Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Tuskira's open-source gateway takes MCP credentials off developer laptops and CI runners

Tuskira released AI Agent Gateway, a free open-source proxy that holds AI agents' tool credentials and checks every call against a profile. A stolen agent config then yields only a gateway key, and that key is limited only if the operator bound it to a profile.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Tuskira's open-source gateway takes MCP credentials off developer laptops and CI runners
Generated illustration

What happened

  • Each agent registers the gateway as its MCP server and sends a gateway key, tied to a tenant and a role, plus a profile name with every request.
  • Model traffic to Anthropic, directly or through AWS Bedrock, plus OpenAI and Gemini can route through the same gateway by changing an SDK base URL, with tokens and estimated cost recorded per call.
  • For local testing, the Docker Compose file that ships with the gateway permits outbound traffic to the host machine and to loopback addresses. Tuskira says to strip both from any shared deployment.
  • The gateway runs on macOS and Linux, while Windows through WSL2 is untested.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A credential thief now has to reach the gateway's encrypted store to get GitHub or Jira tokens, because laptops and CI runners hold only gateway keys.
  • decision Teams adopting the gateway have to bind every key to a profile at setup, because the shipped behavior lets an unbound key choose its own permissions.
  • exposure Anyone who breaches a gateway left at demo settings gets the prompts and code the agents sent, on top of the credential store.
  • capability Call-time checks stop an agent that has been talked into using a tool it was never shown, a case that trimming the tool list alone leaves open.

In Tuskira's account, as reported by Help Net Security, the problem is file theft. For a team using Claude Code, Cursor and a homegrown ticket bot, every laptop and CI runner usually carries copies of the model keys and MCP credentials in each agent's config [16]. Whoever obtains one of those files has the credentials inside it. According to Tuskira, nothing checks the agent's permissions when it acts [17].

The gateway changes what sits in those files. On an allowed call it pulls the real credential from an encrypted store and attaches it on the way out, so the agent never holds the GitHub token [3]. A denied call returns an error and lands in the log without reaching the backend [4].

How exploitable a deployment is depends on one default. If a gateway key has no profile bound to it, the caller can pick a profile itself by naming one in a request header [7]. That means a leaked unbound key can ask for any profile it wants [7]. Lifted from a CI runner, such a key reaches every tool that any profile on the gateway allows, though each request still has to pass through the gateway to get there [15]. If the key is bound to its profile, the same leak reaches only what that profile permits. Tuskira's sample CI profile allows one tool [8].

The demo configuration also makes the gateway a data store. It saves the bodies of LLM requests and responses, up to 1 MiB apiece, for display in the console [9]. Whatever prompts and code the agents send end up in those bodies. One setting turns storage off [9]. Apart from the Compose file's local-testing allowances, by default the gateway won't connect to private or loopback addresses, and it blocks the cloud metadata address without exception [11].

The repository ships worked examples for Claude Code, Cursor, VS Code, Codex CLI, a Python agent and Kubernetes [13]. The code is free on GitHub [14].

What to watch

  • Whether Tuskira changes the default so a key with no bound profile can no longer name its own profile in a request header.
  • Any independent review or disclosed vulnerability in the gateway, which now holds every backend credential its agents use in one encrypted store.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence40
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Tuskira's AI Agent Gateway is an open-source tool that sits between AI agents and the MCP tool servers and model providers they call, and it runs in the user's own environment without a Tuskira account.

    ReportedSupportedView cited source
  2. [2]

    An agent registers the gateway as its MCP server and sends a gateway key and a profile name with every request; the gateway checks the key, which is tied to a tenant and a role, then checks whether that profile may use the requested tool.

    ReportedSupportedView cited source
  3. [3]

    An allowed call gets the real credential pulled from an encrypted store and attached on the way out, so the agent never holds the GitHub token.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. helpnetsecurity.com

    1 article · October 6, 2026

    AI Agent Gateway: Open-source tool keeps credentials out of agent configs

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories