Secret Scanner — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Secret Scanner (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Catch leaked secrets in a diff/file before you commit, push or open a PR.
secret-scanner scans a blob of code, text or a unified git diff for leaked secrets and returns a CLEAN / REVIEW / LEAK verdict. Every finding includes the secret type, provider, severity and `line:column`, a masked excerpt (the full secret is never echoed), and a remediation note.
Detection is 100% local — the content you scan is never sent anywhere.
npx -y secret-scanner-mcpPOST /pro/scan ($0.02 USDC on Base, no sign-up)POST /scan (rate-limited)| Category | Examples |
|---|---|
| 🔑 Provider keys | AWS (AKIA…), GitHub (ghp_…, fine-grained), OpenAI (sk-…), Anthropic (sk-ant-…), Stripe (sk_live_…), Google (AIza…, GOCSPX-…), Slack (xox…), Twilio, SendGrid, Mailgun, npm (npm_…), PyPI, Telegram, Discord, Shopify, Square, DigitalOcean, Cloudflare, Vault, Doppler |
| 📜 Private keys | RSA / EC / DSA / OpenSSH / PGP / encrypted private-key blocks, GCP service-account JSON |
| 🗄️ Connection strings | postgres://, mysql://, mongodb+srv://, redis:// URIs with embedded passwords; JDBC password=; basic-auth URLs |
| 🎫 Tokens | JWTs, generic api_key = "…" assignments |
| 🎲 Unknown secrets | high Shannon-entropy base64/hex blobs that look like credentials even without a known prefix |
{
"mcpServers": {
"secret-scanner": { "command": "npx", "args": ["-y", "secret-scanner-mcp"] }
}
}Tool: `scan_for_secrets` — params content (string, required), deep (boolean, optional; adds offline format-validity hints).
Or connect over HTTP at POST /mcp (free).
# Free (rate-limited 30/h/IP)
curl -X POST https://secret-scanner.vercel.app/scan \
-H 'content-type: application/json' \
-d '{"content":"AWS_KEY=AKIAIOSFODNN7EXAMPLE"}'
# Paid, deep, unlimited (x402 — agent pays $0.02 USDC automatically)
curl -X POST https://secret-scanner.vercel.app/pro/scan \
-H 'content-type: application/json' \
-d '{"content":"<your diff>"}'Example response:
{
"verdict": "LEAK",
"score": 80,
"summary": "1 potential secret(s) across 1 line(s): AWS×1. Verdict LEAK.",
"lines": 1,
"findings": [
{
"rule": "aws-access-key-id",
"title": "AWS Access Key ID",
"provider": "AWS",
"severity": "high",
"line": 1,
"column": 9,
"match": "AKIA…MPLE (20 chars)",
"remediation": "Rotate the IAM key immediately in the AWS console and remove it from history."
}
],
"meta": { "deep": false, "bytes": 28, "truncated": false, "rulesEvaluated": 35, "entropyFindings": 0 }
}The free tier is rate-limited. The /pro/scan route is gated by x402: your agent pays $0.02 USDC per call on Base automatically — no account, no API key. It settles on-chain to the operator's receiving wallet. Deep mode adds offline structural-validity hints for formats whose shape can be verified without any network call.
The scan runs in-process. The content you submit is not stored and not forwarded to any third party. Secrets in findings are always masked (AKIA…MPLE (20 chars)), never returned in full.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.