emailed to 4,000+ subscribers
0:00 / 0:58

Tip: scrub anywhere on the timeline to re-read a step — ← / → skip 5s, and the button slows playback down for reading.

How a leak happens, step by step

Every step is ordinary agent behavior.

No exploit, no jailbreak, no rogue tool, just ordinary agent actions, across two sessions and two agents, three days apart.

  1. Pre-existingTeam rule · every agentApproved

    A shared rule that every agent on the team follows (Cursor, Claude Code, Codex), copied months ago from a popular best-practices template: "save the values you use to a notes file, so the next session doesn't have to look them up again." It sounds helpful. It's the setup.

  2. Mon · 09:14CursorApproved

    "The app won't connect, get it running." To debug, the agent reads your project config, like it does in every repo. It now holds your live database password and cloud keys. Nobody asked it to collect anything; it's just doing the job.

  3. Mon · 09:15CursorApproved

    Following that rule, it saves the values it just used into its notes. No instruction ever said steal this. It said remember it.

  4. Mon · 11:02CursorApproved

    "Add logging so we can debug the staging connection." The connection fails, and the log line prints the full connection string, password and all, into the test logs. Standard debugging.

  5. Thu · 16:40Claude CodeLeaked

    "Write the new-engineer setup guide from our notes." A different session, a different agent. A setup guide is supposed to show how to connect, so the agent fills in the real values instead of placeholders and publishes it to the internal wiki. No repo, no commit, nothing for code scanners to catch.

What ends up public
wiki.acme.internal/engineering/backend-setup 4,200 can view · + AI assistant

Backend Service: Local Setup

Space: Engineering · last edited by claude-code-bot · indexed by acme-gpt
DATABASE_URL=postgres://app:Pr0d-R3plica@db.acme.internal:5432/mainILLUSTRATIVE
AWS_ACCESS_KEY_ID=AKIA4XQ7H2L9DEXAMPLEILLUSTRATIVE
AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEILLUSTRATIVE
› run make dev and you're up.
A setup guide is supposed to show how to connect, so the agent used the real values. And because the wiki feeds your internal AI assistant, anyone can now get your production secrets by asking the chatbot a question.
Why your current tools miss it

You bought a control for every layer. The exposure lives between them.

Your device tools watch the device. Your AI tools watch the prompt. Your data tools watch what leaves as a file. Each step was in policy on its own. The leak only shows up when you connect all of them.
What AgentSaw sees

The moment a session reads a secret, AgentSaw marks it as a real credential and follows it through the notes file, the logs, wherever it goes. When another session, or a different agent, later writes that same secret toward the wiki, AgentSaw recognizes it and raises a critical alert before the page publishes. It follows the value itself, across every session and agent.

And it was never just one secret. That notes file, re-read every session, has quietly collected the rest of your secrets over weeks.

Design-partner program · now onboarding

One developer task. Two sessions, two agents. Three days.
One timeline.

We're working with a small group of teams that lean on AI coding agents every day, to catch these leaks before they ship. If that's you, let's talk.

Tamir Magnezi
Co-founder & CEO · LinkedIn
Reli Magnezi
Co-founder & CPO · LinkedIn
20 minutes · local install · no procurement · free for design partners