Skip to main content
Glama

Server Details

Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.

If you are the author of this connector, you can claim ownership with GitHub, an HTTP challenge, or a DNS record. Claimed connector authors can inspect health checks, view analytics, and manage their listing.
Status
Healthy
Last Tested
Transport
Streamable HTTP
URL

Available Tools

1 tool
scan_for_secretsScan for exposed secrets & misconfigurationsA
Read-onlyIdempotent
Inspect

Scan a pasted config, file, code snippet, or blob for exposed credentials and obvious security misconfigurations. Use whenever a user shares a .env, docker-compose.yml, nginx.conf, JSON/YAML config, or any text and asks "is this safe to share/commit?", "any leaked API keys/secrets?", or "what's misconfigured?". Detects cloud credentials, Stripe/GitHub/GitLab tokens, OpenAI/Anthropic/Gemini/Hugging Face/Groq/Replicate keys, private-key blocks, JWTs, DB connection strings, plus misconfigs like debug-on, 0.0.0.0 binds, disabled TLS verification, privileged containers, and weak passwords. Deterministic. It analyzes the provided text and returns findings only — it never stores, transmits, or requires any live credential.

ParametersJSON Schema
NameRequiredDescriptionDefault
textNoA single blob to scan.
filesNoMultiple named files to scan.

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations (readOnlyHint=true, destructiveHint=false, idempotentHint=true), the description adds critical behavioral context: it is deterministic, returns findings only, and 'never stores, transmits, or requires any live credential.' This gives the agent confidence that the operation is safe and non-invasive, going beyond the annotations alone.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense and front-loaded with the core action. Every sentence contributes useful information: what it scans, when to use it, what it detects, and behavioral guarantees. Despite its length, there is no fluff or redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given there is no output schema, the description compensates by mentioning 'returns findings only,' covering input types, detection categories, and safety guarantees. It fully equips the agent to select and invoke the tool correctly without needing additional context about return values or side effects.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema already provides full descriptions for both parameters ('text' as a single blob, 'files' as multiple named files), so baseline is 3. The description adds context about what kinds of content can be scanned (e.g., config snippets, code) but does not clarify whether text and files are mutually exclusive, which would add value. It does not significantly enhance parameter-level meaning beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's function with a specific verb ('Scan') and resource ('pasted config, file, code snippet, or blob') for detecting exposed credentials and security misconfigurations. It lists concrete detection categories (cloud credentials, API tokens, JWTs, misconfigs), making the purpose unmistakable. There are no sibling tools to differentiate from, so no distinction is needed.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit usage guidance is provided with example user intents ('is this safe to share/commit?', 'any leaked API keys/secrets?') and specific file types ('.env, docker-compose.yml, nginx.conf, JSON/YAML config'). It clearly tells the agent when to invoke this tool, making it easy to match against user requests.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 1 tool update
    • First observedscan_for_secrets

Frequently Asked Questions

Discussions

No comments yet. Be the first to start the discussion!

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    C
    maintenance
    Scans diffs, files, and snippets for leaked secrets like AWS keys, GitHub tokens, and private keys, returning redacted findings while running fully locally without network calls.
    1
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Detects leaked credentials in source code with tools to scan text, files, and directories for API keys, tokens, and private keys across 30+ providers.
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables scanning diffs or code blobs for leaked secrets, returning a verdict with severity and masked findings, all processed locally with no data sent externally.
    1
    MIT
Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.7/5.0
Disambiguation5/5

With only one tool, there is no possibility of confusion. scan_for_secrets has a clear, singular purpose of analyzing text for secrets and misconfigurations.

Naming Consistency5/5

The single tool uses a clear verb_noun pattern (scan_for_secrets), and there are no other tools to create inconsistency.

Tool Count4/5

The server has only one tool, which is slightly below the typical range, but the tool is comprehensive and handles a wide variety of inputs and detections, making the count reasonable.

Completeness5/5

The tool covers the full scope of the secret scanner domain, detecting a wide range of credentials and misconfigurations and returning findings. There are no obvious gaps for the stated purpose.

Resources