Secret Scanner is answering right now. Last checked 14 min ago. It exposes 1 tools.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Today is the operative word: we check Secret Scanner every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 14 min ago.
claude mcp add secret-scanner --transport http https://mcp.knurl.tools/mcp
{
"mcpServers": {
"secret-scanner": {
"url": "https://mcp.knurl.tools/mcp"
}
}
}
[mcp_servers.secret-scanner]
url = "https://mcp.knurl.tools/mcp"
{
"mcpServers": {
"secret-scanner": {
"url": "https://mcp.knurl.tools/mcp"
}
}
}
{
"mcpServers": {
"secret-scanner": {
"url": "https://mcp.knurl.tools/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
scan_for_secrets
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://mcp.knurl.tools/mcp | streamable-http | answering | 482 ms | 14 min ago |
Scans AI coding sessions and assistant configs for leaked secrets and risky hooks; local, redacted
Check text for leaked credentials before an agent writes or commits it. Runs locally.
Find every leaked secret on your machine — API keys in .env files, shell history, and configs.
Scans code changes for leaked secrets and insecure config, with actionable fixes for AI agents.
Scans projects for secret exposure: leaked API keys, unprotected .env files, and secrets in logs.
Local-first defensive scanner for vulnerable dependencies, leaked secrets, and risky agent configs
MCP server for VibeScan — scan projects for leaked secrets and security issues
Scan a running app or repo for leaked secrets, exposed routes and open RLS, and verify live keys
Answers built from our own checks of this server.