Hush Security analysed around 82,000 publicly accessible Model Context Protocol (MCP) configuration files on GitHub and found 12 per cent of credential slots contained a hardcoded credential literal, potentially exposing credentials for the services those AI coding tools connect to. Of the hardcoded secrets, 55 per cent had no vendor-recognisable token format, including 31 per cent classified as opaque bearer tokens for internal MCP servers; the values were predominantly vendor API keys, bearer tokens and database passwords. The figures are lower-bound estimates, since GitHub code search indexes default branches, excludes forks and caps results per query. Humans are the harder problem: examining the history of 7,681 credential-bearing configurations across up to seven revisions, they found 243 where the secret had been removed from the current file but remained readable in an earlier commit — which means rotation at the provider is the only remediation. Hush's chief executive Micha Rave framed the gap as structural: these files are meant to be committed, the secret never should be, and the highest-risk credentials in them match no known pattern while the identities behind them have no owner and no expiry.
| Attribute | Detail |
|---|---|
| Sector | AI & Frontier Technology |
| Date | 2026-09-21 |
| Source | Help Net Security |
| Reliability | Tier 3 |