# secret-scanner MCP server

Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.

## Links
- Registry page: https://www.getdrio.com/mcp/tools-knurl-secret-scanner
- Website: https://knurl.tools/secret-scanner

## Install
- Endpoint: https://mcp.knurl.tools/mcp
- Auth: Not captured

## Setup notes
- Remote endpoint: https://mcp.knurl.tools/mcp

## Tools
- scan_for_secrets (Scan for exposed secrets & misconfigurations) - Scan a pasted config, file, code snippet, or blob for exposed credentials and obvious security misconfigurations. Use whenever a user shares a .env, docker-compose.yml, nginx.conf, JSON/YAML config, or any text and asks "is this safe to share/commit?", "any leaked API keys/secrets?", or "what's misconfigured?". Detects cloud credentials, Stripe/GitHub/GitLab tokens, OpenAI/Anthropic/Gemini/Hugging Face/Groq/Replicate keys, private-key blocks, JWTs, DB connection strings, plus misconfigs like debug-on, 0.0.0.0 binds, disabled TLS verification, privileged containers, and weak passwords. Deterministic. It analyzes the provided text and returns findings only — it never stores, transmits, or requires any live credential. Endpoint: https://mcp.knurl.tools/mcp

## Resources
- ui://widget/scan-report.html

## Prompts
Not captured

## Metadata
- Owner: tools.knurl
- Version: 0.1.0
- Runtime: Streamable Http
- Transports: HTTP
- License: Not captured
- Language: Not captured
- Stars: Not captured
- Updated: Jun 24, 2026
- Source: https://registry.modelcontextprotocol.io
