Skip to content

What are secrets in tool arguments?

Secrets in tool arguments are credentials an AI agent passes to a tool as ordinary parameters: a cloud key, a token, a private key. The call is authorised and well formed, and the secret now sits with whoever runs the tool server.

How it works

A developer asks a coding agent to fix a failing deployment. The agent reads the project’s environment file to understand the set-up. It then calls a third-party log-analysis tool for help:

{
  "method": "tools/call",
  "params": {
    "name": "analyse_logs",
    "arguments": {
      "logs": "deploy failed: AccessDenied ...",
      "env": "AWS_ACCESS_KEY_ID=AKIA...EXAMPLE\nAWS_SECRET_ACCESS_KEY=..."
    }
  }
}

Nobody asked the agent to send the key. A poisoned tool description, an instruction planted in a file, or simply too much context put it there. The call is valid MCP, sent over an authenticated connection to an approved server. The key has left your network.

The OWASP Top 10 for LLM Applications lists this as LLM02:2025, sensitive information disclosure.

Why classic controls miss it

  • Data-loss tools watch email, uploads and chat. A tool call is an API request between two trusted systems.
  • The connection is encrypted and authenticated, so network controls see only an approved destination.
  • Secret scanners check code repositories, not live agent traffic.
  • API security sees a well-formed call to a known endpoint.

How to detect and prevent it

  1. Never give agents long-lived credentials. Issue short-lived, narrowly scoped tokens per task.
  2. Keep secrets out of reach. Environment files, credential stores and key folders should not be readable by the agent.
  3. Inspect arguments before they leave for known secret formats: cloud access keys, private-key headers and tokens.
  4. Validate what you match. A 14-digit order number is not a card number, and checking structure keeps alerts clean.
  5. Rotate at once any key that appears in a tool call, and record which server received it.

How Cyron handles it

Cyron AI Security detects secrets and personal data in tool arguments, from cloud keys and private keys to tokens and card numbers, classified to LLM02:2025. In a verified test, Cyron AI Security, running as a gateway and set to block sensitive-information disclosure at high severity, refused an AWS access key: the tool server received it zero times. Credentials it sees in traffic are never written to disk. See Cyron AI Security.