JSPM

Found 45 results for secret-detection

vibe-hardening

One-command security scanner for AI-generated code. Vibe coded. Vibe hardened.

  • v0.4.0
  • 56.71
  • Published

guardvibe

Security MCP for vibe coding. 424 rules, 36 tools, CLI + doctor. Host security, auth coverage mapping, LLM-powered deep scan (IDOR/business logic), taint analysis. 61 CVE rules refreshed daily from GHSA/OSV/CISA KEV โ€” Next.js May 2026 13-advisory cluster,

  • v3.1.25
  • 56.50
  • Published

detect-secrets-js

A JavaScript implementation of Yelp's detect-secrets tool - no Python required

  • v2.2.1
  • 48.24
  • Published

@ziul285/gitleaks

A custom Gitleaks-like scanner for detecting sensitive data.

  • v1.0.0
  • 46.70
  • Published

modality-safe

Advanced security scanner that detects API key leaks and sensitive information in source code. Scans TypeScript, JavaScript, Markdown, and configuration files for AWS keys, OpenAI tokens, GitHub/GitLab PATs, Slack/Discord tokens, JWT tokens, and other cre

  • v0.4.1
  • 38.91
  • Published

agent-security-mcp

MCP server providing security scanning, prompt injection detection, secret leak detection, and agent permission auditing for AI agent workflows

  • v0.1.3
  • 38.61
  • Published

fulcrum-policy

Policy engine โ€” system invariants, custom rule evaluation, secret guard (detect and redact), and audit logging

  • v0.0.3
  • 37.37
  • Published

pi-secret-guard

A pi extension that guards against committing secrets, API keys, and credentials to git repositories using hybrid regex + LLM review.

  • v1.2.15
  • 37.06
  • Published

@paretools/security

MCP server for security scanning โ€” structured Trivy, Semgrep, and Gitleaks findings for AI agents

  • v0.19.1
  • 36.22
  • Published

mcp-scan

Open-source security scanner for Model Context Protocol (MCP) servers. Audits Claude Desktop, VS Code, Cursor, Windsurf, and 16+ AI tools for secrets, prompt injection, supply-chain risks, and 17+ security checks.

  • v2.0.2
  • 35.39
  • Published

devibe

Intelligent repository cleanup with auto mode, AI learning, markdown consolidation, auto-consolidate workflow, context-aware classification, and cost optimization

  • v3.1.1
  • 32.30
  • Published

logshield-cli

Deterministic, rule-based CLI to sanitize secrets from logs. No AI. No cloud. No config.

  • v0.7.1
  • 31.72
  • Published

ai-scanner

CLI tool to scan codebases for LLM SDK usage, AI frameworks, and exposed API tokens

  • v1.1.0
  • 31.31
  • Published

cerber-core

Prevent secrets (API keys, passwords) and console.log in commits. Zero-config pre-commit hooks with Husky auto-install. Blocks Stripe, GitHub, AWS credentials out-of-the-box. 357+ teams protected.

  • v1.1.12
  • 29.10
  • Published

secure-scan-js

A JavaScript implementation of Yelp's detect-secrets tool - no Python required

  • v1.0.27
  • 27.69
  • Published

xswarm-ai-sanitize

Secret detection for AI agents โ€” 600+ patterns, plugins for LangChain, LlamaIndex, Vercel AI, OpenClaw, Nanobot

  • v2.0.0
  • 27.46
  • Published

aiagentshield

Security scanner for AI Agents and MCP Servers โ€” 10 scanners for prompt injection, supply chain poisoning, secret leaks, and misconfigs

  • v0.8.1
  • 27.36
  • Published

@fronik/envman

A security-first CLI for environment variable management with AES-256 encryption, secret scanning, health diagnostics, auto-backups, and safe sync.

  • v3.0.1
  • 27.13
  • Published

@rich-apis/vibe-tools

CLI toolkit for the stuff you keep re-doing. Env validation, JSON-to-TypeScript, changelogs, depcheck, gitignore, ESLint + Prettier config, test setup, Dockerfile, CI workflow, README scaffold, git hooks, editorconfig, secret scanning, API scaffolding, de

  • v2.11.0
  • 26.68
  • Published

agent-hush

๐Ÿคซ Silent privacy guardian for agent workspaces. Auto-detects API keys, tokens, PII, and infrastructure info before git push or skill publish.

  • v1.2.1
  • 26.32
  • Published

cto-ai-cli

AI context selection done right. Picks the right files, sanitizes secrets, learns from your feedback. --context, --audit, --accept/--reject.

  • v8.1.0
  • 26.02
  • Published

@diego007/security-scanner

Standalone npm package for comprehensive secret detection with 100+ patterns, entropy filtering, and false positive detection - no external dependencies required. Based on TruffleHog detection logic.

    • v1.0.14
    • 25.88
    • Published

    @mcp-guard/core

    Security scanning engine for Model Context Protocol (MCP) servers. Detects hardcoded secrets, command injection, SSRF, auth misconfig, and compliance gaps.

    • v2.1.0
    • 25.68
    • Published

    mcp-fence

    The bidirectional firewall for MCP โ€” scans inputs AND outputs, detects rug-pulls at runtime, zero config.

    • v1.0.2
    • 25.39
    • Published

    @mcp-guard/cli

    Command-line interface for mcp-guard: scan, fix, and monitor Model Context Protocol (MCP) server configs for security issues.

    • v1.1.0
    • 24.93
    • Published

    @nexylore/sentori

    AI Agent Security Scanner โ€” ๅฎˆใ‚‹ในใใ‚‚ใฎใ‚’ใ€ๅฎˆใ‚‹ใ€‚MCP-focused security for the agentic era.

    • v0.11.2
    • 24.70
    • Published

    @gitconductor/core

    Core rule engine, git layer, AI providers, and interceptor for gitconductor

    • v0.1.5
    • 23.49
    • Published

    @gitconductor/cli

    CLI for gitconductor โ€” intercept git commands, enforce safety rules, and recover from mistakes

    • v0.1.5
    • 22.87
    • Published

    mcp-security-agent

    An MCP-based security scanner and agentic AI for vulnerability detection

    • v0.1.0
    • 21.45
    • Published

    ultraenv

    The Ultimate Environment Variable Manager โ€” Validate, Type, Encrypt, Sync, and Never Ship Broken Configs Again

    • v1.0.5
    • 21.38
    • Published

    leak-secure-mcp

    MCP server for Leak Secure - Enterprise GitHub security scanner detecting 35+ types of secrets

    • v1.0.0
    • 20.25
    • Published

    avanasec

    A robust, production-ready CLI tool for detecting secrets and credentials in your codebase

    • v1.0.6
    • 17.65
    • Published

    @andrewlabs/openclaw-messageguard

    OpenClaw plugin: filters outgoing messages for API keys, credentials, PII, and other sensitive data using MessageGuard.

    • v1.0.0
    • 17.02
    • Published

    leak-proof

    Zero-config Git pre-commit hook that blocks secrets (AWS keys, API tokens, .env files) from being committed. Auto-installs for your entire team.

    • v1.1.0
    • 16.94
    • Published

    codeguard-mcp

    Real-time AI code security scanner - MCP Server for detecting vulnerabilities, secrets, and compliance issues

      • v1.0.1
      • 16.76
      • Published

      scannad

      A CLI tool that scans git diffs for API keys and secrets before commits

      • v1.0.2
      • 16.14
      • Published

      secret-guardian-ts

      Plug-and-play pre-commit & pre-push secret scanner that blocks secrets (TypeScript compatible).

      • v1.0.2
      • 15.35
      • Published

      securelog-rsc

      Secure Log React Server Component for Scanning secrets.

      • v1.0.2
      • 15.25
      • Published

      @ravichy9708/secret-scan-cli

      ๐Ÿ” AI-powered CLI tool to scan files and repositories for exposed secrets and credentials

      • v1.0.1
      • 14.90
      • Published

      secretscout

      Rust-powered secret detection for GitHub Actions - Fast, safe, and efficient CLI tool

      • v3.1.0
      • 14.45
      • Published

      react-native-lupin

      Fast, beautiful CLI security scanner for React Native and Expo bundles. Detects API keys, secrets, and 60+ mobile security vulnerabilities.

      • v1.3.0
      • 12.23
      • Published

      secretshield

      ๐Ÿ›ก๏ธ SecretShield is a CLI tool that detects API keys and sensitive credentials before you commit code.

        • v1.1.0
        • 11.09
        • Published

        kafkacode

        AI-powered privacy and compliance scanner by KafkaLabs - identify PII leaks, secrets, and compliance violations

        • v1.2.0
        • 10.91
        • Published

        @lazymac/project-health-scanner

        Premium MCP server that scans projects for dependency issues, secrets, license conflicts, code quality problems, and git health. Returns a 0-100 health score with actionable fix suggestions.

        • v1.0.0
        • 0.00
        • Published