secrets-leak-audit-mcp
Detects and redacts leaked GitHub personal access tokens (classic and fine-grained) in scanned text and added diff lines.
Detects and redacts leaked Google API keys in scanned text and added diff lines.
Detects and redacts leaked npm tokens in scanned text and added diff lines.
Detects and redacts leaked OpenAI API keys in scanned text and added diff lines.
Detects and redacts leaked SendGrid credentials in scanned text and added diff lines.
Detects and redacts leaked Slack tokens in scanned text and added diff lines.
Detects and redacts leaked Stripe live keys in scanned text and added diff lines.
Detects and redacts leaked Twilio credentials in scanned text and added diff lines.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@secrets-leak-audit-mcpscan this diff for any leaked API keys before I commit"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
secrets-leak-audit-mcp
An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops" in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example that includes a real key, or writing a test fixture with a plausible-looking but real value).
What it catches
High-precision vendor key matches. Real, current (2026) structural formats for AWS access keys, GitHub PATs
(classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm
tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded
credentials. These are precise format matches, not guesses — an AWS key is AKIA/ASIA + 16 specific
characters, not "looks like it might be a key."
Entropy-based fallback. For secret-shaped variable names (API_KEY, PASSWORD, *_TOKEN) with no
recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated
credential and "password123" both match a suspicious name, but only one has the entropy of an actual secret —
flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic.
Every match is redacted before it's returned — the tool never echoes a full secret value back, even to confirm a hit.
Related MCP server: pr-guard-mcp
Tools
scan_for_secrets
Scans any text (a file's contents, a config snippet) for both categories above.
scan_diff
Scans a unified git diff and only checks lines the diff actually adds — won't flag a secret that was
already being removed in the same diff, or one that only appears in unchanged context lines.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
npm install
node server.jsPart of a small suite
github-actions-audit-mcp, dockerfile-audit-mcp, regex-safety-audit-mcp, mcp-trust-audit-mcp.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Risk-scan a diff, flag AI-generated-code tells, find secrets. 5 of 7 tools need no account.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Security reviews for coding agents: diffs checked against your org policy and live infrastructure.
Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.
Related MCP Servers
- AlicenseAqualityBmaintenanceEnables scanning diffs or code blobs for leaked secrets, returning a verdict with severity and masked findings, all processed locally with no data sent externally.1MIT
- FlicenseDqualityCmaintenanceEnables AI agents to perform security audits on pull request diffs by detecting secrets, dangerous code patterns, and new dependencies, outputting structured JSON for generating PR review comments.1-
- AlicenseAqualityAmaintenanceScans code strings for hardcoded secrets (AWS keys, tokens, private keys, etc.) and returns redacted findings, helping AI coding agents catch secrets before writing or committing code.1MIT
- AlicenseAqualityCmaintenanceScans diffs, files, and snippets for leaked secrets like AWS keys, GitHub tokens, and private keys, returning redacted findings while running fully locally without network calls.1MIT