Skip to main content
Glama
tylerscomic-lab

secrets-leak-audit-mcp

secrets-leak-audit-mcp

License: MIT Live on MCPize

An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops" in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example that includes a real key, or writing a test fixture with a plausible-looking but real value).

What it catches

High-precision vendor key matches. Real, current (2026) structural formats for AWS access keys, GitHub PATs (classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded credentials. These are precise format matches, not guesses — an AWS key is AKIA/ASIA + 16 specific characters, not "looks like it might be a key."

Entropy-based fallback. For secret-shaped variable names (API_KEY, PASSWORD, *_TOKEN) with no recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated credential and "password123" both match a suspicious name, but only one has the entropy of an actual secret — flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic.

Every match is redacted before it's returned — the tool never echoes a full secret value back, even to confirm a hit.

Related MCP server: pr-guard-mcp

Tools

scan_for_secrets

Scans any text (a file's contents, a config snippet) for both categories above.

scan_diff

Scans a unified git diff and only checks lines the diff actually adds — won't flag a secret that was already being removed in the same diff, or one that only appears in unchanged context lines.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

npm install
node server.js

Part of a small suite

github-actions-audit-mcp, dockerfile-audit-mcp, regex-safety-audit-mcp, mcp-trust-audit-mcp.

License

MIT

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    B
    maintenance
    Enables scanning diffs or code blobs for leaked secrets, returning a verdict with severity and masked findings, all processed locally with no data sent externally.
    1
    MIT
  • F
    license
    D
    quality
    C
    maintenance
    Enables AI agents to perform security audits on pull request diffs by detecting secrets, dangerous code patterns, and new dependencies, outputting structured JSON for generating PR review comments.
    1
    -
  • A
    license
    A
    quality
    C
    maintenance
    Scans diffs, files, and snippets for leaked secrets like AWS keys, GitHub tokens, and private keys, returning redacted findings while running fully locally without network calls.
    1
    MIT