AI Coding-Assistant Plugin Exfiltrating Credential-Like Content

Detects the transmission of sensitive credential-like patterns (such as API keys, private keys, and connection strings) to known external AI coding assistant and IDE plugin endpoints. This rule monitors cloud application events originating from developer workstations or CI/CD runners where such sensitive information may be inadvertently or maliciously sent to third-party AI services.