
Secrets Leak Audit
io.github.tylerscomic-labv1.0.0Updated Oct 2, 2026
Scan text and git diffs for committed credentials using real vendor key formats plus entropy.
Overview
Scans text and git diffs for accidentally committed credentials using vendor key formats and entropy heuristics.
- What it does
- Exposes two tools: scan_for_secrets, which checks arbitrary text such as file contents or config snippets, and scan_diff, which checks only the lines a unified git diff adds. It matches known vendor key formats (AWS, GitHub, Stripe, Slack, Google, OpenAI, Anthropic, npm, SendGrid, Twilio, PEM private key blocks, JWTs, and connection strings with embedded credentials) and falls back to Shannon entropy for secret-shaped variable names. Matches are redacted before being returned.
- When to use it
- Useful when an AI coding agent writes or reviews code and might paste a real key into an example or test fixture, or when you want a quick check of a diff before committing. Best suited to pre-commit or review-time scanning rather than full repository secret management.
- Requirements
- The hosted option is a remote streamable HTTP endpoint at secrets-leak-audit-mcp.mcpize.run; the README mentions a free tier and a $7/mo Pro tier. Self-hosting requires Node.js and running npm install followed by node server.js. No accounts, API keys, or environment variables are declared.
Installation
In SourceWeft
- Open Secrets Leak Audit in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"secrets-leak-audit-mcp": {
"type": "http",
"url": "https://secrets-leak-audit-mcp.mcpize.run/mcp"
}
}
}README
secrets-leak-audit-mcp
[License: MIT] [Live on MCPize]
An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops" in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example that includes a real key, or writing a test fixture with a plausible-looking but real value).
What it catches
High-precision vendor key matches. Real, current (2026) structural formats for AWS access keys, GitHub PATs
(classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm
tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded
credentials. These are precise format matches, not guesses — an AWS key is AKIA/ASIA + 16 specific
characters, not "looks like it might be a key."
Entropy-based fallback. For secret-shaped variable names (API_KEY, PASSWORD, *_TOKEN) with no
recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated
credential and "password123" both match a suspicious name, but only one has the entropy of an actual secret —
flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic.
Every match is redacted before it's returned — the tool never echoes a full secret value back, even to confirm a hit.
Tools
scan_for_secrets
Scans any text (a file's contents, a config snippet) for both categories above.
scan_diff
Scans a unified git diff and only checks lines the diff actually adds — won't flag a secret that was
already being removed in the same diff, or one that only appears in unchanged context lines.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
Part of a small suite
github-actions-audit-mcp, dockerfile-audit-mcp, regex-safety-audit-mcp, mcp-trust-audit-mcp.
License
MIT
Source: README.md at commit a8ddabc
Tools
0Version history
1- v1.0.0LatestOct 2, 2026