MCP 서버

secret-scanner

tools.knurl/secret-scanner
보안 공개 · 연결 가능 MCP 2025-11-25

이 MCP로 할 수 있는 일

Scans supplied files, configurations, code, or text for exposed credentials and common security misconfigurations.

scan_for_secrets
Scan for exposed secrets & misconfigurations
Scan a pasted config, file, code snippet, or blob for exposed credentials and obvious security misconfigurations. Use whenever a user shares a .env, docker-compose.yml, nginx.conf, JSON/YAML config, or any text and asks "is this safe to share/commit?", "any leaked API keys/secrets?", or "what's misconfigured?". Detects cloud credentials, Stripe/GitHub/GitLab tokens, OpenAI/Anthropic/Gemini/Hugging Face/Groq/Replicate keys, private-key blocks, JWTs, DB connection strings, plus misconfigs like debug-on, 0.0.0.0 binds, disabled TLS verification, privileged containers, and weak passwords. Deterministic. It analyzes the provided text and returns findings only — it never stores, transmits, or requires any live credential.
읽기 전용 멱등성
입력 스키마
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'text': {'type': 'string', 'description': 'A single blob to scan.'}, 'files': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'content'], 'properties': {'name': {'type': 'string', 'description': 'Filename or path (e.g. ".env").'}, 'content': {'type': 'string', 'description': 'Raw text content of the file.'}}, 'additionalProperties': False}, 'description': 'Multiple named files to scan.'}}, 'additionalProperties': False}
추가됨
scan_for_secrets
2026년 9월 17일 12:55 PM