secret-scanner
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| scan_for_secretsA | Scan a blob of code, text, or a unified diff for LEAKED SECRETS before you commit, push, open a PR, or paste it somewhere. Detects provider API keys (AWS, GitHub, OpenAI, Anthropic, Stripe, Google, Slack, Twilio, SendGrid, npm, Telegram, Discord, Shopify, Cloudflare and more), generic tokens, private keys (RSA/EC/DSA/OpenSSH/PGP), JWTs, database connection strings with passwords, basic-auth URLs, and high-entropy strings that look like credentials. Returns a CLEAN / REVIEW / LEAK verdict with each finding's secret type, provider, severity, line:column, a MASKED excerpt (never the full secret), and a remediation note. Use this on every diff/file you are about to share. The scan is fully local — the secret is never sent anywhere. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 1 tool
Only one tool exists, so there is no risk of confusion or overlap between tools.
With a single tool, naming is trivially consistent; the name 'scan_for_secrets' clearly describes its action.
A single tool for a focused purpose like secret scanning is reasonable, though additional tools for repository scanning or configuration could be expected for broader coverage.
The tool comprehensively scans various secret types and provides detailed findings, but lacks capabilities like scanning entire repositories or managing ignore lists, which are minor gaps.