AI Coding Agents Leak Credentials: Cursor, Claude Code, Copilot and MCP
GitGuardian's State of Secrets Sprawl 2026 found 24,008 unique secrets in public MCP configuration files, 2,117 of them valid, plus a 3.2% leak rate in Claude Code-assisted commits. The cause: agents store keys in config files, env variables, logs and temp files that repository and CI scanners never inspect.
- 24,008 unique secrets found in public MCP configs, 2,117 valid
- 3.2% leak rate in Claude Code-assisted commits
- Cursor keeps MCP configs in-project and in home dir with inline tokens
- Copilot CLI writes OAuth token to plaintext file when no keychain
Read next
Security