Uploaded August 2026 | Updated September 2026, 2 weeks ago
The oldest unsolved problem in the IT industry is . . . secret and credential exposure and AI agents just made it worse! If you've been spinning up AI tools — Claude Desktop, Cursor, Copilot, and so on — there's a decent chance that API keys, credentials, and access tokens are sitting in plaintext on your laptop. With MCP, every quickstart guide tells you to paste your credentials right into a config file. That was a bad habit before. Now it’s worse because we’re handing keys to agents. William Collins has a new open-source project to help with that - gridctl.
On today’s show we talk with William Collins about gridctl, a new open-source project he’s working on that, among other capabilities, helps make sure that developers aren’t exposing sensitive stuff as they build MCP servers and agentic toolchains and workflows.
William is a cloud and automation engineer and co-host of The Cloud Gambit on the Packet Pushers podcast network.
Links:
William Collins on LinkedIn - linkedin.com/in/william-collins
gridctl - github.com/gridctl/gridctl
The Cloud Gambit - packetpushers.net/podcast/the-cloud-gambit
Your MCP Config Is Leaking Secrets - wcollins.io/posts/2026/your-mcp-config-is-leaking-secrets
Your MCP Stack is a JSON Nightmare. Gridctl Fixes It. - wcollins.io/posts/2026/introducing-gridctl
PP083: A CISO's Perspective on Model Context Protocol (MCP) - packetpushers.net/podcasts/packet-protector/pp083-a-cisos-perspective-on-model-context-protocol-mcp
PP067: Protecting Secrets With Vault and TruffleHog - packetpushers.net/podcasts/packet-protector/pp067-protecting-secrets-with-vault-and-trufflehog
Packet Protector is part of the Packet Pushers network. Visit our website to find more great networking and technology podcasts, along with tutorial videos, the Human Infrastructure newsletter, and loads more resources for building your IT career. packetpushers.net
The oldest unsolved problem in the IT industry is . . . secret and credential exposure and AI agents just made it worse! If you've been spinning up AI tools — Claude Desktop, Cursor, Copilot, and so on — there's a decent chance that API keys, credentials, and access tokens are sitting in plaintext on your laptop. With MCP, every quickstart guide tells you to paste your credentials right into a config file. That was a bad habit before. Now it’s worse because we’re handing keys to agents. William Collins has a new open-source project to help with that - gridctl.
On today’s show we talk with William Collins about gridctl, a new open-source project he’s working on that, among other capabilities, helps make sure that developers aren’t exposing sensitive stuff as they build MCP servers and agentic toolchains and workflows.
William is a cloud and automation engineer and co-host of The Cloud Gambit on the Packet Pushers podcast network.
Links:
William Collins on LinkedIn - linkedin.com/in/william-collins
gridctl - github.com/gridctl/gridctl
The Cloud Gambit - packetpushers.net/podcast/the-cloud-gambit
Your MCP Config Is Leaking Secrets - wcollins.io/posts/2026/your-mcp-config-is-leaking-secrets
Your MCP Stack is a JSON Nightmare. Gridctl Fixes It. - wcollins.io/posts/2026/introducing-gridctl
PP083: A CISO's Perspective on Model Context Protocol (MCP) - packetpushers.net/podcasts/packet-protector/pp083-a-cisos-perspective-on-model-context-protocol-mcp
PP067: Protecting Secrets With Vault and TruffleHog - packetpushers.net/podcasts/packet-protector/pp067-protecting-secrets-with-vault-and-trufflehog
Packet Protector is part of the Packet Pushers network. Visit our website to find more great networking and technology podcasts, along with tutorial videos, the Human Infrastructure newsletter, and loads more resources for building your IT career. packetpushers.net










