secrets-leak-audit-mcp
README.md
# secrets-leak-audit-mcp
[](LICENSE)
[](https://mcpize.com/mcp/secrets-leak-audit-mcp)
An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops"
in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example
that includes a real key, or writing a test fixture with a plausible-looking but real value).
## What it catches
**High-precision vendor key matches.** Real, current (2026) structural formats for AWS access keys, GitHub PATs
(classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm
tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded
credentials. These are precise format matches, not guesses — an AWS key is `AKIA`/`ASIA` + 16 specific
characters, not "looks like it might be a key."
**Entropy-based fallback.** For secret-shaped variable names (`API_KEY`, `PASSWORD`, `*_TOKEN`) with no
recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated
credential and `"password123"` both match a suspicious name, but only one has the entropy of an actual secret —
flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic.
**Every match is redacted before it's returned** — the tool never echoes a full secret value back, even to
confirm a hit.
## Tools
### `scan_for_secrets`
Scans any text (a file's contents, a config snippet) for both categories above.
### `scan_diff`
Scans a unified `git diff` and only checks lines the diff actually **adds** — won't flag a secret that was
already being removed in the same diff, or one that only appears in unchanged context lines.
## Use it
**Hosted (recommended):** [MCPize](https://mcpize.com/mcp/secrets-leak-audit-mcp) — free tier, $7/mo Pro.
**Self-host:**
```bash
npm install
node server.js
```
## Part of a small suite
[github-actions-audit-mcp](https://github.com/tylerscomic-lab/github-actions-audit-mcp),
[dockerfile-audit-mcp](https://github.com/tylerscomic-lab/dockerfile-audit-mcp),
[regex-safety-audit-mcp](https://github.com/tylerscomic-lab/regex-safety-audit-mcp),
[mcp-trust-audit-mcp](https://github.com/tylerscomic-lab/mcp-trust-audit-mcp).
## License
MIT
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues