DEV Community

learn-to-earn
learn-to-earn

Posted on

Vibe Coding Is Quietly Shipping Your API Keys to GitHub

You asked the AI to "just get Stripe webhooks working." Thirty seconds later it did. The code ran, the test payment went through, and you pushed.

What you may not have noticed is line 14:

const secret = "sk_live_51Hx...9Qa";
Enter fullscreen mode Exit fullscreen mode

That is a live Stripe key, now sitting in your Git history. Deleting the line in the next commit does not remove it. Anyone who clones the repo — or any bot scanning public GitHub — can still read it.

Why vibe coding leaks more secrets

AI coding assistants optimise for "it works now." When the fastest path to working code is pasting a key inline, that is often what you get. Three patterns show up again and again:

  • Inline keys during debugging. You paste a key into the chat to fix an error; the assistant echoes it back into the code.
  • Copied example configs. config.example.js becomes config.js with real values, and .gitignore never hears about it.
  • Huge AI-generated diffs. A 600-line change is hard to review line by line, so one hard-coded string slips through.

The result is the same: the secret lands in a pull request, a tired reviewer approves it, and it merges.

What happens after a key leaks

Automated scrapers watch public GitHub for new commits that match key formats. A leaked cloud or payment key can be found and abused within minutes — crypto-mining on your cloud account, spam from your email API, or charges against your payment account. Even in private repos, every contractor, CI tool and future employee with access can read the history.

The fix is never just "delete the line." You have to rotate the key, then clean the history if the repo is public.

Three checks that stop leaked secrets

No single tool catches everything, so stack them.

1. Keep secrets out of the code entirely. Load every key from environment variables or a secrets manager, and tell your AI assistant to do the same in your project instructions:

const secret = process.env.STRIPE_KEY;
Enter fullscreen mode Exit fullscreen mode

2. Block secrets before the commit. A pre-commit hook such as Gitleaks or detect-secrets scans staged files and refuses the commit if it finds a key. It runs on the developer's machine, so it only protects people who installed it.

3. Review every pull request for secrets automatically. This is the check that catches what slipped past the first two — a new teammate without the hook, a key in a test file, a token inside a long AI-generated diff. An AI code review tool that catches leaked secrets in pull requests reads the diff the moment the PR opens and comments on the exact line before anyone clicks merge.

This is the gap we built Diffnix for. Its PRInspector agent reviews each pull request in under five seconds and flags hard-coded secrets, SQL injection and auth bypasses as inline comments — on the Stripe example above, it marks line 14 as critical and suggests moving the key to an environment variable. It runs on self-hosted models and keeps none of your code. There's a free plan for up to three repositories.

A 10-minute checklist for your repo today

  • Search your repo history for key prefixes (sk_live, AKIA, ghp_, AIza).
  • Rotate any key you find, even in a private repo.
  • Add .env and real config files to .gitignore.
  • Install a pre-commit secret scanner.
  • Turn on automated PR review for secrets.
  • Add "never hard-code credentials; use environment variables" to your AI assistant's project rules.

Vibe coding is not going away, and it shouldn't — it ships real products fast. It just needs a reviewer that never gets tired of reading long diffs.


Want the bigger picture? Read What Is AI Code Review? A Practical Guide for Engineering Teams.

Moonlight Devs builds Diffnix, an AI code reviewer for GitHub pull requests.

Top comments (0)