secrets-audit-mcp

secrets-audit-mcp

Detects leaked credentials in source code with tools to scan text, files, and directories for API keys, tokens, and private keys across 30+ providers.

Category
访问服务器

README

secrets-audit-mcp

smithery badge MCP Registry

MCP server that detects leaked credentials in source code. Zero dependencies. Single file.

License: MIT Python 3.6+ MCP Sister: skill-audit-mcp

Detects API keys, OAuth tokens, private keys, webhooks, and crypto wallet secrets across 30+ providers (AWS, GCP, GitHub, Stripe, OpenAI, Anthropic, Slack, Discord, Telegram, Twilio, SendGrid, Heroku, DigitalOcean, npm, HuggingFace, Replicate, Cloudflare, and more).

Companion to skill-audit-mcp (behavioral patterns) — together they cover secrets + behaviors in one MCP toolchain.


Why

Most secret scanners are giant Go binaries (trufflehog, gitleaks). This is a 500-line Python file that runs as an MCP stdio server, so any LLM agent (Claude Desktop, Cursor, Windsurf, Cline) can ask it scan_directory and get a structured report in their tool-call response.

Use cases:

  • Pre-commit hook in CI
  • Agent-driven code review ("did this PR leak credentials?")
  • Audit a freshly-cloned repo before opening it in your shell
  • Inline scan during agent file edits

Install

# Python (recommended)
git clone https://github.com/eltociear/secrets-audit-mcp.git
python3 secrets-audit-mcp/server.py  # stdio MCP server

# Or via npm wrapper (TBD)
npm install -g @eltociear/secrets-audit-mcp

MCP client config

{
  "mcpServers": {
    "secrets-audit": {
      "type": "stdio",
      "command": "python3",
      "args": ["/path/to/secrets-audit-mcp/server.py"]
    }
  }
}

Tools

Tool Use case
scan Scan inline text/content
scan_file Scan a single file
scan_directory Scan a directory recursively (skips .git, node_modules, __pycache__, etc.)

All return a risk score (0-100), severity bucket (CRITICAL/HIGH/MEDIUM/LOW/SAFE), and per-finding details with line numbers and redacted matches.


Coverage

Providers (32 rules total):

  • Cloud: AWS access/secret, GCP API key + service-account JSON, Heroku, DigitalOcean, Cloudflare
  • Source/CI: GitHub PAT/OAuth/App/Refresh/Fine-grained, npm tokens, Docker Hub PAT
  • Payments: Stripe secret + restricted
  • Comms: Slack bot/user/webhook, Discord bot/webhook, Telegram bot, Twilio, SendGrid, Mailgun
  • AI/ML: OpenAI, Anthropic, HuggingFace, Replicate
  • Web3: Ethereum private key (context-aware), Alchemy, Infura
  • Keys: RSA / EC / OpenSSH / PGP / generic PEM private keys
  • Generic: JWT, apikey="..." heuristic, generic secret assignments

Each match is redacted (AKIA***MPLE) before being returned, so the report itself doesn't leak the secret to the next LLM hop.


CI usage

- name: Secrets audit
  run: |
    python3 server.py <<EOF | jq -r '.result.content[0].text'
    {"jsonrpc":"2.0","id":1,"method":"tools/call",
     "params":{"name":"scan_directory","arguments":{"path":"."}}}
    EOF

A first-class GitHub Action will ship as eltociear/secrets-audit-action@v1.


Sister project — skill-audit-mcp

skill-audit-mcp covers behavioral malware patterns (download-and-execute, prompt injection, credential exfiltration). Run both for full coverage:

Layer Tool Detects
Static behaviors skill-audit-mcp curl-pipe-sh, exfiltration, prompt injection (68 patterns)
Static secrets secrets-audit-mcp leaked keys/tokens/PEMs (32 rules)

Subscribe — security pulse

Polar.sh — Security Pulse Monthly ships a monthly briefing on new MCP server vulnerabilities, secrets-audit-mcp rule updates, and mitigation playbooks. $5/mo.

Polar.sh — Pro Audit Stack adds 50 paid scan credits + Discord + custom rule submission. $20/mo.


License

MIT. See LICENSE.

Free MCP vs paid x402

This MCP server is free. For server-side / batch / no-install use, the same scanner is a pay-per-call x402 HTTP API: POST https://eltociear-secrets-audit.hf.space/audit ($0.01 USDC on Base) and /audit/url ($0.03). In the official MCP Registry as io.github.eltociear/secrets-audit-mcp.

Professional audit services

Maintained by the same author — paid services on Polar (Stripe checkout):

Full catalog: polar.sh/eltociear

Also live: clean-read ($0.005 / call)

Same operator, same x402 rails: clean-read turns any URL into clean Markdown for AI agents — fetches the page, strips nav/ads/boilerplate (trafilatura), returns the main content with title and word count. POST https://eltociear-skill-audit.hf.space/read — $0.005 USDC on Base, no signup.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选