ctxbleach
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ctxbleachredact the AWS keys from this log before sending"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ctxbleach
Local CLI and MCP server that bleaches secrets from logs, files, and diffs before AI agents see them.
π― Why?
Trending agent-context projects focus on giving agents more code and memory, while guardrail tools mostly block commands. Developers still need a tiny local middleware that transforms raw logs, env files, and command output into safe, token-budgeted context before it reaches an LLM. Existing secret scanners are CI-oriented and do not provide interactive redaction placeholders, MCP tools, or context budgeting.
Target audience: Developers and platform engineers using Claude Code, Cursor, Codex, or MCP-enabled agents who need to share logs, .env files, stack traces, and CI output without leaking credentials.
Related MCP server: VaultBridge
β¨ Features
β¨ Regex-based redaction for AWS keys, GitHub/Slack tokens, JWTs, bearer headers, URL passwords, private keys, and generic secret assignments
β¨ Stable placeholders and masked scan output so no secret values are echoed back
β¨ Token-budgeted truncation with head or tail preservation for large logs
β¨ CLI commands for scan, redact, and MCP stdio serving
β¨ Zero-dependency Python implementation that can be dropped into agent workflows
π Quick Start
# Install
pip install ctxbleach
# Run
ctxbleach --helpπ¦ Installation
From Source
git clone https://github.com/YOUR_USERNAME/ctxbleach.git
cd ctxbleach# Create virtual environment
python -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
# Install in development mode
pip install -e ".[dev]"
# Run tests
pytest -v㪠Demo
The GIF above was recorded using Charm VHS:
vhs < demo.tapeπ Usage
# Show help
ctxbleach --help
# Common usage examples
ctxbleach --exampleποΈ Architecture
graph LR
A[Input] --> B[Core Engine]
B --> C[Output]
B --> D[Plugins]
D --> E[Extensions]π€ Contributing
Contributions are welcome! Please:
Fork the repo
Create a feature branch (
git checkout -b feature/amazing-feature)Commit your changes (
git commit -m 'Add amazing feature')Push to the branch (
git push origin feature/amazing-feature)Open a Pull Request
π License
MIT Β© 2026 β See LICENSE for details.
If this project helped you, please β star it!
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
No tool schema history has been recorded yet.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Security & DLP proxy for MCP: tool-poisoning scans, PII redaction on tool args/results. Beta.
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Secrets for developers and agentsβsecure context and workflows without exposing secret values.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceLocal-first CLI and MCP server for redacting sensitive text before sharing logs, configs, and errors with AI tools.MIT
- AlicenseNot gradedqualityDmaintenanceSecret management MCP server for AI coding agents that prevents secrets from entering the LLM context window by returning metadata only and using side-channel injection. Integrates with Bitwarden and offers hooks for auto-capture and leak prevention.1MIT
- AlicenseAqualityAmaintenanceA local-first redacting MCP gateway that strips secrets from file reads and shell output before they reach an AI coding agent's context, the command still runs with the real credential, but the model never sees it.218MIT
- AlicenseAqualityCmaintenanceA redaction engine and MCP server that scrubs sensitive identifiers (AWS keys, IPs, emails, etc.) from AI agent traces, enabling safe storage and sharing of war stories via submit, search, and retrieve tools.3Apache 2.0
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/yulinlina/ctxbleach'
If you have feedback or need assistance with the MCP directory API, please join our Discord server