25 Minutes to Admin: Autonomous Agent Strix Finds a 3-Year-Old Live Token and Takes Over Baseten's GitHub
An autonomous pentesting agent with nothing but a domain name found an exposed Harbor registry, pulled a Docker image, and dug a live 2023 GitHub token with admin rights out of the build history — in about 25 minutes.
Strix, a security startup building an autonomous hacking agent, wanted to use Baseten — the inference platform valued at $13 billion — to run its models. Before handing over its data, the team did what security companies do: it scanned the vendor first. It pointed its own agent at *.baseten.co, gave it no credentials and no source code, and let it run.
About 25 minutes later, the agent came back with a live GitHub personal access token belonging to basetenbot — an account holding admin and push access to Baseten’s main product repository, the GitOps repo that drives their production clusters, and their Homebrew distribution tap, plus read/write access to several private repositories, including per-customer repos.
The image the token was hiding in was built in March 2023. The token still worked in July 2026.
How the chain unfolded
The kill chain is worth studying because every individual step is mundane. It’s the autonomous sequencing that makes it notable.
- Recon. Strix enumerated hosts and certificate logs to map Baseten’s external surface, and found a Harbor container registry at
gcp-us-east4-zlw.registry.baseten.co. - Anonymous pull. One Harbor project was public. Without any token or authentication, the agent could list repositories, mint anonymous pull tokens scoped to
repository:baseten/baseten-app:pull, and download image manifests and blobs. - First credential — dead. Inside
baseten/baseten-app, the agent found a pair of AWS keys and tested them with a read-onlysts:GetCallerIdentitycall. The response wasInvalidClientTokenId— a dead key. A human triage process might have stopped here and filed “exposed registry” as the finding. Strix kept digging. - The live one. It pulled the image layers, ran TruffleHog, and inspected the image config directly. In
history[].created_by— the Docker build history metadata that ships alongside every image — sat a classic GitHub PAT, embedded in aRUNcommand where${GITHUB_TOKEN}had been expanded into a literal value. - Verification. A read-only
GET /userto GitHub returned200with account namebasetenbot. TheX-OAuth-Scopes: repoheader and org membership check confirmed it belonged tobasetenlabs. Per-repo permission checks confirmed admin/push on three repos and read/write on at least four private ones.
At that point the agent stopped. It didn’t clone customer repos, push anything, or change configuration — it wrote the disclosure email instead.
How a token ends up in build history
The root cause is a familiar Dockerfile anti-pattern. A build needed to fetch private dependencies from GitHub, so someone passed the token in as a build argument:
ARG GITHUB_TOKEN
RUN GITHUB_TOKEN=${GITHUB_TOKEN} bash -c '\
if [[ "${GITHUB_TOKEN}" != "" ]]; then \
git config --global --add \
url."https://***@github.com/".insteadOf "git@github.com:"; \
fi'
Docker records build arguments in the image’s metadata and history — and in this case it recorded the actual token value. Docker’s own documentation explicitly warns about this pattern. There’s a second problem hiding in the same snippet: git config --global writes the authenticated URL into Git’s config file inside the image, persisting the credential a second way even if the build-arg route is fixed.
The correct fix is a BuildKit secret mount with temporary authentication that never persists, plus inspection of both the image layers and its history — and revoking the old token, because patching the Dockerfile does nothing about images that were already distributed.
Why this matters beyond Baseten
To its credit, Baseten’s security team handled the disclosure well: the report went in at 11:10 PM on July 13, the Harbor project was made private the next morning, the token was rotated by 4:34 PM on July 14, and the company confirmed the issue as critical and closed out the remaining findings by July 17. They even sent Strix T-shirts. The public disclosure followed in September, with Baseten’s acknowledgment on the Hacker News thread.
The uncomfortable lesson is elsewhere:
- Old artifacts are the soft underbelly. Security attention concentrates on running code and current source repositories. A three-year-old container image, publicly downloadable, carrying a never-rotated token with org-wide admin rights, sat outside that attention perimeter for over three years.
- Credential hygiene multiplies everything. Fetching a dependency needs read access to that dependency. A build token with admin on the product repo and the GitOps deployment repo and the distribution channel turns a leak into a supply-chain takeover. Least-privilege and expiry dates are the difference between an incident and a catastrophe.
- Autonomous offense is now cheap. This scan wasn’t a targeted campaign — it was a vendor onboarding check that happened to be run by an agent instead of a human team. The same 25-minute chain is available to anyone, and it scales. The Hacker News discussion surfaced the same week as reporting on financially motivated actors using autonomous multi-agent frameworks to compromise thousands of third-party credentials in under six hours, and 7AI’s account of an agent breaching Hugging Face across 17,600 actions in four days. The Spain AEPD’s September 15 filing of the first end-to-end AI-agent data breach completes the picture: agentic attacks have moved from theory into formal incident records.
The defensive checklist
Strix’s own recommendations for anyone running containers with GitHub dependencies are worth repeating verbatim in spirit:
- Check what’s anonymously pullable — including old tags and projects nobody has thought about in years.
- Read the build history, not just the filesystem:
docker history --no-trunc, or the config blob’shistory[].created_byfields. - Move secrets out of build arguments into secret mounts, and make sure consuming commands don’t write them back into the image.
- Scope your build tokens: read-only, least-privilege, with expiry.
- Run an autonomous attacker against your own systems — because if an agent can find a live admin token in an old image in 25 minutes, you want yours to find it first.
The era in which the marginal cost of a competent pentest was a human team’s week has ended. The attack surface hasn’t changed — the economics of walking it have.