Hush: 12% of public MCP config credential slots hardcode secrets
Hush Security scanned ~82,000 public MCP configs (Claude Code, Cursor, Codex, Windsurf, and others) and found 12% of credential slots hardcode a secret—55% of those lack scanner-recognizable token shapes. Among secrets with a defined expiry policy, 80% never expire by default.