ghosthunt
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| scan_secretsA | Scan your entire machine for leaked API keys, tokens, and credentials. Checks .env files, AWS/SSH/Docker/npm configs, shell history, and more. Returns a detailed report with risk explanations, rotation URLs, and fix guidance. Also returns structured JSON data (in a second content block) for visual rendering. If you have visualization capabilities, render the JSON as a visual dashboard with a health score gauge, color-coded finding cards, and auto-fix indicators. Everything runs locally -- no data leaves your machine. |
| fix_secretsA | Fix leaked secrets found on your machine. Auto-cleans shell history (backs up first), adds .env to .gitignore where missing, and provides step-by-step rotation instructions with direct links for secrets that need manual rotation. Returns structured JSON (in a second content block) with before/after health scores for visual rendering. If you have visualization capabilities, render the JSON as a fix report dashboard with before/after health score comparison and auto-fixed item list. Run scan_secrets first to see what will be fixed. |
| scan_summaryA | Quick health check -- counts how many secrets are on your machine and gives you a health score (0-100). Faster than a full scan. Run scan_secrets for details, or fix_secrets to clean up. |
| ghosthunt_statusA | Show GhostHunt version and license status. Displays whether you're on the Free or Pro tier and what Pro includes. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 4 tools
Each tool has a distinct purpose: scanning for secrets, fixing them, quick summary, and status. No overlap or ambiguity.
Most tools use a consistent verb_noun pattern (scan_secrets, fix_secrets, scan_summary), but ghosthunt_status deviates slightly from the 'scan' prefix, though it is still descriptive.
Four tools is well-scoped for a focused security scanning server, covering essential workflows without bloat.
Core scan, fix, and health check are covered. Missing perhaps an exclusion or configuration tool, but the essential lifecycle is present.