chiprook
← Security
SecurityOctober 4, 2026, 22:51

AI Coding Agents Leak Credentials: Cursor, Claude Code, Copilot and MCP

GitGuardian's State of Secrets Sprawl 2026 found 24,008 unique secrets in public MCP configuration files, 2,117 of them valid, plus a 3.2% leak rate in Claude Code-assisted commits. The cause: agents store keys in config files, env variables, logs and temp files that repository and CI scanners never inspect.

AI Coding Agents Leak Credentials: Cursor, Claude Code, Copilot and MCP
#GitGuardian#Cursor#Claude#GitHub
Read next
Security

GitGuardian Deploys AI Agents to Triage Leaked Credentials

Security

StackHawk's Wingman Fixes Security Flaws While AI Agent Codes

Security

Hundreds of Leaked GitHub App Keys Still Authenticate

Security

Hardcoded MCP Credentials Found in Public GitHub Files