
Company I might start working with. $150M+ valuation.
30 minutes of poking around. Found their OpenAI key in a Lovable experiment.
I'm as far from a security expert as it gets. But this is the AI-native world — you're one prompt away from being dangerously expertable.
These are transition-phase problems. Everyone has them. But you have to move fast.
Three rules:
1. Never paste credentials into any chat tool.
2. Use Doppler. Or Infisical. Or anything that remove the risk of waking up to a $20K bill because your key is sitting on the open web.
3. If your org is doing real AI work, hire someone who builds the AI-native life practice. Engaged, secure, proactive.
Here's a skill that runs this kind of recon — funny artifacts + real vulnerabilities.
github -> 0xSteph/pentest-ai-agents
Use it on your own company, or the one about to hire you. Strong way to show up.
More AI-native life posts coming.

English
















