Server data from the Official MCP Registry
Scan text and git diffs for committed credentials using real vendor key formats plus entropy.
About
Scan text and git diffs for committed credentials using real vendor key formats plus entropy.
Remote endpoints: streamable-http: https://secrets-leak-audit-mcp.mcpize.run/mcp
Security Report
This is a well-designed credential detection MCP server with strong security practices. The code implements high-precision vendor key matching and entropy-based fallback detection without storing credentials. Input is properly scanned and secrets are redacted before output. One minor issue involves regex denial-of-service potential on untrusted input, and error handling could be more explicit, but these are low-severity concerns that do not materially impact the server's security posture.
4 files analyzed · 3 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install & Connect
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Documentation
View on GitHubFrom the project's GitHub README.
secrets-leak-audit-mcp
An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops" in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example that includes a real key, or writing a test fixture with a plausible-looking but real value).
What it catches
High-precision vendor key matches. Real, current (2026) structural formats for AWS access keys, GitHub PATs
(classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm
tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded
credentials. These are precise format matches, not guesses — an AWS key is AKIA/ASIA + 16 specific
characters, not "looks like it might be a key."
Entropy-based fallback. For secret-shaped variable names (API_KEY, PASSWORD, *_TOKEN) with no
recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated
credential and "password123" both match a suspicious name, but only one has the entropy of an actual secret —
flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic.
Every match is redacted before it's returned — the tool never echoes a full secret value back, even to confirm a hit.
Tools
scan_for_secrets
Scans any text (a file's contents, a config snippet) for both categories above.
scan_diff
Scans a unified git diff and only checks lines the diff actually adds — won't flag a secret that was
already being removed in the same diff, or one that only appears in unchanged context lines.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
npm install
node server.js
Part of a small suite
github-actions-audit-mcp, dockerfile-audit-mcp, regex-safety-audit-mcp, mcp-trust-audit-mcp.
License
MIT
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Worldmonitor
Freeby Koala73 · Developer Tools
Live markets, conflicts, country risk, chokepoints, energy, and China decision signals. 86 tools.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
