# secrets-audit-mcp

> secrets-audit-mcp — eltociear-secrets-audit-mcp. Use this tool when you need to detect leaked credentials in your codebase, particularly for 32 major providers like AWS, GCP, and GitHub. It solves the problem of unintentionally exposed sensitive information, providing a secure interface with zero dependencies and a single file execution. Ideal for use in git repositories to identify and remediate potential security risks.

Canonical page: https://skillsregistry.net/skills/eltociear-secrets-audit-mcp  
JSON: https://api.skillsregistry.net/v1/skills/eltociear-secrets-audit-mcp

## Description

MCP server detecting leaked secrets/credentials (32+ provider rules). In the official MCP Registry: io.github.eltociear/secrets-audit-mcp. Pure stdlib, zero deps.

## Trust

- **Trust score (0–1):** 0.97
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Category:** version-control
- **Updated:** 2026-09-21

## Source

- **Source listing:** [GitHub](https://github.com/eltociear/secrets-audit-mcp)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "eltociear-secrets-audit-mcp"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/eltociear-secrets-audit-mcp` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/eltociear-secrets-audit-mcp/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
