Skip to main content

Browse the directory

Showing 19 resources for "secrets"
Saved
Active

Source-backed filter active — add entries to compare trust side by side.

Trust snapshot

19 results in this view

Claimed
0%(0/19)

2 trust signals differ in this sample: Source provenance, Submitter

Signals differ on Source provenance, Submitter — add entries to compare before you install.

Rollout signal scan

2 rollout risk signals in current results

Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.

12 scanned

Install payload

Install payload is broadly covered in current results.

good

100% (12/12)

Adoption queue

Browse adoption queue · balanced

2/19 visible results are in hold tier and need mitigation before adoption.

ready 0caution 17hold 2
caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

agents/cloudflare-workers-deployment-review-agent · trust review · confidence 67%

Dagu MCP Server

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

mcp/dagu-mcp-server · trust review · confidence 67%

Docker MCP Gateway

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

mcp/docker-mcp-gateway · trust review · confidence 67%

Fly.io MCP Server for Claude

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

mcp/fly-io-mcp-server · trust review · confidence 67%

git-secrets Environment Risk Statusline

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

statuslines/git-secrets-env-risk-statusline · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

skills/github-actions-security-review-capability-pack · trust review · confidence 67%

Hardcoded Secret Pre-Write Guard Hook

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/environment-variable-leak-warning-hook · trust review · confidence 67%

Decision confidence

Decision confidence scan · balanced

2/19 results are low-confidence and need review before adoption.

high 0medium 17low 2

Cloudflare Workers Deployment Review Agent

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

agents/cloudflare-workers-deployment-review-agent · trust review

Dagu MCP Server

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

mcp/dagu-mcp-server · trust review

Docker MCP Gateway

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

mcp/docker-mcp-gateway · trust review

Fly.io MCP Server for Claude

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

mcp/fly-io-mcp-server · trust review

git-secrets Environment Risk Statusline

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

statuslines/git-secrets-env-risk-statusline · trust review

Hardcoded Secret Pre-Write Guard Hook

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

hooks/environment-variable-leak-warning-hook · trust review

Freshness distribution

Current results are broadly fresh

Median age 48 days; all 12 scanned entries are within 90 days.

median 48d

Aging

91–180 days

0%

0 entries

Stale

> 180 days

0%

0 entries

Theme distribution

Results center on security

63% of this view shares the top theme. Leading themes: security, secrets, devops.

Focused

61 distinct themes across 19 scanned

Infisical MCP Server logo

The official Infisical MCP server (@infisical/mcp) that lets AI assistants work with Infisical's secrets-management API through function calling — reading, creating, updating, and deleting secrets, and managing projects, environments, folders, and project members — authenticating with a Machine Identity (universal auth) or an access token against Infisical Cloud or a self-hosted instance.

Manage Fly.io applications, machines, volumes, secrets, certificates, and organizations from Claude — with the official Fly.io MCP server built into the flyctl CLI.

Connect Claude to HashiCorp Vault — manage secrets engines, read and write KV secrets, and operate the PKI engine — with HashiCorp's official Model Context Protocol server.

GitHub logo

Expert GitHub Actions security review capability pack applying documented workflow hardening, GITHUB_TOKEN least privilege, secrets handling, and fork PR safety checks from official GitHub Actions security documentation.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓
Cloudflare logo

Source-backed agent for reviewing Cloudflare Workers deployments before production release, covering wrangler config, bindings, routes, secrets, compatibility flags, and rollback plans aligned to official Cloudflare docs.

Slash command that reviews a pull request diff for security regressions: authentication and authorization gaps, injection surfaces, secret exposure, unsafe deserialization, and dependency risk introduced by the change.

Invocation:/pr-security-review [pr-number]
Safety ✓ Privacy ✓
Dagu logo

Built-in Streamable HTTP MCP server for Dagu that lets AI agents read workflow state, inspect DAG specs and logs, preview or apply workflow changes, and start, enqueue, retry, or stop DAG runs.

Docker MCP Gateway logo

Docker's MCP CLI plugin and gateway for running catalog, OCI, registry, or local-file MCP servers in containers and exposing them to Claude, Cursor, VS Code, and other MCP clients through a shared gateway profile.

MCP server that lets Claude install other MCP servers into Claude Desktop by writing MCP config entries for npm packages, uvx packages, or locally cloned Node-based MCP server projects.

PreToolUse hook that reviews proposed writes to MCP configuration files and blocks inline credential values, credential-bearing URLs, and broad filesystem roots before they are saved.

Trigger:PreToolUse
Safety ✓ Privacy ✓
ToolHive logo

Open-source MCP platform for running MCP servers in isolated containers, managing registries, enforcing access policy, and operating local or Kubernetes-based MCP infrastructure.

Claude Code statusline that surfaces sensitive environment-file risk and can optionally run git-secrets as a local pre-commit-style scanner.

PreToolUse hook that scans the exact text Claude Code is about to write or edit for high-confidence secret formats (AWS access keys, GitHub tokens, OpenAI keys, Slack tokens, Google API keys, Stripe keys, and private key blocks) and blocks the write with a non-zero exit before the secret ever reaches disk.

Trigger:PreToolUse
Safety ✓ Privacy ✓
Semgrep logo
Semgrepby Semgrep · submitted by oktofeesh1

Static analysis platform and open-source CLI for finding bugs, security issues, secrets, dependency risk, and custom rule matches in code.

PreToolUse Write and Edit guardrail combining the hooks guide protected-file pattern with a local scan for common hardcoded credential shapes called out by GitHub secret scanning guidance before content is written.

Trigger:PreToolUse
Safety ✓ Privacy ✓
Gitleaks logo
Gitleaksby Gitleaks · submitted by oktofeesh1

Open-source secret scanner for finding passwords, API keys, tokens, and other credentials in git history, files, directories, and stdin.

Security scanner from Snyk for discovering local AI agent components, including MCP servers and Agent Skills, and checking them for prompt injection, tool poisoning, tool shadowing, toxic flows, malware payloads, credential handling, and hardcoded secrets.

Expert MCP client config audit capability pack for reviewing Claude Code MCP server entries, scope placement, tool approval settings, env var secrets, and startup context load before enabling servers in production repositories.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

Source-backed Claude agent prompt for contributing to the official vercel/next.js monorepo using its AGENTS.md guidance, pnpm workspace commands, package-filtered builds, Turbopack and Rust boundaries, mode-specific tests, PR triage rules, and secrets-safety notes.