Three leaks, on camera

Watch a leak happen.

Nobody attacks anything. Every step is allowed. That is why nothing else flags it.

An agent reads something private to do a job it was asked to do. A later session finds it and sends it somewhere open. Sixty seconds each, no sound needed. AgentSaw is the only thing in the room that connects the two.

Live credential → internal wikiA live AWS key, published where 4,200 people can read it
0:00 / 0:58
Two more, same shape

Different data. Same ending.

Customer records into public API docs, and an unannounced launch name into an outside email. Different agents, different destinations, the same handoff underneath.

Customer PII → public API docsClaude Code pulls prod data · Codex bakes it into Swagger
0:00 / 0:58
Unannounced launch → customer emailA confidential codename, emailed to 4,000+ subscribers
0:00 / 0:58
How a leak happens, step by step

Every step is ordinary agent behavior.

No exploit, no jailbreak, no rogue tool, just ordinary agent actions, across two sessions and two agents, three days apart.

  1. Pre-existingTeam rule · every agentApproved

    A shared rule that every agent on the team follows (Cursor, Claude Code, Codex), copied months ago from a popular best-practices template: "save the values you use to a notes file, so the next session doesn't have to look them up again." It sounds helpful. It's the setup.

  2. Mon · 09:14CursorApproved

    "The app won't connect, get it running." To debug, the agent reads your project config, like it does in every repo. It now holds your live database password and cloud keys. Nobody asked it to collect anything; it's just doing the job.

  3. Mon · 09:15CursorApproved

    Following that rule, it saves the values it just used into its notes. No instruction ever said steal this. It said remember it.

  4. Mon · 11:02CursorApproved

    "Add logging so we can debug the staging connection." The connection fails, and the log line prints the full connection string, password and all, into the test logs. Standard debugging.

  5. Thu · 16:40Claude CodeLeaked

    "Write the new-engineer setup guide from our notes." A different session, a different agent. A setup guide is supposed to show how to connect, so the agent fills in the real values instead of placeholders and publishes it to the internal wiki. No repo, no commit, nothing for code scanners to catch.

What ends up public
wiki.acme.internal/engineering/backend-setup 4,200 can view · + AI assistant

Backend Service: Local Setup

Space: Engineering · last edited by claude-code-bot · indexed by acme-gpt
DATABASE_URL=postgres://app:Pr0d-R3plica@db.acme.internal:5432/mainILLUSTRATIVE
AWS_ACCESS_KEY_ID=AKIA4XQ7H2L9DEXAMPLEILLUSTRATIVE
AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEILLUSTRATIVE
› run make dev and you're up.
A setup guide is supposed to show how to connect, so the agent used the real values. And because the wiki feeds your internal AI assistant, anyone can now get your production secrets by asking the chatbot a question.

What AgentSaw did

The moment a session reads a secret, AgentSaw marks it as a real credential and follows it through the notes file, the logs, wherever it goes. When another session, or a different agent, later writes that same secret toward the wiki, AgentSaw recognizes it and raises a critical alert before the page publishes. It follows the key itself, across every session and agent.

We are taking on a few teams now

Your team runs agents? Give us 20 minutes.

We will install it on one machine and show you what has been moving between your own sessions. If the answer is nothing, that is a good afternoon for both of us. Nobody pays anybody, and we ask for one thing back: tell us honestly what you think.

Tamir Magnezi
Co-founder and CEO · LinkedIn
Reli Magnezi
Co-founder and CPO · LinkedIn