Skip to main content
Glama
AleBrito124356

mcp-secret-sentinel

scan_file

Read-onlyIdempotent

Scan a single file for exposed API keys, tokens, private keys, or high-entropy strings and return redacted findings; skip binary or files over 5 MB.

Instructions

Scan a single file for exposed secrets.

UTF-8, UTF-16 and UTF-32 text is decoded by byte-order mark. Binary files (null-byte heuristic) and files larger than 5 MB are skipped and reported as such in the summary.

Args: path: Absolute path to the file to scan. max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files.

Returns: The standard redacted findings report (see scan_text). Returns an error result if the file does not exist.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pathYes
max_findingsNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.2.0

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations, the description discloses important runtime behavior: encoding handling via byte-order marks, skipping binary and >5 MB files with reporting, and max_findings truncation metadata. It also states the error result if the file does not exist, which is valuable behavioral context not covered by annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is front-loaded with the core action, then structured into Args and Returns sections. Each part adds useful information for this two-parameter scanning tool, and there is no redundant filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the lack of an output schema and the tool's scoped complexity, the description is complete: it explains input semantics, file-handling limits, truncation behavior, and the return format by reference to scan_text. An agent has enough information to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must carry the burden, and it does: path is documented as an absolute file path, and max_findings explains the default, the unlimited value, ordering, and truncation-summary fields. This fully compensates for the empty schema descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource: 'Scan a single file for exposed secrets.' It clearly distinguishes file scanning from directory, git, and text-scanning siblings through the 'single file' scope, so an agent can identify the tool's role without inspecting the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The 'single file' phrasing implies the appropriate context, but the description does not explicitly say when to use this tool instead of scan_text, scan_directory, or the git-specific scanners. Usage is therefore present but left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.