AIToday
Large Language ModelsAI Coding AssistantsAI Safety & AlignmentITmedia AI+Published: Sep 15, 2026, 06:00 JST

Over half of MCP servers rely on static API keys, Astrix finds

Over half of MCP servers rely on static API keys, Astrix finds

3 Key Points

  1. What happened

    Astrix Research examined 5,200 MCP servers and found 53 percent depend on static credentials like API keys or access tokens, while 79 percent of API keys are simply read from environment variables.

  2. Why it matters

    Storing API keys in a .env file assumes a human developer controls secrets, but an AI agent reading those keys can be manipulated into sending them externally even without being compromised.

  3. What to watch

    Tool poisoning attacks are already documented, with MCPTox reporting an average attack success rate of 36.5 percent and 72.8 percent in some cases, so the test is whether OAuth and other safeguards replace static secrets.

WHO IT HITSSecurity teams and developers who connect AI agents to internal systems such as CRM, databases, and email services need to rethink whether static API keys stored in .env files are safe, because the body describes a case where leaked keys turned an agent into an insider threat.

Ask the AI about this article →

Summaries like this, in your inbox every morning.

Context & Analysis

The article describes a shift in how developers connect AI agents to services. Previously, a single developer could hold one credential for one service and manage that secret themselves. Now, AI agents often access tools, data sources, and APIs through a growing number of credentials that are not clearly owned by any one person.

The body cites two pieces of evidence that illustrate the problem. GitGuardian reported a roughly eightfold increase in leaked authentication credentials for AI-related services over the past year. Separately, Astrix Research examined 5,200 MCP servers and found that 53 percent relied on static credentials and that 79 percent of API keys were read from environment variables. The article notes these practices were designed under the assumption that a human controls the secret and its scope, which no longer holds when an agent reads those credentials automatically.

The stakes hinge on whether organizations can replace static secrets with stronger mechanisms like OAuth before attacks become widespread. The body describes tool poisoning as emerging, and cites a report of a supply chain attack in February 2026 where attackers registered a fake MCP server as a legitimate listing. For security teams, the outcome likely depends on whether the industry adopts more secure authentication before more agents are deployed with broad access.

FAQ
What is an MCP server?
MCP stands for Model Context Protocol, which the body describes as becoming a standard for connecting AI agents to tools.
How do tool poisoning attacks work?
In a tool poisoning attack, malicious instructions are embedded in tool descriptions or return values that the agent reads, then executed as part of its normal processing.
What did MCPTox find about attack success rates?
MCPTox reported an average attack success rate of 36.5 percent, reaching 72.8 percent in some environments, according to the body.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Aron launches with $8 million to automate procurement RFQsSiliconANGLE AI · 39m ago
  • Talkdesk's Andrade: 98% deploy AI, only 15% orchestrateSiliconANGLE AI · 39m ago
  • Google DeepMind: 100 AI agents split 24-14 over cheatingMITテクノロジーレビュー · 39m ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleBroadcom slips over 4% as $21.7 billion AI forecast meets slowdown fears