Developer · Local MCP server
Secrets Audit MCP
Detects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.eltociear/secrets-audit-mcp- Version
- 1.0.1
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- OCI image (Docker)
- Published
- 2026-06-07
- Updated
- 2026-06-07
- Publisher
- eltociear (GitHub) · 6 servers with pages here
- Listed under
- GitHub MCP servers, Stripe MCP servers, AWS MCP servers, OpenAI MCP servers
- Repository
- github.com/eltociear/secrets-audit-mcp
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| OCI image (Docker) | ghcr.io/eltociear/secrets-audit-mcp:1.0.1 | — | stdio |
How to connect Secrets Audit MCP
Secrets Audit MCP runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: ghcr.io/eltociear/secrets-audit-mcp:1.0.1. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm ghcr.io/eltociear/secrets-audit-mcp:1.0.1.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"secrets-audit-mcp": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/eltociear/secrets-audit-mcp:1.0.1"
]
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from eltociear (GitHub)
| Server | Runs |
|---|---|
| Contract Guard MCPEVM contract/token risk check + ERC20 approval (proxy, EIP-7702, unlimited-allowance). Zero deps. | Local · stdio |
| Repo Security Scanner — Malicious Code & Supply ChainAudit GitHub repos for malicious and supply-chain code before you depend on them. | Remote · HTTP |
| Skill Audit MCPMCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns. | Remote & Local · HTTP, stdio |
| Tokenguard MCPReal-world data for agents: air quality, geocoding, quakes, holidays, web search. | Remote · HTTP |
| URL to Clean Markdown for LLMs & RAGFetch URLs and return clean Markdown for RAG — nav, ads and boilerplate stripped. | Remote · HTTP |
More developer servers
| Server | Runs |
|---|---|
| Secobserve MCPMCP server for SecObserve: triage findings, import scan reports and SBOMs, generate VEX. | Local · stdio |
| Secop MCP ServerConsulta contratación pública de Colombia (SECOP I y II) desde datos.gov.co. | Local · stdio |
| Secret MCPLocal MCP server for isolated, evidence-backed GDWEB design analysis and web search. | Local · stdio |
| Secretguard MCPScans code for hardcoded secrets (AWS, Stripe, GitHub, JWTs) before an AI agent commits it. | Local · stdio |
| Secrets Leak AuditScan text and git diffs for committed credentials using real vendor key formats plus entropy. | Remote · HTTP |
| SecScanScan, monitor and fix a live web app from your editor: graded security reports with fix prompts. | Remote · HTTP |
| Secure FlowsMCP server for secureFlows (secure-flows.com). Alias of io.github.michal-lefler/secureflows-mcp. | Remote · HTTP |
| Secure Privacy MCPAn MCP server that automatically integrate GDPR-compliant cookie consent banners into websites. | Local · stdio |