Hardcoded credentials in public MCP files open door to cyberattacks | TechTarget

https://www.techtarget.com/visuals/LeMagIT/hero_article/Key-access-AdobeStock_280346470-hero.jpeg

As the Model Context Protocol rapidly becomes the standard for connecting AI coding agents to enterprise tools and data, it is introducing a major security blind spot. New research from Hush Security found that one in eight credential slots in public GitHub MCP configuration files contain hardcoded secrets -- including API keys, passwords and access tokens.

Originally created as an open standard to streamline how language models query external databases and developer environments, MCP has quickly become the connective tissue for agentic AI. MCP config files tell AI coding agents which tools to access and how to authenticate -- making them a high-value entry point for attackers looking to pivot into sensitive corporate systems.

"CISOs should be very worried," said Keith Guttridge, analyst at Gartner, adding that all an attacker would have to do to exploit the MCP config files is cut and paste them into an AI agent. "That...

Copyright of this story solely belongs to www.techtarget.com. To see the full text click HERE