THE CRUNCH
GitHub's product lead for secret scanning says AI agents now appear in one in three pull requests on the platform, up from fewer than one in 10 a year ago, and argues secret protection must scale to match. In an essay published on 7 October 2026, the company also unveiled a fine-tuned classifier, built with Microsoft Applied Sciences, that assesses candidate secrets in under two milliseconds and could more than double the number of secrets GitHub can prevent from being pushed.
The data behind the argument covers nine complete quarters. Public pushes screened by GitHub grew 2.84 times between Q2 2024 and Q2 2026, while pushes carrying credentials grew 2.59 times. The share of pushes with a detected secret showed no statistically detectable trend, and the proportion of push-protection blocks overridden by developers fell from 6.63% to 3.93%. GitHub's reading is that developers are not becoming careless as agents write more code; they are simply being outpaced.
The stakes are timing as much as volume. A new secret appears in publicly visible code roughly once every two seconds, and manually revoking an exposed credential takes a mean of around 40 days, with about one in five taking more than 90 days. Push protection currently stops about 30% of newly detected secrets before they enter repository history; the remaining 70% are found only after the credential is already exposed.
The new classifier targets the harder cases. Provider-issued tokens often have recognisable prefixes, but internal database passwords can be completely unstructured, with no identifying pattern. GitHub says the model evaluates a whole set of candidate secrets in less than two milliseconds, extending push protection to secrets that pattern matching alone would miss.


