mcp-secret-sentinel
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| scan_textA | Scan a snippet of text or code for exposed secrets. 33 detectors: GitHub/GitLab/npm/PyPI tokens, OpenAI (incl. sk-proj-), Anthropic, OpenRouter, Groq, NVIDIA and Hugging Face keys, AWS, Azure, Google, DigitalOcean, Stripe, Shopify, SendGrid, Twilio, Slack, Discord and Telegram credentials, JWTs, private and age keys, credentialed connection strings and URLs, generic password/secret/token assignments, plus high-entropy strings. Placeholders ($VAR, ${VAR}, {{ templates }}, %(name)s, changeme, masked values...) are skipped, and a line carrying "secret-sentinel: ignore" or "pragma: allowlist secret" is counted in "suppressed" instead of reported. Args: text: The raw text to scan (code, config, diff output, logs...). source_name: Label used in each finding's "file" field. max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files. Returns: {"clean": bool, "findings": [{"file", "line", "pattern", "severity", "redacted", "advice"}], "files_scanned": int, "summary": str} Secret values are ALWAYS redacted (at most 4 chars, never more than a quarter of the value, + length); the full value is never included. |
| scan_fileA | Scan a single file for exposed secrets. UTF-8, UTF-16 and UTF-32 text is decoded by byte-order mark. Binary files (null-byte heuristic) and files larger than 5 MB are skipped and reported as such in the summary. Args: path: Absolute path to the file to scan. max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files. Returns: The standard redacted findings report (see scan_text). Returns an error result if the file does not exist. |
| scan_directoryA | Recursively scan a directory tree for exposed secrets. Automatically skips .git, node_modules, virtualenvs and conda envs under any name, site-packages, tool caches (.tox, .nox, .mypy_cache, .pytest_cache, .ruff_cache), pycache, dist, build, minified JS bundles, lockfiles, binaries, files over 5 MB, and simple patterns from the root .gitignore (best-effort: no negations, no ** globs). Args: path: Absolute path to the directory to scan. max_files: Stop after scanning this many files (default 500). max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files. Returns: The standard redacted findings report; finding paths are relative to the scanned root, using forward slashes. |
| scan_git_stagedA | Scan ONLY the lines currently staged for commit (git diff --cached). This is the pre-commit checkpoint: it inspects exactly the content the next commit would publish, and reports the file and post-commit line number of every added secret. Local diff settings (external diff tools, textconv filters, prefixes, path quoting) are overridden, and git runs no configured programs. Args: repo_path: Absolute path to a git repository (or any path inside one). max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files. Returns: The standard redacted findings report. If nothing is staged the result is clean with an explanatory summary. |
| scan_git_historyA | Scan the lines added by the most recent commits (git log -p). Each finding is tagged with the short hash of the commit that introduced it. A secret that was later deleted is still reported — history retains it, so the credential must be rotated regardless. Args: repo_path: Absolute path to a git repository (or any path inside one). max_commits: How many commits back to inspect (default 50). all_branches: Walk every branch, tag and the stash instead of only the history of HEAD (default false). max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files. Returns: The standard redacted findings report, with a "commit" field on each finding. |
| scan_git_rangeA | Scan the commits in base..head: by default, what Run this before pushing. With the defaults it scans every commit on the current branch that its upstream does not have yet. If the branch has no upstream, the error says so: pass the branch you will push to as base (for example "origin/main"). Args: repo_path: Absolute path to a git repository (or any path inside one). base: Commits reachable from here are excluded (default "@{upstream}"). head: Last commit to include (default "HEAD"). max_commits: Scan at most this many of the newest commits in the range. max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files. Returns: The standard redacted findings report with a "commit" field on each finding, plus "commits_scanned" and "range". |
| list_patternsA | List the active secret detectors and allowlist rules. Returns: {"count": int, "patterns": [{"name", "severity", "advice"}], "entropy_detector": {...threshold and advice...}, "allowlist_rules": [{"name", "description"}]} Raw regexes are intentionally not exposed. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 7 tools
Each tool has a clearly distinct input target: raw text, single file, directory tree, git staged diff, git history, and a git range. The three git tools (staged/history/range) could superficially overlap, but their descriptions crisply define different scopes (pre-commit checkpoint, past commits, pre-push range), and list_patterns is clearly the only non-scanning tool.
All seven tools follow a strict verb_noun convention (list_patterns, scan_text, scan_file, scan_directory, scan_git_staged, scan_git_history, scan_git_range). The scan_git_* family is a predictable, self-describing sub-pattern that makes the set easy to navigate.
Seven tools is well-scoped for a secret scanner: one introspection tool plus six scan variants covering distinct sources, with no redundant or filler entries. Each tool earns its place by addressing a different context (editor text, file, tree, pre-commit, history, pre-push).
The surface covers the full scanning lifecycle (ad-hoc text, files, directories, staged changes, history, push range) plus detector introspection, which is strong. The only gap is that allowlist/detector configuration is read-only (list_patterns) with no way to add or modify rules via tools, though this is plausibly handled by external config files.