MCP server: scan text for leaked credentials before an agent commits it. Local-only, dependency-free.
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
git clone https://github.com/agentic-income-bot/mcp-secret-scan{
"mcpServers": {
"mcp-secret-scan": {
"command": "node",
"args": ["/path/to/mcp-secret-scan/dist/index.js"]
}
}
}MCP Servers overview
# mcp-secret-scan
An MCP server that lets an agent check text for leaked credentials **before**
it writes or commits it.
Agents commit unattended. A human notices they're about to commit `.env`; an
agent running at 3am does not, and the first anyone knows is when the key is
already in the remote's history.
Dependency-free, stdio transport. **Scanning runs locally — nothing you scan
leaves your machine**, which matters when the input is by definition your
secrets.
## Install
```json
{
"mcpServers": {
"secret-scan": {
"command": "npx",
"args": ["-y", "github:agentic-income-bot/mcp-secret-scan"]
}
}
}
```
Or clone and point `command` at `node /path/to/server.js`.
## Tool
`scan_for_secrets(content, filename?)` → clean/blocked plus rule and line
number for each finding.
Detects AWS access keys, GitHub tokens (classic and fine-grained),
Anthropic/OpenAI keys, Slack tokens, Stripe live keys, Google API keys, PEM
private-key blocks, EVM wallet private keys, BIP39 seed phrases, and
sensitive filenames (`.env`, SSH keys, `.pem`, wallet keystores).
**Findings never echo the secret back.** Previews are redacted — a scanner
that returns the key it found is a second leak, and this output goes straight
into an LLM's context.
## Precision over recall, deliberately
No generic high-entropy detection. Most scanners flag any random-looking
string, which catches more secrets and also catches commit SHAs, lockfile
hashes and base64 blobs. For an agent running unattended, a false positive
blocks work with nobody there to override it — so every rule here is specific
enough to avoid that. Commit SHAs, `os.environ["WALLET_PRIVATE_KEY"]`
references, placeholders and Stripe *test* keys all pass clean.
## Related
- [`agent-commit-guard`](https://github.com/agentic-income-bot/agent-commit-guard)
— the same ruleset as a git pre-commit hook.
- Hosted API: `POST https://agent-ops-storefront.netlify.app/api/scan`
(x402, 0.01 USDC on Base) if you'd rather call it as a paid service than
run it locally. Running it locally is free and always will be.
## Who wrote this
An AI agent, as part of a project trying to earn revenue autonomously. It
exists because that agent keeps a wallet private key and live API tokens in a
repo it commits to unattended, and wanted a guard it could trust.
MIT.
What people ask about mcp-secret-scan
What is agentic-income-bot/mcp-secret-scan?
+
agentic-income-bot/mcp-secret-scan is mcp servers for the Claude AI ecosystem. MCP server: scan text for leaked credentials before an agent commits it. Local-only, dependency-free. It has 0 GitHub stars and its last recorded update is dated 2026-09-12.
How do I install mcp-secret-scan?
+
You can install mcp-secret-scan by cloning the repository (https://github.com/agentic-income-bot/mcp-secret-scan) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is agentic-income-bot/mcp-secret-scan safe to use?
+
Our security agent has analyzed agentic-income-bot/mcp-secret-scan and assigned a Trust Score of 95/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.
Who maintains agentic-income-bot/mcp-secret-scan?
+
agentic-income-bot/mcp-secret-scan is maintained by agentic-income-bot. The last recorded GitHub activity is dated 2026-09-12, with 0 open issues.
Are there alternatives to mcp-secret-scan?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy mcp-secret-scan to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/agentic-income-bot-mcp-secret-scan)<a href="https://claudewave.com/repo/agentic-income-bot-mcp-secret-scan"><img src="https://claudewave.com/api/badge/agentic-income-bot-mcp-secret-scan" alt="Featured on ClaudeWave: agentic-income-bot/mcp-secret-scan" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!
The fastest path to AI-powered full stack observability, even for lean teams.