Hardcoded Credential Audit runs on your own machine — the client starts it, so there is no endpoint to ping. 303 installs a week from npm. Last commit 22 Sep 2026.
Open any config file and see every hardcoded credential — and every setting that quietly undoes your
Today is the operative word: we check Hardcoded Credential Audit every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add hardcoded-credential-audit -- npx -y @readystack/hardcoded-credential-audit
{
"mcpServers": {
"hardcoded-credential-audit": {
"args": [
"-y",
"@readystack/hardcoded-credential-audit"
],
"command": "npx"
}
}
}
[mcp_servers.hardcoded-credential-audit]
command = "npx"
args = ["-y", "@readystack/hardcoded-credential-audit"]
{
"mcpServers": {
"hardcoded-credential-audit": {
"args": [
"-y",
"@readystack/hardcoded-credential-audit"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"hardcoded-credential-audit": {
"args": [
"-y",
"@readystack/hardcoded-credential-audit"
],
"command": "npx"
}
}
}
Reads security headers and CSP line by line in your config file and names the lines that silently do
Names every schedule line in the file you have open that fires at the wrong hour, twice, or never at
Names every line in the file you have open that starts a recurring cloud charge, with the published
Find every leaked secret on your machine — API keys in .env files, shell history, and configs.
Detect hardcoded secrets in source and config. Reports masked previews, never the values.
One profile — skills, credentials, and memory — synced to every agent tool via one MCP URL.
Secure Open Finance Brasil MCP server with typed tools and a credential-free mock mode
The Figma file you have open, as MCP tools. Extract, edit, and keep a saved set.
Answers built from our own checks of this server.