
What happened
Astrix Research examined 5,200 MCP servers and found 53 percent depend on static credentials like API keys or access tokens, while 79 percent of API keys are simply read from environment variables.
Why it matters
Storing API keys in a .env file assumes a human developer controls secrets, but an AI agent reading those keys can be manipulated into sending them externally even without being compromised.
What to watch
Tool poisoning attacks are already documented, with MCPTox reporting an average attack success rate of 36.5 percent and 72.8 percent in some cases, so the test is whether OAuth and other safeguards replace static secrets.
WHO IT HITSSecurity teams and developers who connect AI agents to internal systems such as CRM, databases, and email services need to rethink whether static API keys stored in .env files are safe, because the body describes a case where leaked keys turned an agent into an insider threat.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
The article describes a shift in how developers connect AI agents to services. Previously, a single developer could hold one credential for one service and manage that secret themselves. Now, AI agents often access tools, data sources, and APIs through a growing number of credentials that are not clearly owned by any one person.
The body cites two pieces of evidence that illustrate the problem. GitGuardian reported a roughly eightfold increase in leaked authentication credentials for AI-related services over the past year. Separately, Astrix Research examined 5,200 MCP servers and found that 53 percent relied on static credentials and that 79 percent of API keys were read from environment variables. The article notes these practices were designed under the assumption that a human controls the secret and its scope, which no longer holds when an agent reads those credentials automatically.
The stakes hinge on whether organizations can replace static secrets with stronger mechanisms like OAuth before attacks become widespread. The body describes tool poisoning as emerging, and cites a report of a supply chain attack in February 2026 where attackers registered a fake MCP server as a legitimate listing. For security teams, the outcome likely depends on whether the industry adopts more secure authentication before more agents are deployed with broad access.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Aron Inc. launched with $8 million raised across two rounds
Pedro Andrade, Talkdesk's VP of AI and generative AI business specialist, told theCUBE that CXA is "an operati…
In a Google DeepMind experiment, 100 Gemini 3.1 Pro agents were told to act as top math researchers and solve…

TechTouch surveyed 319 people overseeing generative AI at firms with over 1,000 employees

On Sept. 14, Trump posted on Truth Social that AI needs no guardrails beyond a strong, smart president, named…

Trump said on Monday the U.S
