Research · curated 1 Oct 2026
API Secrets Should Never Become Tokens in the LLM’s Vocabulary: A Threat Analysis of API Credential Handling in LLM Agent Systems and an Empirical Evaluation of a Vault-Mediated Execution Boundary
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Credential handling in agentic LLM systems turns secret storage into an execution-security problem, and this evaluation shows that vault mediation closes several disclosure paths but is necessary rather than sufficient for defenders deploying tool-using agents.
A Corvic AI research paper formalizes the credential-exposure threat chain in tool-using LLM agents, where API keys pasted into prompts or embedded in tool configs propagate into conversation history, logs, memory stores, and generated code, and where prompt injection plus excessive agency can escalate disclosure into unauthorized action. The authors describe a vault-mediated execution architecture (Corvic Security Vault) in which the model selects a connector identifier while a trusted boundary supplies authentication, and report two black-box experiments across 16 probes where an authenticated GitHub request succeeded without the credential appearing in environment, headers, filesystem, echo services, or metadata endpoints.