scan_for_secrets
3 registry entries were observed exposing a tool named scan_for_secrets — none of them flagged as a privileged capability.
Every row is point-in-time scan output, dated below. Forge has an observed tool surface for 8,470 of 26,658 scannable entries (32%) — an entry that has not been scanned cannot appear here, so absence from this list is not evidence that an entry does not expose this tool.
- MCP serverobserved · static extractionScans code for hardcoded secrets (AWS, Stripe, GitHub, JWTs) before an AI agent commits it.
- MCP serverobserved · static extractionScans projects for secret exposure: leaked API keys, unprotected .env files, and secrets in logs.
- MCP serverobserved · static extractionScan a blob of code/text/diff for LEAKED SECRETS before you commit or share — API keys (AWS, GitHub, OpenAI, Stripe, Google, Slack…), tokens