mcp-secret-scrub
Detects and redacts Discord webhook URLs in text, returning only the secret type, count, and position without exposing the value.
Detects and redacts GitHub tokens such as ghp_, gho_, ghu_, ghs_, ghr_, and github_pat_ credentials.
Detects and redacts Redis connection strings to prevent credential leakage in logs or agent context.
Detects and redacts Slack tokens (xox...) and related credentials in text.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-secret-scrubscrub secrets from this log before it goes to the agent"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-secret-scrub
mcp-name: io.github.sudo-ai-git/mcp-secret-scrub
Deterministic, no-LLM MCP server that scrubs secrets from text, logs, and transcripts before they enter agent context — and never leaks the value.
No LLM. No network. Pure structural detection. MIT. Crown-jewel-free.
The problem it solves
Before you hand raw text to an agent (or store it, or pass it to a tool), you
often don't know whether it contains a live secret. Platform scrubbers miss
patterns all the time — a private key, an nvapi- token, a github_pat_
token, an api_key= assignment mid-log. If that text reaches an LLM context
or a persisted transcript, the secret is effectively exfiltrated.
This server answers, deterministically:
Which secrets are in this text, and can you redact them safely before it goes anywhere?
Related MCP server: ai-security-gateway-mcp
Detection coverage (deterministic profiles)
family | examples |
AI provider keys |
|
Cloud / GitHub |
|
Identity / auth | JWTs ( |
Assignments |
|
Endpoints / DSNs | Discord webhooks, Slack |
The scan never returns the secret value — only its type, count, and position. That is a hard safety contract, enforced by test.
Tools (MCP)
tool | purpose |
| redact / mask / hash secrets; returns scrubbed text (never the value) |
| detect which secret types are present (no mutation) |
| scan + redact in one call, scrubbed preview + findings |
| list all supported detection profiles |
Modes:
redact(default) →[REDACTED:TYPE]mask→ shows first 4 + last 2 charshash→ deterministic SHA-256 prefix (reproducible across calls)
Quick start (stdio)
pip install mcp-secret-scrub
mcp-secret-scrub # stdio (default)Or via uv/pipx for an installable console entry:
pipx install mcp-secret-scrubMCP client config:
{ "mcpServers": {
"secret-scrub": { "command": "mcp-secret-scrub" }
}}Streamable HTTP (remote / Smithery-publishable)
python3 mcp_server.py --http --port 8138 # serves on http://<host>:8138/mcp/Determinism & safety guarantees
Deterministic: same input → identical output in every mode, every call.
Never leaks:
scan_textandscrub_textnever emit the original token;_deterministic_hashis SHA-256 (no salt) so output is reproducible.No LLM, no network: pure regex + reachable structure detection.
Input-safe: non-string input returns a clean error, not a traceback.
Verification
python3 test_detector.py— 14/14 core checks (detection, redaction, determinism, no-leak contract, benign/unicode/empty input, bad-mode)python3 test_e2e.py— drives the real MCP stdio transport and asserts the secret does NOT cross the wire
License & provenance
MIT. Part of the sudo-ai-git deterministic no-LLM agent-trust MCP family
(mcp-skill-sec · mcp-verify-claim · mcp-benchmark-hygiene ·
mcp-secret-scrub).
This server cannot be deployed
Maintenance
Related MCP Connectors
Redact PII from text before it reaches a model. Nothing stored, no third-party AI.
Secrets for developers and agents—secure context and workflows without exposing secret values.
Deterministic runtime safety for AI agents: scan PII, gate tool actions, verify LLM output.
Detects and redacts PII (emails, phones, SSNs, names, addresses) from text. $0.02/call via x402.
Related MCP Servers
AlicenseAqualityBmaintenanceEnables AI agents to scan text for leaked secrets and prompt injection markers, and redact them before reaching an LLM.21MIT- AlicenseAqualityDmaintenanceScans prompts for PII and masks or redacts sensitive data locally before sending to an LLM, supporting multiple anonymization modes.1MIT
- FlicenseNot gradedqualityDmaintenanceEnables AI agents to redact PII from text, summarize redacted content, and manage custom redaction patterns across multiple languages.-
- AlicenseAqualityAmaintenanceSanitizes text and files by removing PII, secrets, and custom patterns locally before sending to LLMs, with optional reverse-scrubbing.3507 npm2Cryptographic Autonomy 1.0 (Combined Work Exception)