MCP credential weakness raises red flags
ID: 1e1bcd47-a218-58b7-8f8b-69e9882341b5
STIX ID: report--1e1bcd47-a218-58b7-8f8b-69e9882341b5
Feed Name: ReversingLabs Blog
Astrix Security analyzed 5,200 open-source MCP servers and found pervasive authentication weaknesses: 53% rely on long-lived static secrets (API keys/PATs), only 8.3% support OAuth, and many store credentials in environment variables, exposing organizations to persistent access, data exfiltration, and expanded attack surfaces for AI agents. Experts warn that traditional tools lack visibility into MCP behaviors and that cultural and governance gaps (e.g., absent token rotation, scoped credentials, and vault-based retrieval) exacerbate risk. Astrix released an open-source wrapper that fetches secrets just-in-time from AWS Secrets Manager to reduce static exposure, but practitioners emphasize the need for comprehensive identity lifecycle management, runtime attestation, and policy enforcement to secure agentic AI infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
