Secrets Leak Audit

io.github.tylerscomic-labv1.0.0Updated Oct 2, 2026

Scan text and git diffs for committed credentials using real vendor key formats plus entropy.

VerifiedStreamable HTTPWeb executableDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Scans text and git diffs for accidentally committed credentials using vendor key formats and entropy heuristics.

What it does
Exposes two tools: scan_for_secrets, which checks arbitrary text such as file contents or config snippets, and scan_diff, which checks only the lines a unified git diff adds. It matches known vendor key formats (AWS, GitHub, Stripe, Slack, Google, OpenAI, Anthropic, npm, SendGrid, Twilio, PEM private key blocks, JWTs, and connection strings with embedded credentials) and falls back to Shannon entropy for secret-shaped variable names. Matches are redacted before being returned.
When to use it
Useful when an AI coding agent writes or reviews code and might paste a real key into an example or test fixture, or when you want a quick check of a diff before committing. Best suited to pre-commit or review-time scanning rather than full repository secret management.
Requirements
The hosted option is a remote streamable HTTP endpoint at secrets-leak-audit-mcp.mcpize.run; the README mentions a free tier and a $7/mo Pro tier. Self-hosting requires Node.js and running npm install followed by node server.js. No accounts, API keys, or environment variables are declared.
Before you install
The service receives the text or diff you submit, so anything scanned is sent to a third party when using the hosted endpoint. Entropy-based findings are heuristics and can produce false positives. The README states matches are redacted before being returned, but treat any pasted content as potentially sensitive.

Installation

In SourceWeft

  1. Open Secrets Leak Audit in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "secrets-leak-audit-mcp": {
      "type": "http",
      "url": "https://secrets-leak-audit-mcp.mcpize.run/mcp"
    }
  }
}

README

secrets-leak-audit-mcp

[License: MIT] [Live on MCPize]

An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops" in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example that includes a real key, or writing a test fixture with a plausible-looking but real value).

What it catches

High-precision vendor key matches. Real, current (2026) structural formats for AWS access keys, GitHub PATs (classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded credentials. These are precise format matches, not guesses — an AWS key is AKIA/ASIA + 16 specific characters, not "looks like it might be a key."

Entropy-based fallback. For secret-shaped variable names (API_KEY, PASSWORD, *_TOKEN) with no recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated credential and "password123" both match a suspicious name, but only one has the entropy of an actual secret — flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic.

Every match is redacted before it's returned — the tool never echoes a full secret value back, even to confirm a hit.

Tools

scan_for_secrets

Scans any text (a file's contents, a config snippet) for both categories above.

scan_diff

Scans a unified git diff and only checks lines the diff actually adds — won't flag a secret that was already being removed in the same diff, or one that only appears in unchanged context lines.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

bash
npm installnode server.js

Part of a small suite

github-actions-audit-mcp, dockerfile-audit-mcp, regex-safety-audit-mcp, mcp-trust-audit-mcp.

License

MIT

Source: README.md at commit a8ddabc

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.0LatestOct 2, 2026