Secret Scrub
БесплатноНе проверенDeterministic no-LLM MCP server that scrubs secrets from text/logs before agent context. Redact/mask/hash, never leaks the value.
Описание
Deterministic no-LLM MCP server that scrubs secrets from text/logs before agent context. Redact/mask/hash, never leaks the value.
README
mcp-name: io.github.sudo-ai-git/mcp-secret-scrub
Deterministic, no-LLM MCP server that scrubs secrets from text, logs, and transcripts before they enter agent context — and never leaks the value.
No LLM. No network. Pure structural detection. MIT. Crown-jewel-free.
The problem it solves
Before you hand raw text to an agent (or store it, or pass it to a tool), you
often don't know whether it contains a live secret. Platform scrubbers miss
patterns all the time — a private key, an nvapi- token, a github_pat_
token, an api_key= assignment mid-log. If that text reaches an LLM context
or a persisted transcript, the secret is effectively exfiltrated.
This server answers, deterministically:
Which secrets are in this text, and can you redact them safely before it goes anywhere?
Detection coverage (deterministic profiles)
| family | examples |
|---|---|
| AI provider keys | sk-proj-…, sk-ant-api…, sk-or-v1-…, sk-…, nvapi-… |
| Cloud / GitHub | AKIA…, aws_secret_access_key=, ghp_…, gho_…, ghu_…, ghs_…, ghr_…, github_pat_… |
| Identity / auth | JWTs (eyJ…), PEM private keys, Bearer …, Basic …, OAuth client secrets |
| Assignments | api_key=, token=, secret=, password=, client_secret=, webhook_secret= |
| Endpoints / DSNs | Discord webhooks, Slack xox…, SQL/Redis/Mongo/AMQP connection strings |
The scan never returns the secret value — only its type, count, and position. That is a hard safety contract, enforced by test.
Tools (MCP)
| tool | purpose |
|---|---|
scrub_text(text, mode, keep_label) |
redact / mask / hash secrets; returns scrubbed text (never the value) |
scan_text(text) |
detect which secret types are present (no mutation) |
report_full(text) |
scan + redact in one call, scrubbed preview + findings |
secret_profiles() |
list all supported detection profiles |
Modes:
redact(default) →[REDACTED:TYPE]mask→ shows first 4 + last 2 charshash→ deterministic SHA-256 prefix (reproducible across calls)
Quick start (stdio)
pip install mcp-secret-scrub
mcp-secret-scrub # stdio (default)
Or via uv/pipx for an installable console entry:
pipx install mcp-secret-scrub
MCP client config:
{ "mcpServers": {
"secret-scrub": { "command": "mcp-secret-scrub" }
}}
Streamable HTTP (remote / Smithery-publishable)
python3 mcp_server.py --http --port 8138 # serves on http://<host>:8138/mcp/
Determinism & safety guarantees
- Deterministic: same input → identical output in every mode, every call.
- Never leaks:
scan_textandscrub_textnever emit the original token;_deterministic_hashis SHA-256 (no salt) so output is reproducible. - No LLM, no network: pure regex + reachable structure detection.
- Input-safe: non-string input returns a clean error, not a traceback.
Verification
python3 test_detector.py— 14/14 core checks (detection, redaction, determinism, no-leak contract, benign/unicode/empty input, bad-mode)python3 test_e2e.py— drives the real MCP stdio transport and asserts the secret does NOT cross the wire
License & provenance
MIT. Part of the sudo-ai-git deterministic no-LLM agent-trust MCP family
(mcp-skill-sec · mcp-verify-claim · mcp-benchmark-hygiene ·
mcp-secret-scrub).
Установка Secret Scrub
У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.
▸ github.com/sudo-ai-git/mcp-secret-scrubFAQ
Secret Scrub MCP бесплатный?
Да, Secret Scrub MCP бесплатный — установка в пару кликов через Unyly без оплаты.
Нужен ли API-ключ для Secret Scrub?
Нет, Secret Scrub работает без API-ключей и переменных окружения.
Secret Scrub — hosted или self-hosted?
Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.
Как установить Secret Scrub в Claude Desktop, Claude Code или Cursor?
Открой Secret Scrub на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.
Похожие MCP
Fetch
Web content fetching and conversion for efficient LLM usage.
Roblox Studio
Enables AI coding tools to control Roblox Studio for workspace exploration, instance manipulation, and script management. It provides tools for playtesting, sce
автор: paralovOpencode Omniroute Plugin
OpenCode plugin for the OmniRoute AI Gateway. Drives dynamic model discovery, /connect auth flow, and multi-instance OmniRoute providers via the official @openc
автор: GitHub ActionsAWS KB Retrieval
Retrieval from AWS Knowledge Base using Bedrock Agent Runtime.
автор: modelcontextprotocolSpring AI MCP Server
Provides auto-configuration for setting up an MCP server in Spring Boot applications.
llm-analysis-assistant
A very streamlined mcp client that supports calling and monitoring stdio/sse/streamableHttp, and can also view request responses through the /logs page. It also
автор: xuzexin-hzMCP-Agent
A simple, composable framework to build agents using Model Context Protocol by [LastMile AI](https://www.lastmileai.dev)
автор: lastmile-aiSpring AI MCP Client
Provides auto-configuration for MCP client functionality in Spring Boot applications.
mcp.natoma.ai
A Hosted MCP Platform to discover, install, manage and deploy MCP servers by [Natoma Labs](https://www.natoma.ai)
MCPHub
Website to list high quality MCP servers and reviews by real users. Also provide online chatbot for popular LLM models with MCP server support.
Compare Secret Scrub with
Не уверен что выбрать?
Найди свой стек за 60 секунд
Автор?
Embed-бейдж для README
Похожее
Все в категории ai
