Hardcoded MCP credentials are exposing AI coding agents’ connections to GitHub, databases, Slack, Notion, and other services. Hush Security’s analysis of about 82,000 public GitHub configuration files found that 12% of credential slots contained literal secrets, while more than half were difficult for conventional scanners to recognize.
Source