GitGuardian finds thousands of valid API keys exposed in public GitHub config files

In 2025, GitGuardian discovered 24,008 unique secrets in public MCP configuration files on GitHub, with 2,117 being valid credentials. These credentials were not leaked via an exploit but were mistakenly placed into public repository configs, a practice often suggested in setup guides. The article details how secrets can leak through prompts, tool responses, logs, and agent memory, making them accessible to the AI model. It recommends storing credentials in an encrypted vault that the model cannot query, using a trusted proxy layer to attach them to requests. This method ensures the AI agent never directly handles or sees the raw API tokens.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in