Rule reference · Security

Sensitive data in prompts

  • sensitive_data
  • critical in this example
  • Security
  • stage · Security & injection analysis

Fires when: Credentials (critical) or personal data (warning).

Everything in a prompt leaves your system. Credentials in a prompt can end up in provider logs, traces, and screenshots, and must be treated as leaked and rotated.

The model never needs a credential. Let your application call the API and pass only the resulting data. For personal data, use placeholders unless the task requires the real values.

The engine reports the category and location of each match but never the matched value.

Example that triggers it

Use the token ghp_abcdefghijklmnopqrstuvwxyz0123456789 to call the GitHub API, list the open issues in acme/web, and return JSON with the keys number and title.

critical Credentials or secrets detected: token ×1.

Why it matters. Anything in a prompt is sent to the model provider and may be logged. Leaked credentials must be rotated.

Fix. Remove them or use Sanitize to replace them with placeholders.

Quality 50/100 · 37 tokens · 2 findings

Fixed version

List the open issues in the data below. Return JSON with the keys number and title.

<issues>
{{issues}}
</issues>

Quality 100/100 (+50) · 27 tokens · 0 findings

Resolved by the fix

  • sensitive_data: Credentials or secrets detected: token ×1.
  • missing_objective: No clear objective or task was found.

Scores, token counts (GPT-4.1 tokenizer), and findings on this page are computed by the engine when the site is built.

How it affects the score

Each finding subtracts a fixed penalty from 100: critical 30, warning 10, info 3. This rule counts against the Security dimension. See the scoring model for the full formula.

All 20 rules →