security1 publisher
Hush Security found hardcoded credentials in 12% of credential slots across 82,000 public MCP configs
Hush Security searched public GitHub for the configuration filenames coding agents write, classified how each credential slot gets its value, and found a hardcoded literal in 12% of them, most of which match no vendor token format.
Publishers:helpnetsecurity.com
Reality
- Evidence45
- Adoption38
- Hype gap+12
- Incentives78
- Confidence58