Hush Security
7 stats1 reports
All Statistics
1,394 secrets remain live in current credential-bearing MCP configuration files.
Version ControlSecrets PersistenceConfiguration Security
243 secrets that were removed from MCP configuration files remain fully readable in earlier Git commits.
Version ControlSecrets PersistenceIncident Response
53% of leaked credentials with a definable scope are organization-, account-, workspace-, or database-wide.
Access ManagementCredentials
80% of leaked credentials in MCP configuration files with a defined expiry policy never expire by default.
Access ManagementCredentialsSecrets Management
24% of all hardcoded secrets in the MCP dataset are both broad-scope and non-expiring.
Secrets ManagementAccess Management
12% of credential slots in public MCP configuration files hardcode a secret.
Secrets ManagementConfiguration SecurityNon-Human Identity
55% of hardcoded secrets in MCP configuration files have no vendor-recognizable token shape.
Secrets ManagementSecret ScanningSoftware Security