MCP Secret Scrub runs on your own machine — the client starts it, so there is no endpoint to ping. 472 installs a week from pypi. Last commit 28 Aug 2026.
Deterministic no-LLM MCP server that scrubs secrets before they reach an agent. Never leaks values.
Today is the operative word: we check MCP Secret Scrub every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add mcp-secret-scrub -- uvx mcp-secret-scrub
{
"mcpServers": {
"mcp-secret-scrub": {
"args": [
"mcp-secret-scrub"
],
"command": "uvx"
}
}
}
[mcp_servers.mcp-secret-scrub]
command = "uvx"
args = ["mcp-secret-scrub"]
{
"mcpServers": {
"mcp-secret-scrub": {
"args": [
"mcp-secret-scrub"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"mcp-secret-scrub": {
"args": [
"mcp-secret-scrub"
],
"command": "uvx"
}
}
}
Deterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.
Detect hardcoded secrets in source and config. Reports masked previews, never the values.
A secure MCP server that lets AI agents query databases safely.
Deterministic, zero-token security scanner your AI agent calls to find and re-verify issues.
MCP server for VibeScan — scan projects for leaked secrets and security issues
Context-aware secret scanner: lets an AI agent scan, verify, and rewrite secrets before committing.
MCP server for MySQL. Read-only by default, row caps, statement timeouts, secrets never logged.
Zero-knowledge MCP secrets vault for AI agents: secrets injected at runtime, never seen by the model
Answers built from our own checks of this server.