One in Four Organizations Are Leaking Secrets Through AI Agent Config Files
A Codacy scan of 34,266 repos found credentials, API keys, and system prompts exposed in AI agent config files at 25% of organizations.
Per reporting surfaced on Reddit's r/artificial community, Linktree has updated its terms of service to permit user content � bios, links, posted material � to be collected for AI training purposes, with no prominent disclosure to its tens of millions of users.
The move follows a pattern that has become depressingly familiar. A platform with massive user adoption quietly amends its legal language, buries the change in a ToS update email, and waits to see if anyone notices. Linktree's particular exposure here is its user base: musicians, independent creators, small businesses, and nonprofits who use the service as their primary web presence and have no legal team scanning for this.
The practical consequence is that profile content, link descriptions, and any text users have written to represent themselves publicly is now fair game for model training under Linktree's terms. Whether any AI company has actually ingested it yet is a separate question.
Regulators in the EU are already wrestling with exactly this class of problem under the AI Act's data governance provisions. In the US, there is no equivalent floor. Until there is, opt-out buried in ToS will remain the industry standard.
All comments are reviewed before appearing. Keep it respectful.
A Codacy scan of 34,266 repos found credentials, API keys, and system prompts exposed in AI agent config files at 25% of organizations.
Palantir is championing nation-state control of AI deployments — a policy framework that also positions the company as indispensable government infrastructure.
Netflix is cloning Gene Wilder's voice with AI for a competition series, stepping into legally uncharted territory on posthumous digital performance.