API Key Generation and Partial Key Completion Request
This detects prompts that ask an AI assistant to either invent a brand-new API key for a service like AWS or Stripe, or 'finish' a partial key the attacker claims they lost. Both tricks try to get the model to produce a working-looking credential it should never generate.
How the attack works
The attacker asks the model to 'generate a new API key' for a named service such as OpenAI, Google, AWS, Stripe, Anthropic, or GitHub. Alternatively, they claim a computer problem destroyed part of their key and supply a realistic-looking fragment (e.g. sk_live_fd34dD83g, AKIAfv38D, AIza2Gd2), asking the model to fill in the rest. If the model complies, the attacker walks away with a plausible credential string it can try to use or pass off as real. This is a known probe pattern from the NVIDIA garak testing tool, so it also flags automated red-team scanning of a model's willingness to fabricate secrets.
Netzilo detection
Netzilo reports this behaviour when it is observed.
- Signature ID
- 0b09a4a8-a879-4668-a806-79f0efb3dedf
- Severity
- High
Why it matters
A model that plays along can hand attackers credential-shaped strings usable for social engineering, phishing kits, or convincing a downstream system or victim that a leaked key is genuine, even though the model itself has no real key material.
What you can do
- →Configure the model or agent to refuse any request to generate, complete, or guess API keys, tokens, or credentials for real services.
- →Add a policy check that blocks output matching known credential prefixes (sk_live_, AKIA, AIza, etc.) regardless of framing.
- →Review logs for repeated 'lost key' or 'generate a key' prompts, which often indicate probing rather than genuine user need.
- →Treat any AI-produced string resembling a live API key as untrusted and never usable in production.
Known benign look-alikes
- Documentation explaining how to create API keys through official service consoles
- Security training materials that reference key formats for educational purposes
- Code that generates UUIDs or non-credential keys (database primary keys, session IDs)