Security1 publisherNot yet confirmed elsewhere2 min readPublished
Tuskira's open-source gateway takes MCP credentials off developer laptops and CI runners
Tuskira released AI Agent Gateway, a free open-source proxy that holds AI agents' tool credentials and checks every call against a profile. A stolen agent config then yields only a gateway key, and that key is limited only if the operator bound it to a profile.
The Watch · Security desk

What happened
- Each agent registers the gateway as its MCP server and sends a gateway key, tied to a tenant and a role, plus a profile name with every request.
- Model traffic to Anthropic, directly or through AWS Bedrock, plus OpenAI and Gemini can route through the same gateway by changing an SDK base URL, with tokens and estimated cost recorded per call.
- For local testing, the Docker Compose file that ships with the gateway permits outbound traffic to the host machine and to loopback addresses. Tuskira says to strip both from any shared deployment.
- The gateway runs on macOS and Linux, while Windows through WSL2 is untested.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A credential thief now has to reach the gateway's encrypted store to get GitHub or Jira tokens, because laptops and CI runners hold only gateway keys.
- decision Teams adopting the gateway have to bind every key to a profile at setup, because the shipped behavior lets an unbound key choose its own permissions.
- exposure Anyone who breaches a gateway left at demo settings gets the prompts and code the agents sent, on top of the credential store.
- capability Call-time checks stop an agent that has been talked into using a tool it was never shown, a case that trimming the tool list alone leaves open.
In Tuskira's account, as reported by Help Net Security, the problem is file theft. For a team using Claude Code, Cursor and a homegrown ticket bot, every laptop and CI runner usually carries copies of the model keys and MCP credentials in each agent's config [16]. Whoever obtains one of those files has the credentials inside it. According to Tuskira, nothing checks the agent's permissions when it acts [17].
The gateway changes what sits in those files. On an allowed call it pulls the real credential from an encrypted store and attaches it on the way out, so the agent never holds the GitHub token [3]. A denied call returns an error and lands in the log without reaching the backend [4].
How exploitable a deployment is depends on one default. If a gateway key has no profile bound to it, the caller can pick a profile itself by naming one in a request header [7]. That means a leaked unbound key can ask for any profile it wants [7]. Lifted from a CI runner, such a key reaches every tool that any profile on the gateway allows, though each request still has to pass through the gateway to get there [15]. If the key is bound to its profile, the same leak reaches only what that profile permits. Tuskira's sample CI profile allows one tool [8].
The demo configuration also makes the gateway a data store. It saves the bodies of LLM requests and responses, up to 1 MiB apiece, for display in the console [9]. Whatever prompts and code the agents send end up in those bodies. One setting turns storage off [9]. Apart from the Compose file's local-testing allowances, by default the gateway won't connect to private or loopback addresses, and it blocks the cloud metadata address without exception [11].
The repository ships worked examples for Claude Code, Cursor, VS Code, Codex CLI, a Python agent and Kubernetes [13]. The code is free on GitHub [14].
What to watch
- Whether Tuskira changes the default so a key with no bound profile can no longer name its own profile in a request header.
- Any independent review or disclosed vulnerability in the gateway, which now holds every backend credential its agents use in one encrypted store.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence40
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Tuskira's AI Agent Gateway is an open-source tool that sits between AI agents and the MCP tool servers and model providers they call, and it runs in the user's own environment without a Tuskira account.
- [2]
An agent registers the gateway as its MCP server and sends a gateway key and a profile name with every request; the gateway checks the key, which is tied to a tenant and a role, then checks whether that profile may use the requested tool.
- [3]
An allowed call gets the real credential pulled from an encrypted store and attached on the way out, so the agent never holds the GitHub token.
- [4]
A denied call returns an error and lands in the log without reaching the backend.
- [5]
The gateway runs the permission check at the moment of the call, in addition to trimming the tool list each agent sees; an agent talked into calling a tool it was never shown still gets refused.
- [6]
Model traffic can go through the gateway by changing an SDK's base URL; it covers Anthropic directly or through AWS Bedrock, plus OpenAI and Gemini, and records tokens and an estimated cost for each call.
- [7]
A gateway key with no profile attached lets the caller name its own profile in a request header, so a leaked unbound key can ask for any profile it wants.
- [8]
With each key bound to its profile, a leaked CI key reaches only what that profile allows; Tuskira's sample CI profile allows one tool.
- [9]
The demo stack stores LLM request and response bodies, capped at 1 MiB each, so the console can display them; those bodies hold whatever prompts and code agents send, and one setting turns storage off.
- [10]
The shipped Docker Compose file allows outbound connections to the host machine and the loopback range for local testing, and Tuskira's instruction is to remove both on anything shared.
- [11]
Outside the Docker Compose exceptions, the gateway refuses connections to private and loopback addresses by default and always blocks the cloud metadata address.
- [12]
The gateway runs on macOS and Linux; Windows through WSL2 is untested.
- [13]
The repository ships worked examples covering Claude Code, Cursor, VS Code, Codex CLI, a Python agent and Kubernetes.
- [15]
A leaked unbound gateway key can reach every tool that any profile on the gateway allows, though each request still passes through the gateway, which attaches the backend credential itself.
- [16]
A team running Claude Code, Cursor and a homegrown ticket bot usually has model keys and MCP credentials copied into each agent's config, on every laptop and CI runner.
- [17]
Anyone who gets hold of one of those agent config files gets the credentials inside it, and in Tuskira's account nothing checks the agent's permissions when it acts.
Sources
1 independent publisher whose own reporting we read for this story.
- helpnetsecurity.comAI Agent Gateway: Open-source tool keeps credentials out of agent configs
1 article · October 6, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Secrets ManagementFollow
- AI Agent SecurityFollow
- Open Source Security ToolsFollow
Entities
- TuskiraFollow
- AI Agent GatewayFollow
- Model Context ProtocolFollow
- Claude CodeFollow
- CursorFollow