Secret Hygiene MCP runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 9 Aug 2026.
Count secret-like patterns in bounded local files without returning values, keys, paths,...
Today is the operative word: we check Secret Hygiene MCP every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add secret-hygiene-mcp -- npx -y secret-hygiene-mcp
{
"mcpServers": {
"secret-hygiene-mcp": {
"args": [
"-y",
"secret-hygiene-mcp"
],
"command": "npx"
}
}
}
[mcp_servers.secret-hygiene-mcp]
command = "npx"
args = ["-y", "secret-hygiene-mcp"]
{
"mcpServers": {
"secret-hygiene-mcp": {
"args": [
"-y",
"secret-hygiene-mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"secret-hygiene-mcp": {
"args": [
"-y",
"secret-hygiene-mcp"
],
"command": "npx"
}
}
}
Read-only access to secrets in a local KeePassXC vault. Runs commands with them injected.
Scans projects for secret exposure: leaked API keys, unprotected .env files, and secrets in logs.
Run Python code in a secure sandbox without local setup. Declare inline dependencies and execute s…
Secrets for developers and agents—secure context and workflows without exposing secret values.
Stop AI coding agents from leaking API keys. Local proxy swaps real secrets for phm_ tokens.
Local MCP access to approved 1Password fields without exposing plaintext secrets to AI agents.
Write secrets into .env without the agent ever seeing the value - Windows masked dialog (繁中 UI)
Local-first persistent memory MCP: shared SQLite key/value store, searchable, TTL-aware, secret-safe
Answers built from our own checks of this server.