New research from Hush Security found that one in eight credential slots in public GitHub MCP configuration files contain hardcoded secrets -- including API keys, passwords and access tokens.

MCP config files tell AI coding agents which tools to access and how to authenticate -- making them a high-value entry point for attackers looking to pivot into sensitive corporate systems.

Researchers analyzed around 82,000 public MCP config files across more than a dozen coding agents and found 12% of credential slots hardcoded a credential literal.

Tackling MCP risk exposure Experts agreed that, given the high stakes, CISOs should assess their MCP risk exposure this week.

The researchers' findings underscore dual AI security challenges for CISOs, added Brandon Dixon, CTO and cofounder of Ent, an AI cybersecurity company.