Connection String Secret Audit runs on your own machine — the client starts it, so there is no endpoint to ping. 315 installs a week from npm. Last commit 22 Sep 2026.
26 rules and 32 safe-replacement snippets for hardcoded connection strings, keys and kubeconfigs acr
Today is the operative word: we check Connection String Secret Audit every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add connection-string-secret-audit -- npx -y @readystack/connection-string-secret-audit
{
"mcpServers": {
"connection-string-secret-audit": {
"args": [
"-y",
"@readystack/connection-string-secret-audit"
],
"command": "npx"
}
}
}
[mcp_servers.connection-string-secret-audit]
command = "npx"
args = ["-y", "@readystack/connection-string-secret-audit"]
{
"mcpServers": {
"connection-string-secret-audit": {
"args": [
"-y",
"@readystack/connection-string-secret-audit"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"connection-string-secret-audit": {
"args": [
"-y",
"@readystack/connection-string-secret-audit"
],
"command": "npx"
}
}
}
Secrets vault for Claude Code with audit logs, access rules, and AES-256 encryption.
Scans code for hardcoded secrets (AWS, Stripe, GitHub, JWTs) before an AI agent commits it.
Detect hardcoded secrets in source and config. Reports masked previews, never the values.
Scans AI coding sessions and assistant configs for leaked secrets and risky hooks; local, redacted
Scan codebases for LLM/AI SDK usage, exposed API tokens, and hardcoded secrets.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Debezium / Kafka Connect CDC connector management for AI agents — governed, secret-safe.
Scans code changes for leaked secrets and insecure config, with actionable fixes for AI agents.
Answers built from our own checks of this server.