AI Coding Agents Are Leaking Credentials: Cursor, Claude Code, Copilot, and MCP
Cursor, Claude Code, and GitHub Copilot leave credentials scattered across config files, logs, and shell history that repository and CI scanners never see. Here's where that trail actually lives, and how to close it.