- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Topics declared
- ✓Documented (README)
- !No description
git clone https://github.com/tylerscomic-lab/secrets-leak-audit-mcp{
"mcpServers": {
"secrets-leak-audit-mcp": {
"command": "node",
"args": ["/path/to/secrets-leak-audit-mcp/dist/index.js"]
}
}
}MCP Servers overview
# secrets-leak-audit-mcp [](LICENSE) [](https://mcpize.com/mcp/secrets-leak-audit-mcp) An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops" in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example that includes a real key, or writing a test fixture with a plausible-looking but real value). ## What it catches **High-precision vendor key matches.** Real, current (2026) structural formats for AWS access keys, GitHub PATs (classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded credentials. These are precise format matches, not guesses — an AWS key is `AKIA`/`ASIA` + 16 specific characters, not "looks like it might be a key." **Entropy-based fallback.** For secret-shaped variable names (`API_KEY`, `PASSWORD`, `*_TOKEN`) with no recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated credential and `"password123"` both match a suspicious name, but only one has the entropy of an actual secret — flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic. **Every match is redacted before it's returned** — the tool never echoes a full secret value back, even to confirm a hit. ## Tools ### `scan_for_secrets` Scans any text (a file's contents, a config snippet) for both categories above. ### `scan_diff` Scans a unified `git diff` and only checks lines the diff actually **adds** — won't flag a secret that was already being removed in the same diff, or one that only appears in unchanged context lines. ## Use it **Hosted (recommended):** [MCPize](https://mcpize.com/mcp/secrets-leak-audit-mcp) — free tier, $7/mo Pro. **Self-host:** ```bash npm install node server.js ``` ## Part of a small suite [github-actions-audit-mcp](https://github.com/tylerscomic-lab/github-actions-audit-mcp), [dockerfile-audit-mcp](https://github.com/tylerscomic-lab/dockerfile-audit-mcp), [regex-safety-audit-mcp](https://github.com/tylerscomic-lab/regex-safety-audit-mcp), [mcp-trust-audit-mcp](https://github.com/tylerscomic-lab/mcp-trust-audit-mcp). ## License MIT
What people ask about secrets-leak-audit-mcp
What is tylerscomic-lab/secrets-leak-audit-mcp?
+
tylerscomic-lab/secrets-leak-audit-mcp is mcp servers for the Claude AI ecosystem with 0 GitHub stars.
How do I install secrets-leak-audit-mcp?
+
You can install secrets-leak-audit-mcp by cloning the repository (https://github.com/tylerscomic-lab/secrets-leak-audit-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is tylerscomic-lab/secrets-leak-audit-mcp safe to use?
+
Our security agent has analyzed tylerscomic-lab/secrets-leak-audit-mcp and assigned a Trust Score of 85/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains tylerscomic-lab/secrets-leak-audit-mcp?
+
tylerscomic-lab/secrets-leak-audit-mcp is maintained by tylerscomic-lab. The last recorded GitHub activity is dated 2026-10-01, with 0 open issues.
Are there alternatives to secrets-leak-audit-mcp?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy secrets-leak-audit-mcp to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/tylerscomic-lab-secrets-leak-audit-mcp)<a href="https://claudewave.com/repo/tylerscomic-lab-secrets-leak-audit-mcp"><img src="https://claudewave.com/api/badge/tylerscomic-lab-secrets-leak-audit-mcp" alt="Featured on ClaudeWave: tylerscomic-lab/secrets-leak-audit-mcp" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.