Your API keys are in your code
What's wrong AI tools often paste secret keys straight into the source — and then that code gets pushed to a public GitHub repo.
What it costs you Bots scan public repos within minutes. Stolen Stripe or OpenAI keys get used to run up thousands in charges on your account.