MCP Runtime Process Reading AWS/SSH Credential Files

Detects common runtime processes (Node.js, npx, Python) often used for Model Context Protocol (MCP) servers accessing sensitive local credential files such as AWS credentials, SSH private keys, or environment files. This behavior is indicative of potential credential harvesting by unauthorized MCP servers in developer environments.