Secrets Leak Audit

io.github.tylerscomic-labv1.0.0更新於 Oct 2, 2026

Scan text and git diffs for committed credentials using real vendor key formats plus entropy.

已驗證Streamable HTTP可網頁執行Developer ToolsSecurity & Monitoring

概覽

AI 產生的概覽

掃描文字與 git diff,透過廠商金鑰格式與熵值啟發式規則偵測誤提交的憑證。

功能
提供兩個工具:scan_for_secrets 檢查任意文字(例如檔案內容或設定片段),scan_diff 只檢查統一 git diff 中新增的行。它比對已知廠商金鑰格式(AWS、GitHub、Stripe、Slack、Google、OpenAI、Anthropic、npm、SendGrid、Twilio、PEM 私鑰區塊、JWT,以及內嵌憑證的連線字串),並對看似金鑰的變數名稱以 Shannon 熵值作為備援判斷。比對結果在回傳前會先遮蔽。
適用情境
適合 AI 編碼代理撰寫或審查程式碼時,可能把真實金鑰貼進範例或測試 fixture 的情況,也適合在提交前快速檢查 diff。較適合提交前或審查階段的掃描,而非完整的儲存庫金鑰管理。
執行需求
託管方式為遠端 streamable HTTP 端點 secrets-leak-audit-mcp.mcpize.run;README 提到有免費方案與每月 7 美元的 Pro 方案。自架需要 Node.js,執行 npm install 後再執行 node server.js。未宣告需要帳號、API 金鑰或環境變數。
安裝前請注意
此服務會接收你提交的文字或 diff,使用託管端點時掃描內容會傳送給第三方。以熵值為基礎的發現屬於啟發式判斷,可能產生誤報。README 表示比對結果在回傳前會先遮蔽,但仍應將貼上的內容視為可能敏感。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Secrets Leak Audit,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "secrets-leak-audit-mcp": {
      "type": "http",
      "url": "https://secrets-leak-audit-mcp.mcpize.run/mcp"
    }
  }
}

README

secrets-leak-audit-mcp

[License: MIT] [Live on MCPize]

An MCP server that scans text and diffs for accidentally-committed credentials — the single most common "oops" in software, and an easy thing for an AI coding agent to introduce without noticing (pasting a working example that includes a real key, or writing a test fixture with a plausible-looking but real value).

What it catches

High-precision vendor key matches. Real, current (2026) structural formats for AWS access keys, GitHub PATs (classic and fine-grained), Stripe live keys, Slack tokens, Google API keys, OpenAI and Anthropic keys, npm tokens, SendGrid, Twilio, PEM private key blocks, JWTs, and database connection strings with embedded credentials. These are precise format matches, not guesses — an AWS key is AKIA/ASIA + 16 specific characters, not "looks like it might be a key."

Entropy-based fallback. For secret-shaped variable names (API_KEY, PASSWORD, *_TOKEN) with no recognized vendor prefix, checks the assigned value's character-randomness (Shannon entropy). A real generated credential and "password123" both match a suspicious name, but only one has the entropy of an actual secret — flagged separately and at lower confidence than the vendor-format matches, since this one really is a heuristic.

Every match is redacted before it's returned — the tool never echoes a full secret value back, even to confirm a hit.

Tools

scan_for_secrets

Scans any text (a file's contents, a config snippet) for both categories above.

scan_diff

Scans a unified git diff and only checks lines the diff actually adds — won't flag a secret that was already being removed in the same diff, or one that only appears in unchanged context lines.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

bash
npm installnode server.js

Part of a small suite

github-actions-audit-mcp, dockerfile-audit-mcp, regex-safety-audit-mcp, mcp-trust-audit-mcp.

License

MIT

來源:README.md,提交 a8ddabc

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 2, 2026