MCP Config Access
- Category
- Agent Snooping
- Confidence
- 95% confidence
- Finding
The setup directs users to place plaintext credentials into project-level or user-level MCP config files, including under
~/.claude/mcp.json, which can expose secrets to local compromise, backups, source control mistakes, or other tools that read configuration. Because the skill specifically names credential-bearing env vars and a common agent config path, it materially increases the chance of unsafe secret handling rather than merely referencing configuration in the abstract.- Content
Option A — npx (recommended)
Add to
.mcp.jsonin your project or~/.claude/mcp.json:json {
