Back to Discover

secrets-le

connector

nolindnaidoo

Detect hardcoded secrets in source and config. Reports masked previews, never the values.

View on GitHub
0 starsSynced Aug 5, 2026

Install to Claude Code

/plugin marketplace add nolindnaidoo/secrets-le

README

Secrets-LE Logo

Secrets-LE: Zero Hassle Secret Detection

Find hardcoded credentials across your workspace, then redact them in place
API keys, tokens, passwords, private keys — 100% local, nothing leaves your machine

Install from VS Code Marketplace Open VSX downloads secrets-le-mcp on npm LE Tools


Secrets-LE Demo

Useful? A star or rating is how other developers find it — ★ GitHub · ★ Marketplace · ★ Open VSX

What it does

Open a workspace, press Ctrl+Alt+S (Cmd+Alt+S on Mac), and every detected secret lands in a results document — grouped by file, with line/column positions pointing at the value itself. Run Secrets-LE: Sanitize Secrets to replace the secrets in the active file with a placeholder. Works in VS Code and in VS Code–based editors like Cursor and VSCodium (installable from Open VSX).

Detection is regex-based over the full text of each file, so it works on any text format — code, configs, .env files, YAML, JSON, logs. It is a pre-commit safety net, not a guarantee: a scanner built on patterns can miss secrets and can flag non-secrets. Review the results.

Use it from an AI agent

The same engine runs as an MCP server, so an agent can call it directly instead of you running a command.

EditorHow
VS Code 1.101+Nothing to install — the extension registers detect_secrets with agent mode
ZedSecrets-LEpending review
Claude Codeclaude mcp add secrets-le -- npx -y secrets-le-mcp
Cursor, Windsurf, anything elsepoint it at npx secrets-le-mcp
detect_secrets(content, sensitivity?, includeApiKeys?, includePasswords?, includeTokens?, includePrivateKeys?, maxResults?)

Reports each finding by type, confidence, key name and 1-based position. Values are never returned — previews are truncated and length-annotated, and the context line has the secret masked out, so a finding can be located without the credential leaving the machine it was found on.

The server takes content and returns data — it reads no files and makes no network requests of its own. Published as secrets-le-mcp on npm and as io.github.nolindnaidoo/secrets-le in the MCP registry.

Configuring it by hand — any host with an MCP config file

Most hosts read a JSON config. Add one entry:

{
  "mcpServers": {
    "secrets-le": {
      "command": "npx",
      "args": ["-y", "secrets-le-mcp"]
    }
  }
}

-y skips the install prompt on first run. Pin a version if you would rather not track releases — secrets-le-mcp@2.2.1.

Prefer not to go through npx on every launch? Install it once and point at the binary instead:

npm install -g secrets-le-mcp
{
  "mcpServers": {
    "secrets-le": { "command": "secrets-le-mcp" }
  }
}

It speaks MCP over stdio and needs no environment variables, no API key and no configuration of its own. To check it before wiring it into anything:

echo '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | npx -y secrets-le-mcp

That prints the tool list and exits — if you see detect_secrets, the server works.

What gets detected

CategoryTypes
API keys & cloud credentialsGeneric API keys (api_key = …), AWS Access Key IDs (AKIA…, no key name needed), AWS Secret Access Keys, Azure account keys, GCP/Google Cloud keys
TokensGeneric tokens, bearer tokens, access/refresh tokens, OAuth tokens, JWTs (key-based or bare eyJ… form), known prefixes: GitHub ghp_/github_pat_, Slack xox?-, Stripe sk_live_/sk_test_, Google AIza…
Passwordspassword/passwd/pwd values, including compound keys (DATABASE_PASSWORD)
Private keysMulti-line PEM blocks — RSA/EC, OpenSSH, PGP
Connection dataDatabase URLs with embedded user:pass@ credentials, connection strings, session IDs, cookies

Key-based patterns accept quoted and unquoted keys, so JSON ("apiKey": "…"), YAML (api_key: …), env (API_KEY=…), and code (apiKey = '…') all match.

Intentional non-detections: template placeholders (${VAR}, {{var}}, <your-key>, xxxxxxxx), version numbers and hostnames that merely look dotted (1.2.3 is not a JWT), GCP project ids (identifiers, not credentials), and database URLs without embedded credentials.

Known limitations: detection is pattern-based — obfuscated, split, or unconventionally named secrets are missed; JWTs whose header isn't standard base64 JSON (eyJ…) are missed; a high-entropy string without a recognizable key name or prefix is not reported.

Commands

CommandDescription
Secrets-LE: Detect Secrets (Ctrl+Alt+S / Cmd+Alt+S)Scan the workspace and open a results document
Secrets-LE: Sanitize SecretsReplace detected secrets in the active file (asks for confirmation first)
Secrets-LE: Open SettingsOpen Secrets-LE settings
Secrets-LE: HelpBuilt-in documentation

Settings

SettingDefaultDescription
secrets-le.detection.sensitivitymediumlow reports everything, medium drops low-confidence matches, high keeps only high-confidence ones
secrets-le.detection.includeApiKeystrueDetect API keys and cloud credentials
secrets-le.detection.includePasswordstrueDetect passwords
secrets-le.detection.includeTokenstrueDetect tokens and JWTs
secrets-le.detection.includePrivateKeystrueDetect PEM private-key blocks
secrets-le.sanitization.replaceWith***REDACTED***Replacement text used by Sanitize
secrets-le.workspace.scanPatterns["**/*"]Glob patterns to scan
secrets-le.workspace.scanExcludesnode_modules, .git, dist, …Glob patterns to skip
secrets-le.workspace.scanMaxFiles10000Cap on files scanned per run
secrets-le.safety.enabledtrueGuardrails for very large files
secrets-le.safety.fileSizeWarnBytes1000000Skip/refuse files above this size
secrets-le.dedupeEnabledfalseCollapse identical value+type detections in results
secrets-le.copyToClipboardEnabledfalseAlso copy results to the clipboard
secrets-le.openResultsSideBySidetrueOpen results beside the current editor
secrets-le.notificationsLevelimportantall = every notification, important = warnings + errors, silent = errors only
secrets-le.statusBar.enabledtrueShow the status bar item
secrets-le.telemetryEnabledfalseLocal-only event log (see Privacy)

Languages

Twelve languages besides English:

German · Spanish · French · Indonesian · Italian · Japanese · Korean · Portuguese (Brazil) · Russian · Ukrainian · Vietnamese · Chinese (Simplified)

Both halves are covered — the manifest (command titles, setting names and descriptions) and everything shown while the extension runs (notifications, the status bar, quick-picks and prompts). The extension follows VS Code's display language, so it matches whatever the editor is already set to; no setting of its own.

Privacy & security

  • No network access. The extension never sends data anywhere. The telemetryEnabled setting only writes events to a local Output Channel you can inspect (Secrets-LE Telemetry).
  • The MCP server never returns a secret. Its output goes to whatever model called it, so previews are truncated and length-annotated and the surrounding context line is masked, using the same utils/mask helpers as the report. There is no argument that turns this off, and the bundle gate fails the build if a value ever appears in a response — verified by making the tool leak on purpose and watching the gate catch it.
  • Error notifications redact home directories and credential-shaped fragments before display.
  • Sanitize always asks for confirmation before editing your file, and edits are normal undo-able document edits.

Development

bun install
bun run build            # esbuild bundle -> dist/extension.js
bun run typecheck        # tsc --noEmit (includes tests)
bun run test             # vitest unit suite
bun run test:integration # real VS Code extension host
bun run lint             # biome
bun run package          # VSIX into release/

Architecture and conventions live in AGENTS.md. Changes are tracked in CHANGELOG.md.

Performance

InputSizeFoundTimeRateScan speed
Source with credentials1.97 MB40,000132.32 ms302,301/sec14.9 MB/s
Clean source1.92 MB070.88 ms27.2 MB/s
Env file0.60 MB021.88 ms27.4 MB/s

Median of 7 runs after warmup, on Apple M5 Pro, 24 GB RAM, Node 24.3.0. Inputs are generated by scripts/benchmark.ts rather than checked in, so the sizes above are exactly what was measured. Reproduce with bun run benchmark.

These are machine-specific and are not asserted in CI — a benchmark that gates a build only tells you how busy the runner was.

Testing

MetricCoverage
Statements90.78%
Branches79.45%
Functions95.37%
Lines91.81%

142 test cases across 13 files, plus an integration suite that runs in a real VS Code extension host and an end-to-end test that installs the built .vsix into a clean profile.

Generated from coverage/coverage-summary.json by scripts/coverage-readme.js; CI fails if this section drifts from a fresh run. Reproduce with bun run test:coverage.

More from the LE Family

Every tool in the family, one page: letools.dev

All ten also ship as MCP servers — npx <name>-mcp gives any agent the same engine.

  • String-LE - Extract string values for i18n from JSON, YAML, CSV, TOML, INI, and .env
  • Numbers-LE - Extract numeric values from JSON, YAML, CSV, TOML, INI, and .env
  • EnvSync-LE - Spot missing keys across your .env files, with a markdown report
  • Paths-LE - Extract file paths from JS/TS imports, JSON, HTML, CSS, TOML, CSV, and .env
  • Regex-LE - Find, test, and validate regular expressions with ReDoS screening
  • Scrape-LE - Check whether a page is scrapeable before you write the scraper
  • Colors-LE - Extract and analyze colors from CSS, SCSS, LESS, Stylus, HTML, JS/TS, and SVG
  • URLs-LE - Extract URLs from documentation, configs, and code
  • Dates-LE - Extract and analyze dates from logs, configs, and code

Also by nolindnaidoo

Rust

Contact DeveloperGitHub · LinkedIn

License

MIT © nolindnaidoo

Rendered live from nolindnaidoo/secrets-le's GitHub README — not stored, always reflects the source repo.

1 Install Method

NameDescriptionCategorySource
npm packageInstall via npm (stdio transport)mcp-serversecrets-le-mcp

0 Comments

Login required
Log in to post a comment or update on this repo.

No comments yet — be the first to share an update.