Wake Forest researchers found 520 credential leaking agent skills in a sample of 17,022 and exploitable AI access in 282 of 444 iOS apps. In agent skills, 89.6% of affected cases were reported as immediately exploitable; debug logging, insecure code, and prompt based instructions were among the major leakage paths.
Published byEdited with GPT-5.6 LunaImages generated with GPT Image 1.5
Research answer

Create a landscape editorial hero image for this Studio Global article: What did a Wake Forest University study of AI-agent skills and iOS applications reveal about credential leakage—including the number of skil. Article summary: Wake Forest researchers found that credential leakage is widespread in both third-party AI-agent skills and LLM-enabled iOS apps—and that most leaked credentials can be abused immediately. The studies point to insecure d. Topic tags: general, education, academic, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, water
Wake Forest University research points to a common weakness across two fast-growing AI ecosystems: credentials are frequently placed where agents, apps, or attackers can retrieve them. One study examined 17,022 third-party agent skills and found 520 affected skills containing 1,708 security issues. A related study of 444 LLM-enabled iOS apps found that 282 exposed credentials or backend access mechanisms during testing. 1
2
4
The practical risk is larger than a leaked string. An exposed key or token can give an attacker access to private data, agent capabilities, or paid model inference running on a developer’s account.
The researchers selected 17,022 skills from 170,226 artifacts on SkillsMP. They combined static secret detection, dynamic sandbox testing with mock credentials, and checks comparing a skill’s stated purpose with its runtime behavior. 3
4
The analysis identified:
This means a conventional code-only review may miss important risks. A skill can describe an apparently legitimate task while its instructions or supporting scripts expose secrets during execution.
Debug logging was a particularly important leakage pattern. In agent frameworks that feed standard output into the model context, a credential printed through functions such as print or console.log may become accessible through an ordinary natural-language request. The study summary identifies debug logging as the primary vector and attributes 73.5% of leaks to output exposure to LLMs. 4
The risk is not limited to obvious hardcoded API keys. Credentials can also be exposed through scripts, environment handling, logs, prompt instructions, or combinations of code and language that only become dangerous during normal execution.
The research describes two broad causes of credential leakage:
The distinction matters for remediation. Malicious content requires screening and removal, while accidental exposure requires better secret management, safer logging, authentication controls, and testing before distribution.
After researchers notified SkillsMP, Wake Forest said that all identified malicious skills were removed and that most vulnerable skills were fixed. The study also warns that cleaning the original repository may not be enough: forked copies can preserve exposed credentials after the source has been repaired. 1
4
The related iOS research examined 444 applications with LLM features and found that 282—about 64%—exposed exploitable LLM credentials or backend access mechanisms in network traffic. 2
5
The reported exposure patterns included:
These weaknesses can be visible during ordinary app use. An attacker who captures a key, reuses a token, or discovers an open proxy may be able to send requests through the developer’s LLM account. That can consume paid inference, abuse associated cloud resources, or create unauthorized usage charges. 2
5
The evidence supports the possibility of severe or potentially unbounded billing exposure, depending on account limits and how long an intrusion continues. It does not, however, independently establish a specific loss figure such as “hundreds of thousands of dollars.”
Remediation was also slow. Three months after responsible disclosure, only 28% of affected iOS apps had fixed the reported vulnerability, leaving 72% exploitable in the study’s follow-up. 3
11
Together, the studies show that adding an AI feature or installing a reusable agent skill can expand an application’s attack surface. The new risks include:
The concern is heightened as developers use AI-assisted “vibe coding” to generate and integrate software quickly. Speed does not replace threat modeling: authentication, secret handling, authorization, logging, and dependency review still need deliberate engineering. The agent-skills research also reported signatures of AI-assisted development in 72% of hardcoded-credential cases, suggesting that insecure patterns may spread through generated or rapidly assembled code. 4
The findings support a defensive baseline for teams building AI products or distributing agent skills:
The central lesson is straightforward: AI security cannot be added only after a product ships. Credentials, agent permissions, model context, and billing controls need to be treated as core product-security concerns from the beginning.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Wake Forest researchers found 520 credential leaking agent skills in a sample of 17,022 and exploitable AI access in 282 of 444 iOS apps.
Wake Forest researchers found 520 credential leaking agent skills in a sample of 17,022 and exploitable AI access in 282 of 444 iOS apps. In agent skills, 89.6% of affected cases were reported as immediately exploitable; debug logging, insecure code, and prompt based instructions were among the major leakage paths.
The researchers say AI products need security by design controls, including server side key storage, least privilege access, secret scanning, redacted logs, and stronger marketplace review.
Wake Forest researchers found 520 credential leaking agent skills in a sample of 17,022 and exploitable AI access in 282 of 444 iOS apps. In agent skills, 89.6% of affected cases were reported as immediately exploitable; debug logging, insecure code, and prompt based instructions were among the major leakage paths.
Published byEdited with GPT-5.6 LunaImages generated with GPT Image 1.5
Research answer

Create a landscape editorial hero image for this Studio Global article: What did a Wake Forest University study of AI-agent skills and iOS applications reveal about credential leakage—including the number of skil. Article summary: Wake Forest researchers found that credential leakage is widespread in both third-party AI-agent skills and LLM-enabled iOS apps—and that most leaked credentials can be abused immediately. The studies point to insecure d. Topic tags: general, education, academic, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, water
Wake Forest University research points to a common weakness across two fast-growing AI ecosystems: credentials are frequently placed where agents, apps, or attackers can retrieve them. One study examined 17,022 third-party agent skills and found 520 affected skills containing 1,708 security issues. A related study of 444 LLM-enabled iOS apps found that 282 exposed credentials or backend access mechanisms during testing. 1
2
4
The practical risk is larger than a leaked string. An exposed key or token can give an attacker access to private data, agent capabilities, or paid model inference running on a developer’s account.
The researchers selected 17,022 skills from 170,226 artifacts on SkillsMP. They combined static secret detection, dynamic sandbox testing with mock credentials, and checks comparing a skill’s stated purpose with its runtime behavior. 3
4
The analysis identified:
This means a conventional code-only review may miss important risks. A skill can describe an apparently legitimate task while its instructions or supporting scripts expose secrets during execution.
Debug logging was a particularly important leakage pattern. In agent frameworks that feed standard output into the model context, a credential printed through functions such as print or console.log may become accessible through an ordinary natural-language request. The study summary identifies debug logging as the primary vector and attributes 73.5% of leaks to output exposure to LLMs. 4
The risk is not limited to obvious hardcoded API keys. Credentials can also be exposed through scripts, environment handling, logs, prompt instructions, or combinations of code and language that only become dangerous during normal execution.
The research describes two broad causes of credential leakage:
The distinction matters for remediation. Malicious content requires screening and removal, while accidental exposure requires better secret management, safer logging, authentication controls, and testing before distribution.
After researchers notified SkillsMP, Wake Forest said that all identified malicious skills were removed and that most vulnerable skills were fixed. The study also warns that cleaning the original repository may not be enough: forked copies can preserve exposed credentials after the source has been repaired. 1
4
The related iOS research examined 444 applications with LLM features and found that 282—about 64%—exposed exploitable LLM credentials or backend access mechanisms in network traffic. 2
5
The reported exposure patterns included:
These weaknesses can be visible during ordinary app use. An attacker who captures a key, reuses a token, or discovers an open proxy may be able to send requests through the developer’s LLM account. That can consume paid inference, abuse associated cloud resources, or create unauthorized usage charges. 2
5
The evidence supports the possibility of severe or potentially unbounded billing exposure, depending on account limits and how long an intrusion continues. It does not, however, independently establish a specific loss figure such as “hundreds of thousands of dollars.”
Remediation was also slow. Three months after responsible disclosure, only 28% of affected iOS apps had fixed the reported vulnerability, leaving 72% exploitable in the study’s follow-up. 3
11
Together, the studies show that adding an AI feature or installing a reusable agent skill can expand an application’s attack surface. The new risks include:
The concern is heightened as developers use AI-assisted “vibe coding” to generate and integrate software quickly. Speed does not replace threat modeling: authentication, secret handling, authorization, logging, and dependency review still need deliberate engineering. The agent-skills research also reported signatures of AI-assisted development in 72% of hardcoded-credential cases, suggesting that insecure patterns may spread through generated or rapidly assembled code. 4
The findings support a defensive baseline for teams building AI products or distributing agent skills:
The central lesson is straightforward: AI security cannot be added only after a product ships. Credentials, agent permissions, model context, and billing controls need to be treated as core product-security concerns from the beginning.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Wake Forest researchers found 520 credential leaking agent skills in a sample of 17,022 and exploitable AI access in 282 of 444 iOS apps.
Wake Forest researchers found 520 credential leaking agent skills in a sample of 17,022 and exploitable AI access in 282 of 444 iOS apps. In agent skills, 89.6% of affected cases were reported as immediately exploitable; debug logging, insecure code, and prompt based instructions were among the major leakage paths.
The researchers say AI products need security by design controls, including server side key storage, least privilege access, secret scanning, redacted logs, and stronger marketplace review.