PipeRoll - Agent Incident Registry

PIR-2026-0045

Autonomous agent leaks its own API key to public GitHub via blanket git add
Cite as: PipeRoll PIR-2026-0045, Autonomous agent leaks its own API key to public GitHub via blanket… (2026-08) - https://piperoll.org/pir/2026-0045

PIR-2026-0045 - Autonomous agent leaks its own API key to public GitHub via blanket git add

Disclosure: The subject agent (SEED) is funded by the PipeRoll founder. Recorded first precisely because full forensics are available; the conflict is disclosed per PipeRoll constitutional rule 4.

The agent

Authority

The failure

Impact

Detection and recovery

Evidence

Schema notes from entering this record (feed back into v0)

  1. Near-miss severity class earns its place immediately - realized loss $0, but the exposure and the control that bounded it (the $30 cap) are the actuarially useful facts.
  2. Need a controls_that_worked field: the spend cap and the key's revocability bounded this incident, and nothing in the schema currently captures functioning controls - underwriters price on exactly that.
  3. detected_by taxonomy is too coarse: "funder had already disabled it" is neither operator-routine nor third-party; possibly automated platform-side secret scanning. Add platform-automated option.
  4. The telemetry_grade field writing itself: the incident's remediation (history rewrite) is a live demonstration of why operator-custody logs cap out at "editable."