Report by Hush Security

The State of MCP Configuration: the Identity Security Gaps

7 FINDINGSPublished Sep 17, 2026
View Original Report →

Key Findings

1,394 secrets remain live in current credential-bearing MCP configuration files.

Version ControlSecrets PersistenceConfiguration Security

243 secrets that were removed from MCP configuration files remain fully readable in earlier Git commits.

Version ControlSecrets PersistenceIncident Response

53% of leaked credentials with a definable scope are organization-, account-, workspace-, or database-wide.

Access ManagementCredentials

80% of leaked credentials in MCP configuration files with a defined expiry policy never expire by default.

Access ManagementCredentialsSecrets Management

24% of all hardcoded secrets in the MCP dataset are both broad-scope and non-expiring.

Secrets ManagementAccess Management

12% of credential slots in public MCP configuration files hardcode a secret.

Secrets ManagementConfiguration SecurityNon-Human Identity

55% of hardcoded secrets in MCP configuration files have no vendor-recognizable token shape.

Secrets ManagementSecret ScanningSoftware Security