Severity

high

Exposure

4/5

Date of incident

April 15, 2025
Risky MCP Server Deployments

reported

Tier -

B

Exposed MCP servers leaked credentials — no proxy gate on agent tool egress.
What Happened
Researchers scanned public MCP endpoints and found live API keys, open admin tools, and missing auth on tool handlers — agents could invoke them from developer workstations.
Sumarry
Wiz security research identified MCP server deployments exposing credentials and over-permissioned tool handlers reachable by IDE agents.
Detect
NHIM-014 + MCP endpoint exposure scan
What Happened
MCP proxy allow-list + mask secrets in tool args
Blekline //
MCP proxy + credential mask on tool args
Without agent boundary //
Developer installs any MCP URL from registry without org allow-list

Looking to integrate AI company-wide?