AI-assisted secret triage becomes trustworthy when its attribution and risk reasoning remain visible and remediation stays human-owned
Source: GitGuardian
GitGuardian says Public Secrets Monitoring now runs two AI agents and deep analysis on every public GitHub and Docker Hub incident, returning a company-related verdict, risk score, and visible reasoning. The company reports that AI-service credentials reached 1.27 million exposed instances last year, and that 24,008 unique secrets appeared in public MCP configuration files. New workspaces receive the analysis by default, with existing workspaces rolling out gradually; the workflow does not close incidents automatically.
Why this matters: Use AI to prioritise an expanding external exposure queue, but do not let a score replace accountable remediation. Preserve the evidence behind every attribution, identify the credential owner and reachable systems, rotate or revoke through a tested path, and record the human decision to close. Include MCP configurations, agent logs, tool caches, and generated files in the same prevention and response controls as conventional source code.
Read GitGuardian's Public Secrets Monitoring announcement