secrets-leak-audit-mcp
Scans text and git diffs for accidentally-committed credentials via high-precision structural matching against real current key formats (AWS, GitHub, Stripe, Slack, Google, OpenAI, Anthropic, npm, SendGrid, Twilio, PEM keys, JWTs, DB connection strings) plus an entropy-based fallback for unrecognized secret-shaped values.
How to pay
Subscribe
$12/month
Predictable monthly cost with included usage. Best for steady, high-volume traffic.
- Unlimited tools within plan limits
- One API key, billed once a month
- Cancel any time
Catch the key before it is committed
Scans text and git diffs for credentials using structural matching against real current key formats, with an entropy fallback for secret-shaped values that match nothing known.
Detects
AWS, GitHub, Stripe, Slack, Google, OpenAI, Anthropic, npm, SendGrid and Twilio keys, PEM private keys, JWTs and database connection strings.
Tools
- scan_for_secrets: scan any text, file contents or config.
- scan_diff: scan a unified git diff and report only the added lines.
Run it on a diff before an agent commits or pushes. Input is analysed in memory and never stored or logged.
Pricing
Free: 10 scans a day. Pro: unlimited. Static, deterministic checks, no LLM calls, no data stored. Your input is analysed in memory and discarded.