Secret Hygiene MCP server
Count secret-like patterns in bounded local files without returning values, keys, paths,...
0 stars
Reviews
Write oneNobody has reviewed Secret Hygiene yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Secret Hygiene tools (1)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
scan_secret_hygieneCount secret-like patterns in bounded local files without returning values, keys, paths, filenames, or matches.
Public scan report
scanner v0.1.9 · 2026-09-22 · same rubric, same numbers if you re-run it
- Code scan8 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 44 days ago12/15
- Maintainer identityregistry namespace matches repository owner6/10
What the publisher says
From the Secret Hygiene repository's README, as published. We do not edit it. Read it on GitHub
secret-hygiene-mcp
Secret Hygiene scans bounded local files for common secret-like patterns and returns category counts only. It is designed as a pre-commit review signal, not a credential detector with perfect coverage.
Quick start
npm install
npm test
npm startUse scansecrethygiene inside SECRETHYGIENEROOT.
Privacy and limits
Values, keys, matches, filenames, paths, and source text are never returned. Pattern matching is conservative and can produce false positives or miss unusual formats. Rotate exposed credentials separately.
Nothing above is checked by us. What we check is on the safety report.
Install directly
Runs npx -y secret-hygiene-mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add secret-hygiene-mcp -- npx -y secret-hygiene-mcp
Secret Hygiene: common questions
- Is Secret Hygiene MCP server safe?
- Yes, by our scan: it is graded A (85/100). Read the Secret Hygiene safety report
- How do I install Secret Hygiene?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Secret Hygiene need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Secret Hygiene maintained?
- The last commit was 45 days ago (2026-08-09). The latest release is v1.0.0.
- What can I use instead of Secret Hygiene?
- Servers from other publishers that do the same job: Connection String Secret Audit MCP server, MCP server and grim-mcp server. Compare all Secret Hygiene alternatives.
Alternatives to Secret Hygiene
Same job from other publishers: the closest match first, then the best rated.
- Connection String Secret Audit26 rules and 32 safe-replacement snippets for hardcoded connection strings, keys and kubeconfigs acrnot reviewedGrowingA
- MCPSecurity tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.not reviewedGrowingA
- grim-mcpSecurity audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.not reviewedGrowingC
- DebeziumDebezium / Kafka Connect CDC connector management for AI agents — governed, secret-safe.not reviewedGrowingA
DraugrSecurity scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.not reviewedGrowingA