Find every leaked secret on your machine — API keys in .env files, shell history, and configs.
Most developer tooling work still happens through a UI a human drives. Ghosthunt MCP server moves it into the conversation instead. Find every leaked secret on your machine — API keys in .env files, shell history, and configs.
GhostHunt is an MCP server that scans your development machine for API keys, tokens, and credentials hiding in places you forgot to check: .env files scattered across projects, shell history, AWS/SSH/Docker configs, and more.
The server publishes 2 tools. What each one is for:
scan_secrets — Full detailed scan. Returns every finding with file paths, line numbers, severity ratings, and remediation stepsscan_summary — Quick health check. Returns your health score (0-100) and a count by severity. Run this first to see if you have a problemConfiguration is passed through the environment: STRIPE_SECRET_KEY, OPENAI_API_KEY. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.
The server ships on npm as ghosthunt, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.
This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. Ghosthunt's toolset — scan_secrets, scan_summary — is a fair guide to whether it matches your workflow. It is maintained by 78degrees; worth a glance at recent repository activity before you build anything load-bearing on it.
We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.
| Tool | What it does |
|---|---|
| scan_secrets | Full detailed scan. Returns every finding with file paths, line numbers, severity ratings, and remediation steps. |
| scan_summary | Quick health check. Returns your health score (0-100) and a count by severity. Run this first to see if you have a problem. |
{
"mcpServers": {
"ghosthunt": {
"command": "npx",
"args": ["-y", "ghosthunt"]
}
}
}Configuration as documented by the project. Restart the client after saving.
| Variable | Description | Required |
|---|---|---|
| STRIPE_SECRET_KEY | Credential the server authenticates with. | Yes |
| OPENAI_API_KEY | Credential the server authenticates with. | Yes |
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.