19,482 packages matching “hardcoded secrets”
vibe-audit-security
v0.1.0 · 2 months ago
Security scanner for vibe-coded projects: local CLI and MCP server that catch the security mistakes an AI coding assistant can silently introduce (hardcoded secrets, disabled RLS, open CORS, missing security headers) before you push.
No known vulnerabilities
lockzero-lsp
v0.1.0 · 4 months ago
LockZero language server — diagnostics and code actions for hardcoded secrets
No known vulnerabilities
vite-plugin-security
v0.2.0 · 8 months ago
Build-time security scanner for Vite projects - detect hardcoded secrets, RSC leaks, and dangerous patterns
No known vulnerabilities
securepush
v1.0.14 · 1 year ago
A powerful and AI-driven CLI tool that automatically scans source code for hardcoded secrets before Git operations and deployments, helping developers prevent sensitive data leaks
No known vulnerabilities
nox-agent-lens
v1.0.2 · 6 months ago
See what your AI agents can access. Scans for installed AI coding agents, maps their MCP data sources, and flags hardcoded secrets.
No known vulnerabilities
codesentinel-cli
v1.0.2 · 1 month ago
Code Sentinel AST & AI Security Auditor CLI - Scan local repositories, SD cards, live URLs, and GitHub repos for security flaws and hardcoded secrets.
No known vulnerabilities
@gumballwotersan/clean-code
v1.3.1 · 6 hours ago
Antigravity skill and CLI to strip unnecessary comments, sanitize hardcoded secrets (Supabase, Firebase, OpenAI, Stripe) into .env, and enforce clean code across AI workflows.
No known vulnerabilities
@buildbench/mcp-security-scanner
v1.1.0 · 3 months ago
Static security scanner for Model Context Protocol (MCP) servers. Detects tool-description poisoning, exfiltration cues, hidden-unicode payloads, arbitrary command execution, SSRF surface, hardcoded secrets, and rug-pull risk. Runs locally for Cursor and
No known vulnerabilities
@felix-neuro/eslint-plugin-routeguard
v0.1.1 · 4 months ago
ESLint plugin for Node.js API security — detects BOLA/IDOR, mass-assignment, SSRF, SQL injection, command injection, path traversal, open redirect, and hardcoded secrets across Express, Fastify, and NestJS.
No known vulnerabilities
eslint-plugin-no-secrets
v2.3.3 · 6 months ago
An eslint rule that searches for potential secrets/keys in code
No known vulnerabilities
vibe-to-docker
v5.2.2 · 9 months ago
Fully automated Docker containerization for AI-generated projects. One command handles container setup, dependency installation, and security fixes. 24 features addressing 82% dependency conflicts, 60-70% environment mismatches, 48% hardcoded secrets in L
No known vulnerabilities
gitleash
v0.2.0 · 2 months ago
Keep your AI coding agent on a leash: a zero-config git hook that blocks reckless commits and force-pushes — huge diffs, deleted tests, hardcoded secrets, CI edits — before they land.
No known vulnerabilities
@didrod2539/envlint
v0.1.0 · 3 months ago
Lint .env files locally: sync against .env.example, validate syntax, detect hardcoded secrets (AWS, Stripe, GitHub, OpenAI, private keys…), and enforce an optional schema. Deterministic CLI, JSON/Markdown reports, no network — your secrets never leave the
No known vulnerabilities
@mcp-guard/core
v2.1.0 · 5 months ago
Security scanning engine for Model Context Protocol (MCP) servers. Detects hardcoded secrets, command injection, SSRF, auth misconfig, and compliance gaps.
No known vulnerabilities
@hasna/secrets
v0.5.3 · 14 hours ago
Hosted-first secrets vault client for AI agents — CLI, MCP server and SDK against the Hasna secrets API (credentials via @hasna/contracts), with an explicit opt-in on-box encrypted vault
No known vulnerabilities
@azure/keyvault-secrets
v4.11.2 · 4 months ago
Azure Key Vault Secrets
No known vulnerabilities
leakscan-cli
v1.0.0 · 6 months ago
Zero-dependency CLI to scan your codebase for hardcoded secrets, API keys, and passwords before they leak
No known vulnerabilities
@goguard/scan
v0.1.0 · 5 months ago
Security scanner for AI-generated code — finds hardcoded secrets, missing auth, data leaks, insecure configs
No known vulnerabilities
@quantasyte/scanner
v0.2.1 · 4 months ago
Free + offline post-quantum and weak-crypto scanner. Finds RSA / ECDSA / ECDH, hardcoded secrets, SHA-1 / MD5, TLS misconfig. Outputs a PDF + CycloneDX CBOM. No signup, no telemetry, Apache 2.0.
No known vulnerabilities
@cruxet/mcp-audit
v0.2.0 · 5 months ago
Local, zero-setup security linter for your MCP client configs. Catches command injection, hardcoded secrets, insecure transports, and known CVEs across Cursor, Claude, Windsurf, VSCode, Continue, Codex, and Zed. No account, no API calls, no data leaves yo
No known vulnerabilities