Back to Browse

Secret Hygiene MCP Server

Developer ToolsModerate7.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Count secret-like patterns in bounded local files without returning values, keys, paths,...

About

Count secret-like patterns in bounded local files without returning values, keys, paths,...

Security Report

7.2
Moderate7.2Low Risk

Secret Hygiene MCP is a well-designed, security-conscious server for local secret pattern scanning. The codebase demonstrates strong privacy practices by intentionally returning only pattern category counts and never exposing values, keys, paths, or filenames. Minimal dependencies, proper input validation with path traversal protection, and bounded file scanning provide a solid security foundation. One minor finding regarding environment variable reliance for configuration. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

6 files analyzed · 4 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

env_vars

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-mrfentmen-secret-hygiene-mcp": {
      "args": [
        "-y",
        "secret-hygiene-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

secret-hygiene-mcp

Secret Hygiene scans bounded local files for common secret-like patterns and returns category counts only. It is designed as a pre-commit review signal, not a credential detector with perfect coverage.

Quick start

npm install
npm test
npm start

Use scan_secret_hygiene inside SECRET_HYGIENE_ROOT.

Privacy and limits

Values, keys, matches, filenames, paths, and source text are never returned. Pattern matching is conservative and can produce false positives or miss unusual formats. Rotate exposed credentials separately.

Reviews

No reviews yet

Be the first to review this server!