Copilot committed my repo secrets into AGENTS.md

10 pointsposted 5 hours ago
by benjaminbenben

4 Comments

zvqcMMV6Zcr

an hour ago

So it didn't warn user that secrets are still visible in repo history and have to rotated, it only made that revert?

nulone

3 hours ago

How did you catch it — scanner, review, or just noticed manually? I treat agent-generated diffs as untrusted by default now.

nik282000

3 hours ago

LLMs are not intelligent machines, they are lying engines that predict the next most likely thing to do or say. If publishing your credit card details, home address and blood type meshes with the last thing it ingested, it'll do it.

chrisjj

5 hours ago

"… though to be fair, it did sincerely apologize and promised never to do it again."