secret-scanner

Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.

我該用這個嗎

品質與安全性

A
說明品質
100%
結構描述完整度
90%
命名品質
80%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

根據工具定義與協定合規性的自動化分析。

上下文成本

~347Token(工具定義)
~1.5 KB典型回應大小
極小的注意力影響(128k 上下文的 0.27%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "secret-scanner": {
      "url": "https://mcp.knurl.tools/mcp"
    }
  }
}

遠端端點

https://mcp.knurl.tools/mcpstreamable-http

它能做什麼

工具清單

工具(1)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟢scan_for_secrets(text, files)

Scan a pasted config, file, code snippet, or blob for exposed credentials and obvious security misconfigurations. Use whenever a user shares a .env, docker-compose.yml, nginx.conf, JSON/YAML config, or any text and asks "is this safe to share/commit?", "any leaked API keys/secrets?", or "what's misconfigured?". Detects cloud credentials, Stripe/GitHub/GitLab tokens, OpenAI/Anthropic/Gemini/Hugging Face/Groq/Replicate keys, private-key blocks, JWTs, DB connection strings, plus misconfigs like debug-on, 0.0.0.0 binds, disabled TLS verification, privileged containers, and weak passwords. Deterministic. It analyzes the provided text and returns findings only — it never stores, transmits, or requires any live credential.

輸入結構描述

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "description": "A single blob to scan."
    },
    "files": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "description": "Filename or path (e.g. \".env\")."
          },
          "content": {
            "type": "string",
            "description": "Raw text content of the file."
          }
        },
        "required": [
          "name",
          "content"
        ],
        "additionalProperties": false
      },
      "description": "Multiple named files to scan."
    }
  },
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本1 個工具
已驗證未記錄版本1 個工具