Secrets Leak Audit

io.github.tylerscomic-labv1.0.0更新于 Oct 2, 2026

Scan text and git diffs for committed credentials using real vendor key formats plus entropy.

已验证Streamable HTTP可网页运行Developer ToolsSecurity & Monitoring

概览

AI 生成的概览

扫描文本和 git diff,通过厂商密钥格式与熵值启发式检测误提交的凭据。

功能
提供两个工具:scan_for_secrets 检查任意文本(如文件内容或配置片段),scan_diff 仅检查统一 git diff 中新增的行。它匹配已知厂商密钥格式(AWS、GitHub、Stripe、Slack、Google、OpenAI、Anthropic、npm、SendGrid、Twilio、PEM 私钥块、JWT 以及内嵌凭据的连接字符串),并对形似密钥的变量名使用香农熵作为回退判断。匹配结果在返回前会被脱敏。
适用场景
适用于 AI 编码代理编写或审查代码时,可能把真实密钥粘贴进示例或测试夹具的场景,也适合在提交前快速检查 diff。更适合提交前或审查阶段的扫描,而非完整的仓库密钥管理。
运行要求
托管方式为远程 streamable HTTP 端点 secrets-leak-audit-mcp.mcpize.run;README 提到有免费套餐和每月 7 美元的 Pro 套餐。自托管需要 Node.js,运行 npm install 后执行 node server.js。未声明需要账户、API 密钥或环境变量。
安装前请注意
该服务会接收你提交的文本或 diff,使用托管端点时扫描内容会发送给第三方。基于熵值的发现属于启发式判断,可能产生误报。README 称匹配结果返回前会脱敏,但仍应将粘贴的内容视为可能敏感。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Secrets Leak Audit,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "secrets-leak-audit-mcp": {
      "type": "http",
      "url": "https://secrets-leak-audit-mcp.mcpize.run/mcp"
    }
  }
}

README

secrets-leak-audit-mcp

[License: MIT] [Live on MCPize]

An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops" in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example that includes a real key, or writing a test fixture with a plausible-looking but real value).

What it catches

High-precision vendor key matches. Real, current (2026) structural formats for AWS access keys, GitHub PATs (classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded credentials. These are precise format matches, not guesses — an AWS key is AKIA/ASIA + 16 specific characters, not "looks like it might be a key."

Entropy-based fallback. For secret-shaped variable names (API_KEY, PASSWORD, *_TOKEN) with no recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated credential and "password123" both match a suspicious name, but only one has the entropy of an actual secret — flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic.

Every match is redacted before it's returned — the tool never echoes a full secret value back, even to confirm a hit.

Tools

scan_for_secrets

Scans any text (a file's contents, a config snippet) for both categories above.

scan_diff

Scans a unified git diff and only checks lines the diff actually adds — won't flag a secret that was already being removed in the same diff, or one that only appears in unchanged context lines.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

bash
npm installnode server.js

Part of a small suite

github-actions-audit-mcp, dockerfile-audit-mcp, regex-safety-audit-mcp, mcp-trust-audit-mcp.

License

MIT

来源:README.md,提交 a8ddabc

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.0.0最新Oct 2, 2026