
- 01Secrets in system prompts are a systemic vulnerability. They can be exfiltrated through direct prompt leakage attacks, indirect prompt injection via retrieved content, and model memory if fine tuning on prompt logs is used.
- 02AI systems should authenticate to tools and external services through runtime credential injection at the tool execution layer, not through credentials passed in the model context window.
- 03RAG indexed document corpora require pre indexing secret scanning. A credential accidentally committed to a source document and then embedded in a vector store is effectively accessible to any user who can query that store.
- 04Prompt logs, which capture full context windows for debugging, are high risk secret stores if not treated with the same controls as production credentials. Scrub secrets from prompt logs before storage or route them to appropriately controlled storage.
Secret management is a well understood discipline in application security. Store secrets in a secrets manager, inject at runtime through environment variables or mounted secrets, rotate regularly, and scan code repositories for accidental commits. AI systems follow all of these rules and introduce several new pathways for secret exposure that require additional controls.
The new pathways share a common characteristic. They all involve secrets entering the model context window, either directly through system prompts or indirectly through retrieved content. Once a secret is in the context window, it can potentially be extracted through prompt leakage attacks or included in model outputs.
Eliminating secrets from system prompts
System prompts frequently accumulate API keys, database connection strings, and internal URLs as developers add tool integration instructions. This practice creates a secret exposure pathway that is distinct from any other in the application. The secret is not just stored, it is processed by the model on every request and can be reproduced in model output if the model is prompted to reveal its instructions.
The correct pattern is to move all authentication credentials out of the model context window entirely. Tools should authenticate to external services using runtime injected credentials at the tool execution layer. The model receives a tool name and parameters. The tool execution layer, which runs outside the model, looks up the appropriate credential from the secrets manager and uses it directly.
System prompt credentials are one injection away from exfiltration
An attacker who can deliver a prompt injection through any retrieved content that reaches the model context window can instruct the model to include system prompt content in its response. If the system prompt contains API keys or other secrets, those secrets are exposed. The fix is architectural. Credentials must not be present in the context window at any point.
Pre indexing secret scanning for RAG corpora
Documents ingested into a RAG vector store frequently come from sources that have not been through a security review. Internal wikis, support ticket archives, email exports, and code repository content all may contain accidentally included credentials. Once embedded and indexed, those credentials are retrievable by any user with query access to the collection.
Run a secret scanning pass over every document corpus before indexing. The same tools used for repository secret scanning, including patterns for API key formats from major providers, private key headers, and connection string patterns, apply directly to document corpora. Documents containing detected secrets should be quarantined and reviewed before indexing. The finding should also trigger a credential rotation for the detected secret.
- 01Integrate secret scanning into the document ingestion pipeline as a mandatory pre index step.
- 02Use the same secret scanning tool and pattern library used for code repositories.
- 03Quarantine documents with detected secrets and block them from indexing until reviewed.
- 04Treat every detected secret as potentially exposed and initiate rotation.
- 05Rescan the existing vector store corpus when expanding the secret pattern library.
Prompt log handling as a secret management problem
Prompt logs, which capture the full context window sent to the model for debugging and evaluation purposes, are one of the most commonly overlooked secret stores in AI infrastructure. Because system prompts may contain credentials and retrieved context may contain sensitive data, prompt logs inherit the sensitivity of everything that has ever appeared in the context window.
Apply the same controls to prompt log storage as to production secret stores. Encrypt at rest with a key managed separately from the log storage. Restrict access to a small set of authorized debugging identities. Implement a retention policy that removes prompt logs after the debugging window has passed. Consider scrubbing detected secrets from prompt logs before storage if the scrubbing can be done reliably.
Measuring secret hygiene in AI systems
Track secret hygiene in AI systems through four metrics. System prompt secret incidents should be zero, measured through periodic system prompt audits that scan for credential patterns. RAG corpus secret scan coverage should be 100 percent, with no documents indexed without a completed scan. Prompt log access reviews should confirm that only authorized identities have accessed prompt logs in the past quarter. Credential rotation compliance for AI adjacent service accounts should meet the same standard as production application credentials.
/AI Secret Hygiene Metrics
| Metric | Target | Review Frequency |
|---|---|---|
| System prompt credential incidents | Zero | Quarterly audit |
| RAG corpus secret scan coverage | 100% of indexed documents | Per ingestion batch |
| Prompt log access anomalies | Zero unauthorized access | Monthly review |
| AI service account credential rotation | Meets production SLA | Quarterly verification |
