Skip to main content
ClaudeWave
tylerscomic-lab avatar
tylerscomic-lab

secrets-leak-audit-mcp

View on GitHub
MCP ServersOfficial Registry0 stars0 forks● JavaScriptMITUpdated today
ClaudeWave Trust Score
85/100
✓ Trusted
Passed
  • ✓Open-source license (MIT)
  • ✓Actively maintained (<30d)
  • ✓Topics declared
  • ✓Documented (README)
Flags
  • !No description
Last scanned: 10/2/2026
Install in Claude Code / Claude Desktop
Method: Manual
Claude Code CLI
git clone https://github.com/tylerscomic-lab/secrets-leak-audit-mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "secrets-leak-audit-mcp": {
      "command": "node",
      "args": ["/path/to/secrets-leak-audit-mcp/dist/index.js"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Clone https://github.com/tylerscomic-lab/secrets-leak-audit-mcp and follow its README for install instructions.
Use cases

MCP Servers overview

# secrets-leak-audit-mcp

[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)
[![Live on MCPize](https://img.shields.io/badge/Live%20on-MCPize-6d28d9)](https://mcpize.com/mcp/secrets-leak-audit-mcp)

An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops"
in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example
that includes a real key, or writing a test fixture with a plausible-looking but real value).

## What it catches

**High-precision vendor key matches.** Real, current (2026) structural formats for AWS access keys, GitHub PATs
(classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm
tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded
credentials. These are precise format matches, not guesses — an AWS key is `AKIA`/`ASIA` + 16 specific
characters, not "looks like it might be a key."

**Entropy-based fallback.** For secret-shaped variable names (`API_KEY`, `PASSWORD`, `*_TOKEN`) with no
recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated
credential and `"password123"` both match a suspicious name, but only one has the entropy of an actual secret —
flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic.

**Every match is redacted before it's returned** — the tool never echoes a full secret value back, even to
confirm a hit.

## Tools

### `scan_for_secrets`
Scans any text (a file's contents, a config snippet) for both categories above.

### `scan_diff`
Scans a unified `git diff` and only checks lines the diff actually **adds** — won't flag a secret that was
already being removed in the same diff, or one that only appears in unchanged context lines.

## Use it

**Hosted (recommended):** [MCPize](https://mcpize.com/mcp/secrets-leak-audit-mcp) — free tier, $7/mo Pro.

**Self-host:**
```bash
npm install
node server.js
```

## Part of a small suite

[github-actions-audit-mcp](https://github.com/tylerscomic-lab/github-actions-audit-mcp),
[dockerfile-audit-mcp](https://github.com/tylerscomic-lab/dockerfile-audit-mcp),
[regex-safety-audit-mcp](https://github.com/tylerscomic-lab/regex-safety-audit-mcp),
[mcp-trust-audit-mcp](https://github.com/tylerscomic-lab/mcp-trust-audit-mcp).

## License

MIT
devsecopsmcpmcp-servermodel-context-protocolsecrets-detectionsecurity

What people ask about secrets-leak-audit-mcp

What is tylerscomic-lab/secrets-leak-audit-mcp?

+

tylerscomic-lab/secrets-leak-audit-mcp is mcp servers for the Claude AI ecosystem with 0 GitHub stars.

How do I install secrets-leak-audit-mcp?

+

You can install secrets-leak-audit-mcp by cloning the repository (https://github.com/tylerscomic-lab/secrets-leak-audit-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is tylerscomic-lab/secrets-leak-audit-mcp safe to use?

+

Our security agent has analyzed tylerscomic-lab/secrets-leak-audit-mcp and assigned a Trust Score of 85/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.

Who maintains tylerscomic-lab/secrets-leak-audit-mcp?

+

tylerscomic-lab/secrets-leak-audit-mcp is maintained by tylerscomic-lab. The last recorded GitHub activity is dated 2026-10-01, with 0 open issues.

Are there alternatives to secrets-leak-audit-mcp?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy secrets-leak-audit-mcp to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: tylerscomic-lab/secrets-leak-audit-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/tylerscomic-lab-secrets-leak-audit-mcp)](https://claudewave.com/repo/tylerscomic-lab-secrets-leak-audit-mcp)
<a href="https://claudewave.com/repo/tylerscomic-lab-secrets-leak-audit-mcp"><img src="https://claudewave.com/api/badge/tylerscomic-lab-secrets-leak-audit-mcp" alt="Featured on ClaudeWave: tylerscomic-lab/secrets-leak-audit-mcp" width="320" height="64" /></a>