FixVibe

// コード / スポットライト

Committed AI-Generated Secrets

AI snippets should not ship provider keys into git.

What it is

AI coding tools are good at producing complete integration snippets. That is also the failure mode: a route handler, config file, or example implementation lands with a real OpenAI, Anthropic, Stripe, AWS, GitHub, SendGrid, Mailgun, Google, Slack, Twilio, private-key, or Supabase service-role credential committed into source.

How it happens

A key that lands in a commit stays in git history after the line is deleted, and every clone, fork, and CI log that saw it keeps a copy. AI-generated integration code is a common source: the assistant fills in a working credential so the example runs, and the change is merged without anyone noticing. Publishable keys such as the Supabase anon key are meant to be public; service-role keys, provider secret keys, and private keys are not, and those are the ones the report flags.

What an attacker gets

A committed secret remains exposed even if it never reaches the deployed JavaScript bundle. Anyone with repo access, CI log access, fork history, or a cached public clone may be able to reuse the credential. The highest-risk findings are live provider secrets, private keys, GitHub tokens, payment keys, and Supabase service-role credentials that bypass normal application authorization.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Rotate or revoke the credential at the provider, remove it from current source, decide whether shared git history needs purging, and move runtime access to server-only environment variables or a managed secret store. Add Gitleaks, TruffleHog, GitHub secret scanning, or equivalent CI enforcement so future AI-generated snippets fail before merge.

// あなたのアプリで実行してみてください

FixVibe が見守る間も、安心して出荷を続けられます。

Connect a GitHub repo to check its code, dependencies and workflows.

ソースコード
198
このカテゴリで実行されるテスト
モジュール
155
専用の ソースコード チェック
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// 最新チェック · 実用的な修正 · 安心してリリース

Committed AI-Generated Secrets: what it is and how to fix it · FixVibe