Developer · Local MCP server

Secrets Audit MCP

Detects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps.

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.eltociear/secrets-audit-mcp
Version
1.0.1
Status
Active
Category
developer
Transport
stdio (local process)
Package
OCI image (Docker)
Published
2026-06-07
Updated
2026-06-07
Publisher
eltociear (GitHub) · 6 servers with pages here
Listed under
GitHub MCP servers, Stripe MCP servers, AWS MCP servers, OpenAI MCP servers
Repository
github.com/eltociear/secrets-audit-mcp
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
OCI image (Docker)ghcr.io/eltociear/secrets-audit-mcp:1.0.1—stdioNone declared

How to connect Secrets Audit MCP

Secrets Audit MCP runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: ghcr.io/eltociear/secrets-audit-mcp:1.0.1. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm ghcr.io/eltociear/secrets-audit-mcp:1.0.1.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "secrets-audit-mcp": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/eltociear/secrets-audit-mcp:1.0.1"
      ]
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More from eltociear (GitHub)

All 6 →
ServerRunsEndpoint or package
Contract Guard MCPEVM contract/token risk check + ERC20 approval (proxy, EIP-7702, unlimited-allowance). Zero deps.Local · stdioOCI image (Docker): ghcr.io/eltociear/contract-guard-mcp:mcp-1.1.0
Repo Security Scanner — Malicious Code & Supply ChainAudit GitHub repos for malicious and supply-chain code before you depend on them.Remote · HTTPmcp.apify.com
Skill Audit MCPMCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.Remote & Local · HTTP, stdioeltociear-skill-audit.hf.space
Tokenguard MCPReal-world data for agents: air quality, geocoding, quakes, holidays, web search.Remote · HTTPeltociear-tokenguard.hf.space
URL to Clean Markdown for LLMs & RAGFetch URLs and return clean Markdown for RAG — nav, ads and boilerplate stripped.Remote · HTTPmcp.apify.com

More developer servers

All 6,250 →
ServerRunsEndpoint or package
Secobserve MCPMCP server for SecObserve: triage findings, import scan reports and SBOMs, generate VEX.Local · stdioPyPI: secobserve-mcp
Secop MCP ServerConsulta contratación pública de Colombia (SECOP I y II) desde datos.gov.co.Local · stdioPyPI: secop-mcp-server
Secret MCPLocal MCP server for isolated, evidence-backed GDWEB design analysis and web search.Local · stdionpm: secret-design-mcp
Secretguard MCPScans code for hardcoded secrets (AWS, Stripe, GitHub, JWTs) before an AI agent commits it.Local · stdioMCP Bundle (.mcpb): vladimirbakalov/secretguard-mcp/releases/downloa
Secrets Leak AuditScan text and git diffs for committed credentials using real vendor key formats plus entropy.Remote · HTTPsecrets-leak-audit-mcp.mcpize.run
SecScanScan, monitor and fix a live web app from your editor: graded security reports with fix prompts.Remote · HTTPsecscan.us
Secure FlowsMCP server for secureFlows (secure-flows.com). Alias of io.github.michal-lefler/secureflows-mcp.Remote · HTTPsecure-flows.com
Secure Privacy MCPAn MCP server that automatically integrate GDPR-compliant cookie consent banners into websites.Local · stdionpm: secure-privacy-mcp