Skip to main content
Glama

Scan for exposed secrets & misconfigurations

scan_for_secrets
Read-onlyIdempotent

Scan a pasted config, file, code snippet, or blob for exposed credentials and obvious security misconfigurations. Use whenever a user shares a .env, docker-compose.yml, nginx.conf, JSON/YAML config, or any text and asks "is this safe to share/commit?", "any leaked API keys/secrets?", or "what's misconfigured?". Detects cloud credentials, Stripe/GitHub/GitLab tokens, OpenAI/Anthropic/Gemini/Hugging Face/Groq/Replicate keys, private-key blocks, JWTs, DB connection strings, plus misconfigs like debug-on, 0.0.0.0 binds, disabled TLS verification, privileged containers, and weak passwords. Deterministic. It analyzes the provided text and returns findings only — it never stores, transmits, or requires any live credential.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
textNoA single blob to scan.
filesNoMultiple named files to scan.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations (readOnlyHint=true, destructiveHint=false, idempotentHint=true), the description adds critical behavioral context: it is deterministic, returns findings only, and 'never stores, transmits, or requires any live credential.' This gives the agent confidence that the operation is safe and non-invasive, going beyond the annotations alone.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense and front-loaded with the core action. Every sentence contributes useful information: what it scans, when to use it, what it detects, and behavioral guarantees. Despite its length, there is no fluff or redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given there is no output schema, the description compensates by mentioning 'returns findings only,' covering input types, detection categories, and safety guarantees. It fully equips the agent to select and invoke the tool correctly without needing additional context about return values or side effects.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema already provides full descriptions for both parameters ('text' as a single blob, 'files' as multiple named files), so baseline is 3. The description adds context about what kinds of content can be scanned (e.g., config snippets, code) but does not clarify whether text and files are mutually exclusive, which would add value. It does not significantly enhance parameter-level meaning beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's function with a specific verb ('Scan') and resource ('pasted config, file, code snippet, or blob') for detecting exposed credentials and security misconfigurations. It lists concrete detection categories (cloud credentials, API tokens, JWTs, misconfigs), making the purpose unmistakable. There are no sibling tools to differentiate from, so no distinction is needed.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit usage guidance is provided with example user intents ('is this safe to share/commit?', 'any leaked API keys/secrets?') and specific file types ('.env, docker-compose.yml, nginx.conf, JSON/YAML config'). It clearly tells the agent when to invoke this tool, making it easy to match against user requests.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources