
blog.trailofbits.com/2025/04/30/insecure-credential-storage-plagues-mcp
Preview meta tags from the blog.trailofbits.com website.
Linked Hostnames
12- 11 links toblog.trailofbits.com
- 9 links togithub.com
- 1 link todeveloper.apple.com
- 1 link togohugo.io
- 1 link toinfosec.exchange
- 1 link tolearn.microsoft.com
- 1 link tolinkedin.com
- 1 link tomodelcontextprotocol.io
Thumbnail

Search Engine Appearance
https://blog.trailofbits.com/2025/04/30/insecure-credential-storage-plagues-mcp
Insecure credential storage plagues MCP
This post describes how many examples of MCP software store long-term API keys for third-party services in plaintext on the local filesystem, often with insecure, world-readable permissions.
Bing
Insecure credential storage plagues MCP
https://blog.trailofbits.com/2025/04/30/insecure-credential-storage-plagues-mcp
This post describes how many examples of MCP software store long-term API keys for third-party services in plaintext on the local filesystem, often with insecure, world-readable permissions.
DuckDuckGo

Insecure credential storage plagues MCP
This post describes how many examples of MCP software store long-term API keys for third-party services in plaintext on the local filesystem, often with insecure, world-readable permissions.
General Meta Tags
7- titleInsecure credential storage plagues MCP - The Trail of Bits Blog
- charsetUTF-8
- viewportwidth=device-width,initial-scale=1
- description
- article:sectionposts
Open Graph Meta Tags
7- og:urlhttps://blog.trailofbits.com/2025/04/30/insecure-credential-storage-plagues-mcp/
- og:site_nameThe Trail of Bits Blog
- og:titleInsecure credential storage plagues MCP
- og:descriptionThis post describes how many examples of MCP software store long-term API keys for third-party services in plaintext on the local filesystem, often with insecure, world-readable permissions.
og:locale
en_us
Twitter Meta Tags
4- twitter:cardsummary_large_image
- twitter:imagehttps://blog.trailofbits.com/img/Trail-of-Bits-Open-Graph.png
- twitter:titleInsecure credential storage plagues MCP
- twitter:descriptionThis post describes how many examples of MCP software store long-term API keys for third-party services in plaintext on the local filesystem, often with insecure, world-readable permissions.
Link Tags
11- dns-prefetch//fonts.googleapis.com
- dns-prefetch//fonts.gstatic.com
- preconnecthttps://fonts.gstatic.com
- preload stylesheet/css/syntax.css
- shortcut icon/favicon.png
Links
30- https://blog.trailofbits.com
- https://blog.trailofbits.com/2025/04/21/jumping-the-line-how-mcp-servers-can-attack-you-before-you-ever-use-them
- https://blog.trailofbits.com/2025/04/23/how-mcp-servers-can-steal-your-conversation-history
- https://blog.trailofbits.com/2025/04/29/deceiving-users-with-ansi-terminal-codes-in-mcp
- https://blog.trailofbits.com/2025/04/30/insecure-credential-storage-plagues-mcp