Secret Scan MCP server
Check text for leaked credentials before an agent writes or commits it. Runs locally.
B83/100grade B
Adoption
New
0 stars
Reviews
Write oneNobody has reviewed Secret Scan yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Secret Scan tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
no findings
- –Code scanpackage could not be scannedn/a
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 7 days ago15/15
- Maintainer identityregistry namespace matches repository owner6/10
Overall 83/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Install directly
The registry entry has no remote endpoint or installable package.
Secret Scan: common questions
- Is Secret Scan MCP server safe?
- Mostly: it is graded B (83/100). Read the Secret Scan safety report
- Does Secret Scan need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Secret Scan maintained?
- The last commit was 8 days ago (2026-09-12). The latest release is v1.0.0.
- What can I use instead of Secret Scan?
- Servers from other publishers that do the same job: SkillTotal MCP server, Agent Wormhole MCP server and Husk MCP server. Compare all Secret Scan alternatives.
Alternatives to Secret Scan
Same job from other publishers: the closest match first, then the best rated.
- SkillTotalDeterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.not reviewedGrowingB
- Agent WormholeCheck tokens, pages and x402 payments before your agent trusts them. Offline verdicts.not reviewedGrowingB
- HuskLocal-first defensive scanner for vulnerable dependencies, leaked secrets, and risky agent configsnot reviewedGrowingA
- MCPAuthorize consequential AI agent actions before executionnot reviewedEstablishedA
- Claude Real VideoLet any LLM watch a video locally — and search everything it has ever watched.not reviewedEstablishedA