TECH

Sieve – scans Cursor/Claude chat history for leaked API keys

Hacker News · Tue, 19 May 2026 03:06:45 GMT

Background: I was using Cursor to set up an OpenAI integration.The agent read my .env file, added the key to the config, and everything worked. What I didn't think about: that key was now sitting in a plaintext SQLite database at ~/Library/ApplicationSupport/Cursor/User/workspace

Read original source Discuss with A.S.I.S