Mmcp.market

Secret Hygiene MCP server

by mrfentmen·io.github.mrfentmen/secret-hygiene-mcp·v1.0.0

Count secret-like patterns in bounded local files without returning values, keys, paths,...

A85/100grade A
What users say
No reviews yet
Be the first
Safety scan
A85/100

full report

Adoption
New

0 stars

Reviews

Write one

Nobody has reviewed Secret Hygiene yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Secret Hygiene tools (1)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • scan_secret_hygiene

    Count secret-like patterns in bounded local files without returning values, keys, paths, filenames, or matches.

Public scan report

scanner v0.1.9 · 2026-09-22 · same rubric, same numbers if you re-run it

no findings
  • Code scan8 source files scanned25/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 44 days ago12/15
  • Maintainer identityregistry namespace matches repository owner6/10
Overall 85/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

What the publisher says

From the Secret Hygiene repository's README, as published. We do not edit it. Read it on GitHub

secret-hygiene-mcp

Secret Hygiene scans bounded local files for common secret-like patterns and returns category counts only. It is designed as a pre-commit review signal, not a credential detector with perfect coverage.

Quick start

npm install
npm test
npm start

Use scansecrethygiene inside SECRETHYGIENEROOT.

Privacy and limits

Values, keys, matches, filenames, paths, and source text are never returned. Pattern matching is conservative and can produce false positives or miss unusual formats. Rotate exposed credentials separately.

Nothing above is checked by us. What we check is on the safety report.

Install directly

Runs npx -y secret-hygiene-mcp on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add secret-hygiene-mcp -- npx -y secret-hygiene-mcp
Add to Cursor

Secret Hygiene: common questions

Is Secret Hygiene MCP server safe?
Yes, by our scan: it is graded A (85/100). Read the Secret Hygiene safety report
How do I install Secret Hygiene?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does Secret Hygiene need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Secret Hygiene maintained?
The last commit was 45 days ago (2026-08-09). The latest release is v1.0.0.
What can I use instead of Secret Hygiene?
Servers from other publishers that do the same job: Connection String Secret Audit MCP server, MCP server and grim-mcp server. Compare all Secret Hygiene alternatives.

Alternatives to Secret Hygiene

Same job from other publishers: the closest match first, then the best rated.

All Secret Hygiene alternatives →
  • Connection String Secret Audit
    26 rules and 32 safe-replacement snippets for hardcoded connection strings, keys and kubeconfigs acr
    A
  • MCP
    Security tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.
    A
  • grim-mcp
    Security audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.
    C
  • Debezium
    Debezium / Kafka Connect CDC connector management for AI agents — governed, secret-safe.
    A
  • Draugr
    Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.
    A

More from mrfentmen