$ python3 scripts/scan.py --root .AGENT CONNECTIONS: 6 · highest blast radius: DatabaseCREDENTIALS IN PLAIN TEXT: 6 (values are never read out)line 3 postgresql connection-string password: 13 chars [postgresql://admin:<redacted>@prod-db.internal:5432]cred1 fail 6 credential(s) in plain text in agent config. A compromised session yields replayable credentials.cred2 fail Credentials sit in the agent runtime's own config, not managed separately.$ python3 scripts/scan.py --selftest✓ RESULT: PASS · no secret material in output
Real run · python3 scripts/scan.py on the scanner's self-test fixture (.mcp.json with six fake credentials), 23 Sep 2026
Not met · cred1 and cred2: a database password sits in plain text in the agent's own MCP config
line 3 · postgresql connection-string password, 13 chars · [postgresql://admin:<redacted>@prod-db.internal:5432] · 6 plaintext credentials found, 0 values printed
One machine is one machine: a local scan can falsify an org-wide claim but never confirm one. Every finding is a proposal the user confirms or corrects.
Move the credential behind a broker or gateway that injects auth server-side, rotate the password, then re-run the scan.