Hardcoded MCP credentials found in public GitHub files
Hush Security found 12% of 82,000 public GitHub MCP config files contained hardcoded API keys, bearer tokens, and database passwords.
Hush Security's 'The State of MCP Configuration: The Identity Security Gaps' report analyzed roughly 82,000 MCP configuration files in public GitHub repositories, finding that 12% of credential slots contained hardcoded credential literals. Researchers used provider-specific token patterns and Shannon entropy to identify likely secrets, predominantly vendor API keys, bearer tokens, and database passwords. Of 7,681 credential-bearing configurations whose history was examined, 243 had secrets removed from the current file but still recoverable from earlier Git commits. Many exposed credentials were high-impact: 53% of classified credentials granted organization-, account-, workspace-, or database-wide access, and 80% with a defined expiration policy did not expire by default.