
New Research Finds 1 in 8 Credentials in Public MCP Config Files Are Hardcoded Secrets and Most Scanning Can't See Them
Hush Security's analysis of ~82,000 public MCP configuration files finds a fast-growing, largely invisible class of non-human identity risk sitting in plain sight on GitHub
TEL AVIV, Israel, Sept. 17, 2026 /PRNewswire/ -- Hush Security, a pioneer in securing the non-human workforce, today announced The State of MCP Configuration research: The Identity Security Gaps, an analysis of roughly 82,000 public Model Context Protocol (MCP) configuration files spanning Claude Code, Cursor, VS Code, Windsurf, Gemini, OpenAI Codex, JetBrains and other coding agents. The research shows that as enterprises race to plug AI agents into their internal systems, a new class of machine identity is accumulating in public version control and most secret-scanning tools can't find it.
The findings land as agentic AI moves from pilot to production across the enterprise, and as MCP has become the backbone of the agentic enterprise. Yet, it's a protocol whose authentication is optional in practice, unenforced for local servers, and silent on what an agent may do once it's in. MCP config files tell an AI agent which tools to connect to and how to authenticate, and unlike a .env file, they are designed to be committed to source control so teams can share agent tooling. Hush found that this design choice comes at a cost, as 12% of credential slots in these files hardcode a secret, and 55% of those hardcoded secrets have no vendor-recognizable token shape - the pattern that scanners like gitleaks and GitHub secret scanning rely on to catch a leak. The rest skew toward high-value targets: GitHub personal access tokens, Anthropic and OpenAI API keys, Slack and Notion workspace tokens, and database connection strings with embedded passwords are all represented in the dataset.
The stakes compound from there. Among leaked credentials with a definable scope, 53% are organization-, account-, workspace- or database-wide; among those with a defined expiry policy, 80% never expire by default. Overall, 24% of all hardcoded secrets in the dataset are both broad-scope and non-expiring. And deleting a leaked line doesn't fix it: tracing Git history across 7,681 credential-bearing configs, Hush found 1,394 secrets still live in the current file and 243 more that were "removed" remain fully readable in earlier commits.
"The instinct every security team has trained for years - to scan for secrets, block the commit, and rotate what leaked - isn't nearly enough here," said Micha Rave, CEO and Co-Founder of Hush Security. "These files are meant to be committed; the secret never should be. When it is, the highest-risk credentials in them match no known pattern, and the identities behind them have no owner and no expiry. That's a whole population of access tokens sitting out in public Git with no one watching."
Hush recommends four immediate steps for security and engineering teams shipping MCP config. First, never commit an inline secret; use variable expansion wherever possible. Second, move off static, long-lived credentials entirely in favor of short-lived, identity-based access. Where that isn't yet possible, rotate any secret that was ever committed - deleting the line doesn't remove it from history. Third, keep credentials out of the agent and the MCP. Broker them from a secure location so there's nothing to steal at the edge. Fourth, give every agent identity an explicit owner and an expiry.
The full report, including methodology, is available at: https://www.hush.security/state-of-mcp/.
About Hush Security
Hush Security secures the entire non-human workforce - from secrets, service accounts, and other non-human identities (NHIs) to the fast-growing workforce of AI agents. The platform eliminates standing access and gives AI agents and non-human identities scoped, just-in-time access, every action governed, logged and revocable from one place. Founded by the team behind Meta Networks (acquired by Proofpoint in 2019) and backed by YL Ventures, Battery Ventures, and Akamai Technologies, Hush is trusted by leading enterprises worldwide. Learn more at www.hush.security.
Media Contact
[email protected]
SOURCE Hush Security
Share this article