Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
scan_for_secretsA

Scans a code string for hardcoded secrets (AWS keys, Stripe keys, GitHub tokens, Google API keys, Slack tokens, private key blocks, JWTs, and generic high-entropy credentials assigned to secret/token/password/key-like variable names) BEFORE that code is written to a file or committed. Call this proactively whenever you are about to write, edit, or commit code that could plausibly contain a credential — config files, env handling, API client setup, tests with fixture values, or any snippet you're not 100% sure is clean — and again right before creating a commit or PR. Every reported line is redacted; the raw secret value is never returned.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.6/5.0

Scored across 1 tool

Disambiguation5/5

Only one tool exists, so there is no possibility of confusion between tools. The purpose is unambiguous.

Naming Consistency5/5

The tool name 'scan_for_secrets' follows a clear verb_noun pattern, consistent with common MCP naming conventions. With a single tool, there is no inconsistency.

Tool Count3/5

A single tool is minimal for a focused secret-scanner server, but feels thin compared to typical MCP servers that offer a broader range of operations. The count is borderline.

Completeness5/5

The tool covers the core functionality of scanning for secrets in code snippets, and no obvious additional operations are needed for this narrow domain. The tool description explicitly addresses proactive scanning before commits, making it self-contained.

Maintenance

ActivitySlowing
ResponsivenessNo issues