Skip to main content
Glama

Server Details

Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.

Status
Healthy
Last Tested
Transport
Streamable HTTP
URL

Glama MCP Gateway

Connect through Glama MCP Gateway for full control over tool access and complete visibility into every call.

MCP client
Glama
MCP server

Full call logging

Every tool call is logged with complete inputs and outputs, so you can debug issues and audit what your agents are doing.

Tool access control

Enable or disable individual tools per connector, so you decide what your agents can and cannot do.

Managed credentials

Glama handles OAuth flows, token storage, and automatic rotation, so credentials never expire on your clients.

Usage analytics

See which tools your agents call, how often, and when, so you can understand usage patterns and catch anomalies.

100% free. Your data is private.
Tool DescriptionsA

Average 4.7/5 across 1 of 1 tools scored.

Server CoherenceA
Disambiguation5/5

With only one tool, there is no possibility of confusion. scan_for_secrets has a clear, singular purpose of analyzing text for secrets and misconfigurations.

Naming Consistency5/5

The single tool uses a clear verb_noun pattern (scan_for_secrets), and there are no other tools to create inconsistency.

Tool Count4/5

The server has only one tool, which is slightly below the typical range, but the tool is comprehensive and handles a wide variety of inputs and detections, making the count reasonable.

Completeness5/5

The tool covers the full scope of the secret scanner domain, detecting a wide range of credentials and misconfigurations and returning findings. There are no obvious gaps for the stated purpose.

Available Tools

1 tool
scan_for_secretsScan for exposed secrets & misconfigurationsA
Read-onlyIdempotent
Inspect

Scan a pasted config, file, code snippet, or blob for exposed credentials and obvious security misconfigurations. Use whenever a user shares a .env, docker-compose.yml, nginx.conf, JSON/YAML config, or any text and asks "is this safe to share/commit?", "any leaked API keys/secrets?", or "what's misconfigured?". Detects cloud credentials, Stripe/GitHub/GitLab tokens, OpenAI/Anthropic/Gemini/Hugging Face/Groq/Replicate keys, private-key blocks, JWTs, DB connection strings, plus misconfigs like debug-on, 0.0.0.0 binds, disabled TLS verification, privileged containers, and weak passwords. Deterministic. It analyzes the provided text and returns findings only — it never stores, transmits, or requires any live credential.

ParametersJSON Schema
NameRequiredDescriptionDefault
textNoA single blob to scan.
filesNoMultiple named files to scan.
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations (readOnlyHint=true, destructiveHint=false, idempotentHint=true), the description adds critical behavioral context: it is deterministic, returns findings only, and 'never stores, transmits, or requires any live credential.' This gives the agent confidence that the operation is safe and non-invasive, going beyond the annotations alone.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense and front-loaded with the core action. Every sentence contributes useful information: what it scans, when to use it, what it detects, and behavioral guarantees. Despite its length, there is no fluff or redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given there is no output schema, the description compensates by mentioning 'returns findings only,' covering input types, detection categories, and safety guarantees. It fully equips the agent to select and invoke the tool correctly without needing additional context about return values or side effects.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema already provides full descriptions for both parameters ('text' as a single blob, 'files' as multiple named files), so baseline is 3. The description adds context about what kinds of content can be scanned (e.g., config snippets, code) but does not clarify whether text and files are mutually exclusive, which would add value. It does not significantly enhance parameter-level meaning beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's function with a specific verb ('Scan') and resource ('pasted config, file, code snippet, or blob') for detecting exposed credentials and security misconfigurations. It lists concrete detection categories (cloud credentials, API tokens, JWTs, misconfigs), making the purpose unmistakable. There are no sibling tools to differentiate from, so no distinction is needed.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit usage guidance is provided with example user intents ('is this safe to share/commit?', 'any leaked API keys/secrets?') and specific file types ('.env, docker-compose.yml, nginx.conf, JSON/YAML config'). It clearly tells the agent when to invoke this tool, making it easy to match against user requests.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Discussions

No comments yet. Be the first to start the discussion!

Related MCP Servers

  • A
    license
    -
    quality
    A
    maintenance
    Detects leaked credentials in source code with tools to scan text, files, and directories for API keys, tokens, and private keys across 30+ providers.
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables scanning diffs or code blobs for leaked secrets, returning a verdict with severity and masked findings, all processed locally with no data sent externally.
    1
    MIT
  • A
    license
    -
    quality
    C
    maintenance
    Scans code for exposed secrets, API keys, tokens, and credentials across 69 patterns covering cloud services, AI platforms, payment providers, authentication services, and databases.
    MIT

View all MCP Servers

Try in Browser

Your Connectors

Sign in to create a connector for this server.

Resources