Colin Miley
← All essays
26 September 2026 · Originally published on LinkedIn

My AI could've leaked credentials. I closed that gap in 4 hours — here's how.

AI agents are only as safe as the access you hand them. Mine had more than it needed — and that was my fault, not its.

While auditing my own setup, I found API keys and credentials sitting in places an agent could read, repeat, or worse — include in an outbound message. Nothing bad happened. But the gap was real, and it took four hours to close.

The fix was boring, which is exactly what good security looks like: credentials moved into a proper secrets store, agents given scoped, least-privilege access, and an explicit rule about what an agent may never touch.

If you run AI tooling in your business, assume your agents can see everything they can technically reach. Then make sure that list is short, deliberate, and reviewed.

One sales leak, fixed, every week

Get the next issue by email — no algorithm in the way.

Find the leaks in your own revenue system — the free assessment takes two minutes.