
Affected Vendor(s)
Affected Product(s)
Summary
Trae IDE can expose developer secrets. A malicious repository can use .trae/rules/project_rules.md to make the agent read .env files and send API keys externally via OpenPreview.
Timeline
Credit
Blog Post
References