{
  "markdown": "<p align=\"center\">\n  <img src=\"src/assets/images/icon.png\" alt=\"Secrets-LE Logo\" width=\"96\" height=\"96\"/>\n</p>\n<h1 align=\"center\">Secrets-LE: Zero Hassle Secret Detection</h1>\n<p align=\"center\">\n  <b>Find hardcoded credentials across your workspace, then redact them in place</b><br/>\n  <i>API keys, tokens, passwords, private keys — 100% local, nothing leaves your machine</i>\n</p>\n\n<p align=\"center\">\n  <a href=\"https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.secrets-le\">\n    <img src=\"https://img.shields.io/badge/Install%20from-VS%20Code-blue?style=for-the-badge&logo=visualstudiocode\" alt=\"Install from VS Code Marketplace\" />\n  </a>\n  <a href=\"https://open-vsx.org/extension/OffensiveEdge/secrets-le\">\n    <img src=\"https://img.shields.io/open-vsx/dt/OffensiveEdge/secrets-le?style=for-the-badge&label=Open%20VSX&color=blue\" alt=\"Open VSX downloads\" />\n  </a>\n  <a href=\"https://www.npmjs.com/package/secrets-le-mcp\">\n    <img src=\"https://img.shields.io/npm/v/secrets-le-mcp?style=for-the-badge&label=MCP%20server&color=blue&logo=npm\" alt=\"secrets-le-mcp on npm\" />\n  </a>\n  <a href=\"https://crates.io/crates/secrets-le\">\n    <img src=\"https://img.shields.io/crates/v/secrets-le?style=for-the-badge&label=Rust%20CLI&color=blue&logo=rust\" alt=\"secrets-le on crates.io\" />\n  </a>\n  <a href=\"https://letools.dev/tools/secrets-le\">\n    <img src=\"https://img.shields.io/badge/LE%20Tools-letools.dev-blue?style=for-the-badge\" alt=\"LE Tools\" />\n  </a>\n</p>\n\n---\n\n<p align=\"center\">\n  <img src=\"src/assets/images/demo.gif\" alt=\"Secrets-LE Demo\" style=\"max-width: 100%; height: auto;\" />\n</p>\n\n> **Useful?** A star or rating is how other developers find it —\n> [★ GitHub](https://github.com/nolindnaidoo/secrets-le) ·\n> [★ Open VSX](https://open-vsx.org/extension/OffensiveEdge/secrets-le/reviews) ·\n> [★ Marketplace](https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.secrets-le&ssr=false#review-details)\n\n## What it does\n\nOpen a workspace, press `Ctrl+Alt+S` (`Cmd+Alt+S` on Mac), and every detected secret lands in a results document — grouped by file, with line/column positions pointing at the value itself. Run `Secrets-LE: Sanitize Secrets` to replace the secrets in the active file with a placeholder. Works in VS Code and in VS Code–based editors like Cursor and VSCodium (installable from Open VSX).\n\nDetection is regex-based over the full text of each file, so it works on any text format — code, configs, `.env` files, YAML, JSON, logs. It is a pre-commit safety net, not a guarantee: a scanner built on patterns can miss secrets and can flag non-secrets. Review the results.\n\n## Install\n\n| Where | What you get | Install |\n|---|---|---|\n| **VS Code** | Detection and in-place sanitising, in your editor | [Marketplace](https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.secrets-le) |\n| **Cursor, VSCodium, Windsurf** | The same extension | [Open VSX](https://open-vsx.org/extension/OffensiveEdge/secrets-le) |\n| **A terminal or a CI step** | The same run over a whole tree, with exit codes | `cargo install secrets-le` · [crates.io](https://crates.io/crates/secrets-le) |\n| **Any MCP agent, via Node** | `detect_secrets` over stdio | `npx secrets-le-mcp` · [npm](https://www.npmjs.com/package/secrets-le-mcp) |\n| **Zed** | The MCP server as a context server | [add it by hand](https://zed.dev/docs/ai/mcp) *(no listing yet)* |\n\n## Use it from an AI agent\n\nThe same engine runs as an [MCP](https://modelcontextprotocol.io) server, so an agent can call it directly instead of you running a command.\n\n| Editor | How |\n|---|---|\n| **VS Code** 1.101+ | Nothing to install — the extension registers `detect_secrets` with agent mode |\n| **Zed** | No listing yet — [add the MCP server by hand](https://zed.dev/docs/ai/mcp) |\n| **Claude Code** | `claude mcp add secrets-le -- npx -y secrets-le-mcp` |\n| **Cursor, Windsurf, anything else** | point it at `npx secrets-le-mcp` |\n\n```\ndetect_secrets(content, sensitivity?, includeApiKeys?, includePasswords?, includeTokens?, includePrivateKeys?, maxResults?)\n```\n\nReports each finding by type, confidence, key name and 1-based position. **Values are never returned** — previews are truncated and length-annotated, and the context line has the secret masked out, so a finding can be located without the credential leaving the machine it was found on.\n\nThe server takes content and returns data — it reads no files and makes no network requests of its own. Published as [`secrets-le-mcp`](https://www.npmjs.com/package/secrets-le-mcp) on npm and as `io.github.nolindnaidoo/secrets-le` in the [MCP registry](https://registry.modelcontextprotocol.io).\n\n<details>\n<summary><b>Configuring it by hand</b> — any host with an MCP config file</summary>\n\nMost hosts read a JSON config. Add one entry:\n\n```json\n{\n  \"mcpServers\": {\n    \"secrets-le\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"secrets-le-mcp\"]\n    }\n  }\n}\n```\n\n`-y` skips the install prompt on first run. Pin a version if you would rather not track releases — `secrets-le-mcp@2.3.1`.\n\nPrefer not to go through `npx` on every launch? Install it once and point at the binary instead:\n\n```bash\nnpm install -g secrets-le-mcp\n```\n\n```json\n{\n  \"mcpServers\": {\n    \"secrets-le\": { \"command\": \"secrets-le-mcp\" }\n  }\n}\n```\n\nIt speaks MCP over stdio and needs no environment variables, no API key and no configuration of its own. To check it before wiring it into anything:\n\n```bash\necho '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"tools/list\"}' | npx -y secrets-le-mcp\n```\n\nThat prints the tool list and exits — if you see `detect_secrets`, the server works.\n\n</details>\n\n## The CLI\n\nThe same detection runs from a terminal or a CI step: a Rust CLI in\n[`crate/`](crate/README.md), sharing one pattern table with the extension\n— [`crate/signatures/patterns.toml`](crate/signatures/patterns.toml) —\nso the two can never disagree about what counts as a credential.\n\n```bash\nsecrets-le .                        # scan a tree\nsecrets-le --sensitivity high .     # only high-confidence findings\nsecrets-le --no-ignore --hidden .   # reach .env and everything git ignores\nsecrets-le mcp                      # the same detection over MCP on stdio\n```\n\nThe exit code is the answer: **0 nothing found · 1 findings · 2 the\nquestion was malformed** — so `secrets-le .` is a CI step as it stands.\n\n**It never prints a credential.** A scanner's output goes into a CI log,\nwhich is archived, often world-readable, and outlives the secret; a\nscanner that printed what it found would disclose it more widely than\nthe commit would have. Previews are capped at eight characters *and* at\nhalf the value's length, context lines are masked, and there is no flag\nthat changes either. The extension is the half that can *fix* what it\nfinds; the binary only reports.\n\n## What gets detected\n\nThirty-four patterns, in `crate/signatures/patterns.toml` — the one table\nboth frontends load.\n\n| Category | Types |\n|---|---|\n| Named issuers | Anthropic `sk-ant-`, OpenAI `sk-`/`sk-proj-`, GitHub `ghp_`/`github_pat_`, GitLab, Slack `xox?-`, Stripe `sk_live_`/`sk_test_`, Google `AIza…`, SendGrid, Mailgun, Sentry, npm, PyPI, Docker Hub, HashiCorp Vault, Terraform Cloud, Supabase, Shopify, Square, Azure SAS |\n| Cloud credentials | AWS Access Key IDs (`AKIA…`, no key name needed), AWS Secret Access Keys, Azure account keys, GCP/Google Cloud keys |\n| Tokens | Generic tokens, bearer tokens, access/refresh tokens, OAuth tokens, JWTs (key-based or bare `eyJ…` form) |\n| Passwords | `password`/`passwd`/`pwd` values, including compound keys (`DATABASE_PASSWORD`) |\n| Private keys | Multi-line PEM blocks — RSA/EC, OpenSSH, PGP |\n| Connection data | Database URLs with embedded `user:pass@` credentials, connection strings, session IDs, cookies |\n\nKey-based patterns accept quoted and unquoted keys, so JSON (`\"apiKey\": \"…\"`), YAML (`api_key: …`), env (`API_KEY=…`), and code (`apiKey = '…'`) all match.\n\n**Intentional non-detections**: template placeholders (`${VAR}`, `{{var}}`, `<your-key>`, `xxxxxxxx`), version numbers and hostnames that merely look dotted (`1.2.3` is not a JWT), GCP project ids (identifiers, not credentials), and database URLs without embedded credentials.\n\n**Known limitations**: detection is pattern-based — obfuscated, split, or unconventionally named secrets are missed; JWTs whose header isn't standard base64 JSON (`eyJ…`) are missed; a high-entropy string without a recognizable key name or prefix is not reported.\n\n## Commands\n\n| Command | Description |\n|---|---|\n| `Secrets-LE: Detect Secrets` (`Ctrl+Alt+S` / `Cmd+Alt+S`) | Scan the workspace and open a results document |\n| `Secrets-LE: Sanitize Secrets` | Replace detected secrets in the active file (asks for confirmation first) |\n| `Secrets-LE: Open Settings` | Open Secrets-LE settings |\n| `Secrets-LE: Help` | Built-in documentation |\n\n## Settings\n\n| Setting | Default | Description |\n|---|---|---|\n| `secrets-le.detection.sensitivity` | `medium` | `low` reports everything, `medium` drops low-confidence matches, `high` keeps only high-confidence ones |\n| `secrets-le.detection.includeApiKeys` | `true` | Detect API keys and cloud credentials |\n| `secrets-le.detection.includePasswords` | `true` | Detect passwords |\n| `secrets-le.detection.includeTokens` | `true` | Detect tokens and JWTs |\n| `secrets-le.detection.includePrivateKeys` | `true` | Detect PEM private-key blocks |\n| `secrets-le.sanitization.replaceWith` | `***REDACTED***` | Replacement text used by Sanitize |\n| `secrets-le.workspace.scanPatterns` | `[\"**/*\"]` | Glob patterns to scan |\n| `secrets-le.workspace.scanExcludes` | node_modules, .git, dist, … | Glob patterns to skip |\n| `secrets-le.workspace.scanMaxFiles` | `10000` | Cap on files scanned per run |\n| `secrets-le.safety.enabled` | `true` | Guardrails for very large files |\n| `secrets-le.safety.fileSizeWarnBytes` | `1000000` | Skip/refuse files above this size |\n| `secrets-le.dedupeEnabled` | `false` | Collapse identical value+type detections in results |\n| `secrets-le.copyToClipboardEnabled` | `false` | Also copy results to the clipboard |\n| `secrets-le.openResultsSideBySide` | `true` | Open results beside the current editor |\n| `secrets-le.notificationsLevel` | `important` | `all` = every notification, `important` = warnings + errors, `silent` = errors only |\n| `secrets-le.statusBar.enabled` | `true` | Show the status bar item |\n| `secrets-le.telemetryEnabled` | `false` | Local-only event log (see Privacy) |\n\n## Languages\n\nTwelve languages besides English:\n\nGerman · Spanish · French · Indonesian · Italian · Japanese · Korean ·\nPortuguese (Brazil) · Russian · Ukrainian · Vietnamese · Chinese (Simplified)\n\nBoth halves are covered — the manifest (command titles, setting names and\ndescriptions) and everything shown while the extension runs (notifications,\nthe status bar, quick-picks and prompts). The extension follows VS Code's\ndisplay language, so it matches whatever the editor is already set to; no\nsetting of its own.\n\n## Privacy & security\n\n- **No network access.** The extension never sends data anywhere. The `telemetryEnabled` setting only writes events to a local Output Channel you can inspect (`Secrets-LE Telemetry`).\n- **The MCP server never returns a secret.** Its output goes to whatever model called it, so previews are truncated and length-annotated and the surrounding context line is masked, using the same `utils/mask` helpers as the report. There is no argument that turns this off, and the bundle gate fails the build if a value ever appears in a response — verified by making the tool leak on purpose and watching the gate catch it.\n- Error notifications redact home directories and credential-shaped fragments before display.\n- Sanitize always asks for confirmation before editing your file, and edits are normal undo-able document edits.\n\n## Documentation\n\n| What | Where |\n|---|---|\n| What the tool is allowed to say — scope, output contract, refusals, non-goals | [`crate/SPEC.md`](crate/SPEC.md) |\n| How the extension is built and held together — architecture, invariants, toolchain, release | [AGENTS.md](AGENTS.md) |\n| How the CLI is built and held together | [`crate/AGENTS.md`](crate/AGENTS.md) |\n| What changed | [CHANGELOG.md](CHANGELOG.md) · [`crate/CHANGELOG.md`](crate/CHANGELOG.md) |\n| The tool's page, and the other fifteen | [letools.dev/tools/secrets-le](https://letools.dev/tools/secrets-le) |\n\n## Performance\n\n<!-- performance:start -->\n| Input | Size | Found | Time | Rate | Scan speed |\n| --- | --- | --- | --- | --- | --- |\n| Source with credentials | 1.97 MB | 40,000 | 132.32 ms | 302,301/sec | 14.9 MB/s |\n| Clean source | 1.92 MB | 0 | 70.88 ms | — | 27.2 MB/s |\n| Env file | 0.60 MB | 0 | 21.88 ms | — | 27.4 MB/s |\n\nMedian of 7 runs after warmup, on Apple M5 Pro, 24 GB RAM, Node 24.3.0. Inputs are generated\nby `scripts/benchmark.ts` rather than checked in, so the sizes above are\nexactly what was measured. Reproduce with `bun run benchmark`.\n\nThese are machine-specific and are not asserted in CI — a benchmark that gates\na build only tells you how busy the runner was.\n<!-- performance:end -->\n\n## Testing\n\n<!-- coverage:start -->\n| Metric | Coverage |\n| --- | --- |\n| Statements | 91.03% |\n| Branches | 79.75% |\n| Functions | 95.90% |\n| Lines | 91.89% |\n\n248 test cases across 15 files, plus an integration suite that runs\nin a real VS Code extension host and an end-to-end test that installs the\nbuilt `.vsix` into a clean profile.\n\nGenerated from a real run — `coverage/coverage-summary.json` and\n`coverage/test-results.json` — by `scripts/coverage-readme.js`; CI fails if\nthis section drifts. Reproduce with `bun run test:coverage`, and the case\ncount is the one vitest prints.\n<!-- coverage:end -->\n\n## More from the LE family\n\nSixteen single-purpose tools for the work in front of every model. Each ships\na Rust CLI and an MCP server. One page: **[letools.dev](https://letools.dev)**\n\n**Get it out**\n\n- **[String-LE](https://letools.dev/tools/string-le)** — Extract every string in a codebase, with its position, so a person can read them\n- **[Numbers-LE](https://letools.dev/tools/numbers-le)** — Extract every hardcoded number in a codebase, so a person can check them\n- **[Units-LE](https://letools.dev/tools/units-le)** — Extract every quantity with its unit, normalized, and refuse the ambiguous ones by name\n- **[Dates-LE](https://letools.dev/tools/dates-le)** — Extract every date and timestamp, and the exact instant each one resolves to\n- **[IDs-LE](https://letools.dev/tools/ids-le)** — Extract every UUID, ULID, NanoID, ObjectId and Snowflake, and decode the time inside\n- **[IPs-LE](https://letools.dev/tools/ips-le)** — Extract every IP address, CIDR block and MAC, normalized and classified by scope\n- **[URLs-LE](https://letools.dev/tools/urls-le)** — Extract every URL in a codebase, with its protocol and exact position\n- **[Paths-LE](https://letools.dev/tools/paths-le)** — Extract every file path in a codebase, and say whether it still points at anything\n- **[Colors-LE](https://letools.dev/tools/colors-le)** — Extract every color in a codebase, and say which ones are not in your palette\n\n**Check it**\n\n- **[Regex-LE](https://letools.dev/tools/regex-le)** — Find every regex in a codebase, and report which can be driven into catastrophic backtracking\n- **[Versions-LE](https://letools.dev/tools/versions-le)** — Find where one dependency is constrained differently across a repository's manifests\n- **[i18n-LE](https://letools.dev/tools/i18n-le)** — Identify the i18n library a project uses, then audit its catalogs by that library's rules\n- **[Scrape-LE](https://letools.dev/tools/scrape-le)** — Check whether a page is scrapeable before the scraper is written, and say when it cannot tell\n\n**Guard it**\n\n- **[Secrets-LE](https://letools.dev/tools/secrets-le)** — Find hardcoded credentials in a codebase, and never print one into the report\n- **[EnvSync-LE](https://letools.dev/tools/envsync-le)** — Compare the dotenv files in a tree, and say which keys are missing from which\n- **[Unicode-LE](https://letools.dev/tools/unicode-le)** — Find the Unicode that hides meaning — bidi controls, invisibles, homoglyphs, mixed scripts\n\nEach stands on its own: no shared crate, no published core. Where two of them\nagree, it is because the same answer was right twice.\n\n**Contact** — [nolindnaidoo.com](https://nolindnaidoo.com) · [GitHub](https://github.com/nolindnaidoo) · [LinkedIn](https://www.linkedin.com/in/nolindnaidoo/)\n\n## Also by nolindnaidoo\n\n**Rust** — pixelcoords and pixelactions are one loop: pixelcoords answers\n*where*, pixelactions *acts* there. Their own tools, their own voice — not\npart of the LE family.\n\n- **[pixelcoords](https://github.com/nolindnaidoo/pixelcoords)** — Freeze your screen, mark regions, get pixel-exact coordinates and crops\n  [pixelcoords.dev](https://pixelcoords.dev) · [crates.io](https://crates.io/crates/pixelcoords) · [docs.rs](https://docs.rs/pixelcoords)\n- **[pixelactions](https://github.com/nolindnaidoo/pixelactions)** — Consume human-verified coordinates, perform the interaction, confirm it landed\n  [pixelactions.dev](https://pixelactions.dev) · [crates.io](https://crates.io/crates/pixelactions) · [docs.rs](https://docs.rs/pixelactions)\n\n## License\n\nMIT © [nolindnaidoo](https://github.com/nolindnaidoo)\n",
  "bytes": 17282,
  "sha": "62df1ab502aa96b3d8df191d920bab738059fbb85a69d95aa65ffebacd29197d",
  "repo_slug": "nolindnaidoo/secrets-le",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_nolindnaidoo_secrets_le_3a07fb3c/readme"
}