Mmcp.market

Secret Scan MCP server

by agentic-income-bot·io.github.agentic-income-bot/mcp-secret-scan·v1.0.0

Check text for leaked credentials before an agent writes or commits it. Runs locally.

B83/100grade B
What users say
No reviews yet
Be the first
Safety scan
B83/100

full report

Adoption
New

0 stars

Reviews

Write one

Nobody has reviewed Secret Scan yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Secret Scan tools

No tool declarations could be read from the package source. They show once the server is installed.

Public scan report

scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it

no findings
  • Code scanpackage could not be scannedn/a
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 7 days ago15/15
  • Maintainer identityregistry namespace matches repository owner6/10
Overall 83/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

The registry entry has no remote endpoint or installable package.

Secret Scan: common questions

Is Secret Scan MCP server safe?
Mostly: it is graded B (83/100). Read the Secret Scan safety report
Does Secret Scan need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Secret Scan maintained?
The last commit was 8 days ago (2026-09-12). The latest release is v1.0.0.
What can I use instead of Secret Scan?
Servers from other publishers that do the same job: SkillTotal MCP server, Agent Wormhole MCP server and Husk MCP server. Compare all Secret Scan alternatives.

Alternatives to Secret Scan

Same job from other publishers: the closest match first, then the best rated.

All Secret Scan alternatives →
  • SkillTotal
    Deterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.
    B
  • Agent Wormhole
    Check tokens, pages and x402 payments before your agent trusts them. Offline verdicts.
    B
  • Husk
    Local-first defensive scanner for vulnerable dependencies, leaked secrets, and risky agent configs
    A
  • MCP
    Authorize consequential AI agent actions before execution
    A
  • Claude Real Video
    Let any LLM watch a video locally — and search everything it has ever watched.
    A

More from agentic-income-bot