repo-guardian
Detects hardcoded GitHub tokens in scanned repositories so agents can identify exposed credentials before they leak.
Detects exposed Google API keys in source files to help prevent unauthorized use of Google APIs.
Detects exposed Slack tokens in source files to help prevent unauthorized access to Slack workspaces.
Detects exposed Stripe keys in source files to help prevent unauthorized payment operations.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@repo-guardianScan this repo for hardcoded secrets before I commit it"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
repo-guardian
MCP server exposing repo-health tools so any agent can guard repositories — detect pinned/unpinned dependencies, license compliance issues, hardcoded secrets, and dead code.
Features
audit_dependencies — Parse
pyproject.toml,requirements*.txt, andsetup.py; flag exact pins that may miss security patches and dependencies with no version constraints.check_licenses — Scan declared dependency licenses for compliance issues (GPL/AGPL copyleft, unknown licenses, license incompatibilities with the project license).
scan_for_secrets — Search for AWS keys, GitHub tokens, Slack tokens, Google API keys, Stripe keys, private key blocks, password assignments, bearer tokens, and high-entropy strings.
find_dead_code — Detect unused Python imports, unused functions, and orphaned files.
All scanners are dependency-free (stdlib only) and never crash the MCP session — errors are returned as tool results.
Related MCP server: sdlc-integrity-mcp
Installation
pip install repo-guardianFor development:
git clone https://github.com/prem-the-dev/repo-guardian.git
cd repo-guardian
pip install -e ".[dev]"Quickstart (Claude Desktop / Cursor / Windsurf)
Add to your MCP client config:
Claude Desktop (claude_desktop_config.json)
{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}Cursor (.cursor/mcp.json)
{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}Windsurf (.codeium/windsurf/mcp.json)
Same config as Cursor above.
Gemini CLI (gemini/.gemini/.mcp.json)
{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}Hermes Agent
Copy the bundled mcp.json into your Hermes profile or merge it with your
existing MCP server config:
cp mcp.json ~/.hermes/profiles/mcp-specialist/mcp.json
hermes profile reload{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}Usage Examples
Once configured, any agent can call the tools:
Audit Dependencies
audit_dependencies(path="/path/to/my-project")Returns:
{
"status": "ok",
"scanned_files": ["pyproject.toml", "requirements.txt"],
"total_dependencies": 4,
"pinned_dependencies": [
{"name": "Django", "version_spec": "==4.2.7", "classification": "pinned"}
],
"potential_issues": [
{"type": "pinned_exact", "dependency": "Django", "message": "..."}
]
}Check Licenses
check_licenses(path="/path/to/my-project")Returns:
{
"status": "ok",
"project_license": "MIT",
"restricted_licenses": [],
"unknown_licenses": [...],
"potential_issues": []
}Scan for Secrets
scan_for_secrets(path="/path/to/my-project", max_file_size_mb=5)Returns:
{
"status": "ok",
"total_findings": 3,
"findings": [
{"type": "aws_access_key", "file": ".env", "line": 2, "confidence": "high"},
{"type": "github_token", "file": "config.py", "line": 5, "confidence": "high"}
]
}Find Dead Code
find_dead_code(path="/path/to/my-project")Returns:
{
"status": "ok",
"unused_imports": [
{"type": "unused_import", "file": "main.py", "line": 3, "name": "unused_module"}
],
"unused_functions": [
{"type": "unused_function", "file": "main.py", "line": 12, "name": "unused_function"}
],
"orphaned_files": [...]
}Running Tests
python -m pytest tests/ -vArchitecture
graph TD
A[MCP Client<br/>Claude/Cursor/Windsurf/Hermes] -->|stdio JSON-RPC| B[MCP Server<br/>repo_guardian]
B --> C[Tool Registry<br/>tools/list + tools/call]
C --> D[audit_dependencies]
C --> E[check_licenses]
C --> F[scan_for_secrets]
C --> G[find_dead_code]
D --> D1[pyproject.toml parser]
D --> D2[requirements.txt parser]
D --> D3[setup.py parser]
E --> E1[SPDX license DB<br/>offline lookup]
E --> E2[Project license<br/>detect]
F --> F1[Pattern matchers<br/>AWS/GH/Slack/etc]
F --> F2[Shannon entropy<br/>high-entropy scan]
G --> G1[AST parser<br/>imports + defs]
G --> G2[Cross-file<br/>usage tracker]License
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables hybrid code audits using MCP tools across 12 domains, producing structured, scored, and actionable code quality reports.61MIT
- AlicenseAqualityAmaintenanceMCP server that provides audit and safety-check tools for enterprise SDLC code integrity, enabling AI agents to scan workspaces for lifecycle gaps, mock-theater tests, DRY violations, and language-specific issues in shell, JavaScript/HTML, and Python.4376MIT
- AlicenseAqualityCmaintenanceEnables policy-first defensive security operations for MCP, providing repository and web-security analysis with controlled authorization, scoped execution, and auditability.9MIT
- AlicenseAqualityCmaintenanceMCP server providing diagnostic tools to analyze software architecture, security, REST API compliance, and dependencies for multiple programming languages. Enables AI agents to run scans and audits on codebases.7MIT
Related MCP Connectors
Remote MCP for tool license checks, vendor policy review, alternatives, and license receipts.
Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
Generate AGENTS.md, AP2 compliance docs, checkout rules, debug playbook & MCP configs from any repo.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/prem-the-dev/repo-guardian'
If you have feedback or need assistance with the MCP directory API, please join our Discord server