Skip to main content
ClaudeWave
tylerscomic-lab avatar
tylerscomic-lab

secrets-leak-audit-mcp

Ver en GitHub
MCP ServersRegistry oficial0 estrellas0 forks● JavaScriptMITActualizado today
ClaudeWave Trust Score
85/100
✓ Trusted
Passed
  • ✓Open-source license (MIT)
  • ✓Actively maintained (<30d)
  • ✓Topics declared
  • ✓Documented (README)
Flags
  • !No description
Last scanned: 10/2/2026
Install in Claude Code / Claude Desktop
Method: Manual
Claude Code CLI
git clone https://github.com/tylerscomic-lab/secrets-leak-audit-mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "secrets-leak-audit-mcp": {
      "command": "node",
      "args": ["/path/to/secrets-leak-audit-mcp/dist/index.js"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Clone https://github.com/tylerscomic-lab/secrets-leak-audit-mcp and follow its README for install instructions.
Casos de uso

Resumen de MCP Servers

# secrets-leak-audit-mcp

[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)
[![Live on MCPize](https://img.shields.io/badge/Live%20on-MCPize-6d28d9)](https://mcpize.com/mcp/secrets-leak-audit-mcp)

An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops"
in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example
that includes a real key, or writing a test fixture with a plausible-looking but real value).

## What it catches

**High-precision vendor key matches.** Real, current (2026) structural formats for AWS access keys, GitHub PATs
(classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm
tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded
credentials. These are precise format matches, not guesses — an AWS key is `AKIA`/`ASIA` + 16 specific
characters, not "looks like it might be a key."

**Entropy-based fallback.** For secret-shaped variable names (`API_KEY`, `PASSWORD`, `*_TOKEN`) with no
recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated
credential and `"password123"` both match a suspicious name, but only one has the entropy of an actual secret —
flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic.

**Every match is redacted before it's returned** — the tool never echoes a full secret value back, even to
confirm a hit.

## Tools

### `scan_for_secrets`
Scans any text (a file's contents, a config snippet) for both categories above.

### `scan_diff`
Scans a unified `git diff` and only checks lines the diff actually **adds** — won't flag a secret that was
already being removed in the same diff, or one that only appears in unchanged context lines.

## Use it

**Hosted (recommended):** [MCPize](https://mcpize.com/mcp/secrets-leak-audit-mcp) — free tier, $7/mo Pro.

**Self-host:**
```bash
npm install
node server.js
```

## Part of a small suite

[github-actions-audit-mcp](https://github.com/tylerscomic-lab/github-actions-audit-mcp),
[dockerfile-audit-mcp](https://github.com/tylerscomic-lab/dockerfile-audit-mcp),
[regex-safety-audit-mcp](https://github.com/tylerscomic-lab/regex-safety-audit-mcp),
[mcp-trust-audit-mcp](https://github.com/tylerscomic-lab/mcp-trust-audit-mcp).

## License

MIT
devsecopsmcpmcp-servermodel-context-protocolsecrets-detectionsecurity

Lo que la gente pregunta sobre secrets-leak-audit-mcp

¿Qué es tylerscomic-lab/secrets-leak-audit-mcp?

+

tylerscomic-lab/secrets-leak-audit-mcp es mcp servers para el ecosistema de Claude AI con 0 estrellas en GitHub.

¿Cómo se instala secrets-leak-audit-mcp?

+

Puedes instalar secrets-leak-audit-mcp clonando el repositorio (https://github.com/tylerscomic-lab/secrets-leak-audit-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar tylerscomic-lab/secrets-leak-audit-mcp?

+

Nuestro agente de seguridad ha analizado tylerscomic-lab/secrets-leak-audit-mcp y le ha asignado un Trust Score de 85/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.

¿Quién mantiene tylerscomic-lab/secrets-leak-audit-mcp?

+

tylerscomic-lab/secrets-leak-audit-mcp es mantenido por tylerscomic-lab. La última actividad registrada en GitHub es del 2026-10-01, con 0 issues abiertos.

¿Hay alternativas a secrets-leak-audit-mcp?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega secrets-leak-audit-mcp en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: tylerscomic-lab/secrets-leak-audit-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/tylerscomic-lab-secrets-leak-audit-mcp)](https://claudewave.com/repo/tylerscomic-lab-secrets-leak-audit-mcp)
<a href="https://claudewave.com/repo/tylerscomic-lab-secrets-leak-audit-mcp"><img src="https://claudewave.com/api/badge/tylerscomic-lab-secrets-leak-audit-mcp" alt="Featured on ClaudeWave: tylerscomic-lab/secrets-leak-audit-mcp" width="320" height="64" /></a>

Más MCP Servers

Alternativas a secrets-leak-audit-mcp