# secretscan-mcp-server

> secretscan-mcp-server — wedo911-secretscan-mcp-server. Use this tool when you need to detect and prevent leaked secrets in code, such as AWS keys, GitHub tokens, or private keys, before committing or sharing it. It scans diffs, files, or snippets for sensitive information, providing redacted output to protect security. Ideal for use in git workflows to identify potential security risks and prevent accidental exposures.

Canonical page: https://skillsregistry.net/skills/wedo911-secretscan-mcp-server  
JSON: https://api.skillsregistry.net/v1/skills/wedo911-secretscan-mcp-server

## Description

MCP server that scans a diff/file/snippet for leaked secrets (AWS, GitHub, Slack, Stripe, private keys, JWTs, entropy-gated generic) before an agent commits or shares it. Local-only, redacted output.

## Trust

- **Trust score (0–1):** 1.00
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **License:** MIT
- **Updated:** 2026-09-28

## Source

- **Source listing:** [GitHub](https://github.com/wedo911/secretscan-mcp-server)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "wedo911-secretscan-mcp-server"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/wedo911-secretscan-mcp-server` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/wedo911-secretscan-mcp-server/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
