Newsletter

Forty-six credentials on one laptop

27 September 2026

We sat down with one senior developer's laptop and counted what the AI agents on it could read. Forty-six credentials.

They were in .env files across cloned repositories, in the cloud CLI profiles in the home directory, in SSH keys and package registry tokens, and in two cases pasted into an agent's own configuration so it would stop asking.

That is what a working developer machine looks like. What changed is that Claude Code, Cursor and Codex now run on it with the developer's access, and they read text all day that they may treat as instructions.

The full list, where each one sat, and what an attacker does with them: https://zybe.ai/blog/forty-six-credentials

Two things from it worth your time.

The fix for most of the forty-six is moving one file per project out of the agent's working directory. An afternoon on one machine. Nobody does it by hand across three hundred.

The dangerous case is not a credential the agent can read. It is a credential the agent can read on a machine where it can also reach the network without asking. That is the combination the sensor blocks.

Next time: the prompt injection we watched get caught on an endpoint, step by step.

Reply with the agents your developers run and we'll tell you what the sensor sees for each. We answer every one.

The ZYBE team

See what AI agents are really doing on developer machines.

One short mail every two weeks, and first access when ZYBE opens.