Back to Browse

Secrets Leak Audit MCP Server

Developer ToolsLow Risk8.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Scan text and git diffs for committed credentials using real vendor key formats plus entropy.

About

Scan text and git diffs for committed credentials using real vendor key formats plus entropy.

Remote endpoints: streamable-http: https://secrets-leak-audit-mcp.mcpize.run/mcp

Security Report

8.2
Low Risk8.2Low Risk

This is a well-designed credential detection MCP server with strong security practices. The code implements high-precision vendor key matching and entropy-based fallback detection without storing credentials. Input is properly scanned and secrets are redacted before output. One minor issue involves regex denial-of-service potential on untrusted input, and error handling could be more explicit, but these are low-severity concerns that do not materially impact the server's security posture.

4 files analyzed · 3 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

secrets-leak-audit-mcp

License: MIT Live on MCPize

An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops" in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example that includes a real key, or writing a test fixture with a plausible-looking but real value).

What it catches

High-precision vendor key matches. Real, current (2026) structural formats for AWS access keys, GitHub PATs (classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded credentials. These are precise format matches, not guesses — an AWS key is AKIA/ASIA + 16 specific characters, not "looks like it might be a key."

Entropy-based fallback. For secret-shaped variable names (API_KEY, PASSWORD, *_TOKEN) with no recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated credential and "password123" both match a suspicious name, but only one has the entropy of an actual secret — flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic.

Every match is redacted before it's returned — the tool never echoes a full secret value back, even to confirm a hit.

Tools

scan_for_secrets

Scans any text (a file's contents, a config snippet) for both categories above.

scan_diff

Scans a unified git diff and only checks lines the diff actually adds — won't flag a secret that was already being removed in the same diff, or one that only appears in unchanged context lines.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

npm install
node server.js

Part of a small suite

github-actions-audit-mcp, dockerfile-audit-mcp, regex-safety-audit-mcp, mcp-trust-audit-mcp.

License

MIT

Reviews

No reviews yet

Be the first to review this server!