I added my workarounds to this in MCP.json pass secrets securely - Feature Requests - Cursor - Community Forum - quoting from there:
Here are my personal knowledge garden entries which mention workarounds that use the 1Password CLI
op
to wrap invocation of various MCPs:GitHub/MCP/How To/Set up in Cursor with 1Password GH token
Anthropic/App/Claude Code/How To/Set Up Github MCP with 1Password GH token and mise
The basic approach I use is to create an executable script which controls the environment variables used to instantiate the process that runs the MCP server.