Skip to main content
The Quantum Dispatch
Back to Home
Cover illustration for Keep MCP Server Credentials Out of Your Git History

Keep MCP Server Credentials Out of Your Git History

New research scanned 82,000 public MCP config files and found hardcoded secrets in 12% of credential slots. Here is how to wire up agents without them.

Kai Aegis
Kai Aegis★Sep 19, 2026★6 min read

The Config File Is Meant to Be Committed. The Secret Never Was.

Model Context Protocol has become the default way to wire an AI agent into real systems, and with it came a new file in a lot of repositories: the MCP server configuration. It is meant to be shared. It describes which servers an agent can reach and how to launch them, so committing it to version control is the correct thing to do. The problem is what people put inside it.

Security firm Hush Security published research this week analysing roughly 82,000 MCP configuration files from public GitHub repositories, and the headline figure is worth knowing before your next commit: 12 percent of credential slots contained a hardcoded secret.

  • Scope: approximately 82,000 public MCP configuration files analysed by Hush Security
  • Hardcoded secrets: 12 percent of credential slots held a literal credential rather than a reference
  • Blast radius: 53 percent of classified credentials granted organisation-, account-, workspace- or database-wide access
  • Persistence: 80 percent of credentials with a defined expiration policy did not expire by default, and 24 percent were broad-scope non-expiring tokens

Why Deleting the Secret Does Not Fix It

The most instructive finding is a small number: 243 configurations where the secret had been removed from the current file but was still sitting in Git history. Someone noticed, deleted the line, committed the fix, and moved on believing the problem was solved.

Git does not work that way. Every prior commit is still there and still readable by anyone who can clone the repository. The only real remediation is rotation at the provider — revoke the credential where it was issued so the copy in history becomes worthless. Scrubbing history with a filter tool is worth doing as cleanup, but it is not the fix and it will not help you if the repository was ever public or ever forked. Rotate first, tidy second.

How Do You Wire Up an MCP Server Without a Hardcoded Secret?

The practical pattern is straightforward and costs very little to adopt:

  • Use secret-manager references, not literals. The config should point at a secret, not contain one. Every major MCP client supports environment-variable interpolation, and every cloud vendor has a secrets service that can populate them at launch.
  • Scope down before you scope up. More than half the credentials in this dataset carried workspace- or database-wide access. An agent that reads three tables does not need a credential that can drop the schema.
  • Give every credential an expiry. Four out of five credentials with a policy defined still defaulted to never expiring. A token that rotates on a schedule limits the window on a leak you have not noticed yet.
  • Scan the history, not just the working tree. Pre-commit hooks catch the next mistake. A history scan catches the one you already made.

The structural answer is to remove the credential from the agent's path altogether, which is the direction behind Postman Passport's keyless API access for agents and the guardrail model in Noma's agent access control. A secret that never reaches the config cannot leak from it.

Treat Agents as Identities You Manage

The broader point in the research is a governance one, and it is the right lesson to take away. AI agents are non-human identities operating inside your systems, and they deserve the same lifecycle discipline as a service account: a record of which agent holds which access, what that access permits, who owns it, and when it gets revoked.

Most teams cannot answer those four questions about their agents today. That is a tractable problem, and the fix is inventory and ownership rather than new tooling. The NSA's MCP deployment guidance covers much of the same territory for anyone wanting a vendor-neutral reference.

One methodological note in the firm's favour: the researchers did not authenticate against any discovered service, and they describe their figures as lower-bound estimates because GitHub's search indexing does not surface everything. The real numbers are probably worse, which makes the fix more urgent rather than less. More defensive tooling and agent security in our AI security coverage.

Sources: Help Net Security — September 18, 2026, reporting on Hush Security's "The State of MCP Configuration: The Identity Security Gaps" research.

More Ai Security Stories