Hardcoded MCP Credentials Found in Public GitHub Files
Hush Security analyzed about 82,000 MCP configuration files on GitHub and found that 12% of credential slots contained keys and tokens in plaintext. 24% of found secrets have broad permissions and do not expire by default, and 243 secrets remained in Git history after removal from the current version.
- 12% of ~82,000 MCP files contained hardcoded credentials
- 55% of secrets had no recognizable format, 31% were opaque bearer tokens
- 53% of keys with known permissions granted org- or DB-level access
- 243 secrets remained in Git history after removal from current file
Read next
Security