Altro · Server MCP locale
Secret Scanner
Scans files for leaked secrets and API keys.
Cosa indica il MCP Registry
La voce come pubblicata nel MCP Registry ufficiale (consultazione: 4 ottobre 2026), ultima versione.
- Nome nel registro
io.github.4hmetuyar/secret-scanner- Versione
- 0.2.10
- Stato
- Attivo
- Categoria
- altro
- Trasporto
- stdio (processo locale)
- Pacchetto
- npm
- Pubblicato
- 2 ottobre 2026
- Aggiornato
- 2 ottobre 2026
- Editore
- 4hmetuyar (GitHub) · 26 server con una pagina qui
- Namespace
- Namespace verificato dal MCP Registry tramite GitHub (github.com/4hmetuyar) · come funziona
- Repository
- github.com/GuardBee/guardbee-mcp (cartella packages/secret-scanner)
- Fonte
- Voce nell’API del registro
Pacchetti
| Registro | Pacchetto | Versione | Trasporto |
|---|---|---|---|
| npm | @guardbee/mcp-secret-scanner | 0.2.10 | stdio |
Come collegare Secret Scanner
Secret Scanner viene eseguito in locale a partire da un pacchetto Node.js pubblicato nel registro npm: @guardbee/mcp-secret-scanner, versione 0.2.10. Comunica via MCP su stdio, quindi il client lo avvia come programma e dialoga con esso tramite standard input e standard output. Richiede Node.js; i client in genere lo avviano con npx - il comando abituale è npx -y @guardbee/mcp-secret-scanner@0.2.10.
Nel formato JSON mcpServers, letto da molti client MCP desktop e per editor di codice, la voce si presenta così (segnaposto tra parentesi angolari):
{
"mcpServers": {
"secret-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-secret-scanner@0.2.10"
]
}
}
}Ricavato dalla voce del registro, non testato qui. Cosa fa il server, e a quali condizioni, lo stabilisce il suo editore; prima di concedergli l’accesso ai propri account o file conviene consultarne il repository o il sito web. Come aggiungere un server MCP a un assistente · Prima di collegare un server
Altri server di 4hmetuyar (GitHub)
| Server | Esecuzione |
|---|---|
| Memory Poisoning ScannerScans agent code for untrusted input poisoning persistent cross-session memory. | Locale · stdio |
| Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks. | Locale · stdio |
| Oauth AuditorScans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience. | Locale · stdio |
| Prompt Injection ScannerScans RAG content/scraped pages for indirect prompt injection. | Locale · stdio |
| Prompt Leak ScannerCatches leaked credentials and PII in outbound LLM prompts. | Locale · stdio |
| Rug Pull DetectorBaselines an MCP server's tools and detects tool-definition changes after approval. | Locale · stdio |
| Security ProxyMCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log. | Locale · stdio |
| Security SuiteBundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence. | Locale · stdio |
| Slopsquat ScannerChecks declared npm/PyPI dependencies against real registries to catch slopsquatting. | Locale · stdio |
| Tool Poisoning ScannerScans MCP tool definitions for hidden instructions and confused-deputy sinks. | Locale · stdio |
| Toxic Flow AuditorFinds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress. | Locale · stdio |
| Unbounded Consumption AuditorScans LLM/agent code for Unbounded Consumption / denial-of-wallet risks (OWASP LLM Top 10 2026 #6) | Locale · stdio |
Altri server della categoria altro
| Server | Esecuzione |
|---|---|
| Secop MCP ServerConsulta contratación pública de Colombia (SECOP I y II) desde datos.gov.co. | Locale · stdio |
| Secret Hygiene MCPCount secret-like patterns in bounded local files without returning values, keys, paths,... | Locale · stdio |
| Secret Safe EnvWrite secrets into.env without the agent ever seeing the value - Windows masked dialog (繁中 UI) | Locale · stdio |
| Secret ScanCheck text for leaked credentials before an agent writes or commits it. Runs locally. | Locale · stdio |
| Secret ScannerScan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored. | Remoto · HTTPVerifica live: ✗ nessun handshake |
| SecretcarouselAgent-first secrets vault. Store, rotate, and share credentials from chat. 20 tools. | Remoto e locale · SSE e stdioVerifica live: ✓ SSE raggiungibile |
| Secrets-LEDetect hardcoded secrets in source and config. Reports masked previews, never the values. | Locale · stdio |
| Sector PulseLive US sector rotation: 30 sector baskets ranked every session, versioned rosters, daily record. | Remoto · HTTPVerifica live: ✓ handshake |