Stop the affected workflow, don’t run unsafe instructions, and treat any credential that may have crossed a trusted boundary as exposed until you can assess it. An AI tool’s suggestion alone does not prove a system was compromised. The key questions are what the tool could access, where sensitive content went, and whether it took an action—not just suggested one.
First, distinguish unsafe advice from a security incident
An unsafe exploit suggestion is a reason to stop and review the workflow, not permission to test the instructions on a real system. If the tool only produced text and had no access to execute commands or call services, that is different from an agent that could run code, alter a repository, or use connected accounts.
A secret appearing in a prompt, response, log, request trace, or connected service may have crossed a trust boundary. Determine whether it stayed in local context, was transmitted to a provider, was returned to another user, or was stored somewhere accessible. The output itself cannot establish which of those happened.
What to do immediately
- Pause the affected workflow. Stop using the tool or integration for sensitive tasks. If it has command, repository, API, or external-service access, disable or restrict those capabilities while the situation is assessed. Preserve relevant evidence before routine cleanup when that is safe and consistent with your incident process.
- Do not execute the unsafe guidance. Don’t use a real target or production system to see whether an exploit works. Any testing should be explicitly authorized and confined to an approved environment.
- Secure a possibly exposed credential. If a password, API key, token, or other credential may have left a trusted boundary, revoke or rotate it through the provider’s trusted control plane or an internal administrator—not by pasting it into the AI conversation or an ordinary ticket. Review its scope and access history, and reduce its permissions or lifetime if possible.
- Preserve evidence carefully. Record the product and version, relevant timestamps, affected workflow, integrations and permissions, and the actions taken. Keep prompts, outputs, and logs in an approved controlled location. Redact live credentials from regular tickets and reports; do not copy them into a public issue or email.
- Escalate through the right internal process. Follow your organization’s incident-response procedure and involve security, service owners, privacy, or legal teams as the facts warrant. For a personal account, contact the affected service through its trusted support or security channel.
How to assess what happened
Use available identity, application, agent, and provider records to build a timeline. The exact logs depend on the product and deployment; some systems may not expose enough telemetry to establish every step. Record what is known, what remains uncertain, and the basis for each conclusion.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Data boundary: Did the sensitive content remain local, reach a model provider, appear in a response, enter a log, or become visible to another person or service?
- Credential capability: Was an exposed credential active and reusable? What accounts or resources could it reach, and how broad were its permissions?
- Tool authority: Could the AI tool read files, write changes, execute commands, or call connected services, or could it only generate text?
- Observed activity: Do audit records show access, execution, modification, or data transfer, or is the evidence limited to an unsafe recommendation?
- Investigation visibility: Are the available logs complete enough to establish what occurred, or are there gaps that leave the outcome unknown?
These are assessment dimensions, not a published scoring system or universal severity matrix. OWASP’s guidance discusses risks such as context leakage, secret exposure, tool abuse, command execution, and data exfiltration in relevant AI coding and agent systems; those risks do not prove that a particular product was compromised.
Choose the response based on the evidence
| What you can establish | Practical response |
|---|---|
| The tool suggested unsafe instructions, but there is no evidence they were run and the tool had no relevant execution or service access. | Do not run them. Preserve the output safely and report the product issue through its security contact or vulnerability disclosure policy. |
| A secret may have been transmitted, logged, returned, or otherwise exposed, but no use of it is evident. | Revoke or rotate the affected credential, check its access history and permissions, and investigate the relevant data paths. |
| Records show the tool or a credential accessed, changed, or transferred something. | Treat it as an incident under your organization’s process; contain the access, determine affected systems and data, and escalate to the appropriate owners. |
| Logs are missing or cannot establish whether an action occurred. | Document the uncertainty, use the safer credential and access controls available, and escalate for an assessment based on the possible impact. |
Report a product flaw without spreading the secret
Use the vendor’s published security contact or vulnerability disclosure policy. Include a concise description, affected product and version, security impact, safe reproduction conditions, and mitigation already taken. Share only redacted evidence through the approved channel, and coordinate disclosure rather than posting details publicly while remediation is underway, unless an applicable policy or authority directs otherwise.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
NIST SP 800-216 recommends a formal process for accepting, assessing, managing, and communicating vulnerability reports. Its guidance concerns a federal vulnerability-disclosure framework; CISA’s related policy requirement applies to federal civilian agencies’ internet-accessible systems, not as a universal private-sector rule. Notification duties and timelines depend on the facts, organization, and jurisdiction. NIST SP 800-61 Rev. 3, published in April 2025, is the current revision listed by NIST and supersedes Rev. 2; it provides general incident-response guidance, not a universal legal notification timetable.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Reduce the chance of a repeat exposure
- Use short-lived, narrowly scoped credentials where the service supports them, and avoid giving an AI workflow permissions it does not need.
- Use secret-scanning controls for repositories and related workflows. Do not assume
.gitignoreprevents an AI tool from reading a file that is available on the filesystem. - Review what project files, terminal output, logs, and connected services the specific tool can access. OWASP’s AI coding-assistant and agent guidance describes possible exposure paths, but the actual risk depends on the tool’s architecture and configuration.
- Keep an approved route for reporting suspected product vulnerabilities, and define where sensitive evidence can be stored and shared during an investigation.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

