Scans projects for secret exposure: leaked API keys, unprotected .env files, and secrets in logs.
Your AI agent is one debug session away from leaking your secrets. MCP server that scans your project for secret exposure risks — hardcoded API keys, unprotected files, and calls that print credentials at runtime. Before your agent accidentally reads them out loud. You ask your AI agent to debug a config issue. It reads . Inside: The agent now has your database password in its context. It might…
Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.
Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.
Forge hat zu diesem Eintrag keinen Scan verzeichnet und hat daher keine Beobachtung seiner Tool-Oberfläche. Das ist das Fehlen eines Belegs, nicht der Beleg, dass er keine Tools offenlegt.
Your AI agent is one debug session away from leaking your secrets. MCP server that scans your project for secret exposure risks — hardcoded API keys, unprotected files, and calls that print credentials at runtime. Before your agent accidentally reads them out loud. You ask your AI agent to debug a config issue. It reads . Inside: The agent now has your database password in its context. It might log it, include it in a summary, or pass it to another tool. And your isn't in , so the next will do…