GhostHunt
Find every leaked secret on your machine. Scans .env files, shell history, and config directories for API keys, tokens, and credentials. Everything runs locally.
GhostHunt
Find every leaked secret on your machine.
GhostHunt is an MCP server that scans your development machine for API keys, tokens, and credentials hiding in places you forgot to check: .env files scattered across projects, shell history, AWS/SSH/Docker configs, and more.
Everything runs locally. No data leaves your machine.
What It Scans
- Environment files — recursively finds every
.env,.env.local,.env.production, etc. under your home directory - AWS credentials —
~/.aws/credentialsand session tokens - SSH keys — unprotected private keys in
~/.ssh/ - Docker config — registry auth tokens in
~/.docker/config.json - npm/PyPI tokens —
~/.npmrc,~/.pypircauth tokens - GitHub CLI — OAuth tokens in
~/.config/gh/hosts.yml - Shell history — API keys pasted into
bash,zsh, orfishcommands - Kubernetes —
~/.kube/configcredentials - Netrc —
~/.netrcpasswords - 35+ secret patterns — AWS, Stripe, GitHub, OpenAI, Anthropic, Google, Slack, Twilio, SendGrid, database connection strings, private keys, and more
Install
Claude Desktop
Add to your Claude Desktop config (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"ghosthunt": {
"command": "npx",
"args": ["-y", "ghosthunt"]
}
}
}
Restart Claude Desktop. Then ask Claude: "Scan my machine for leaked secrets"
Direct Usage
npx ghosthunt
Tools
scan_secrets
Full detailed scan. Returns every finding with file paths, line numbers, severity ratings, and remediation steps.
Example prompt: "Run a full GhostHunt scan and show me everything"
scan_summary
Quick health check. Returns your health score (0-100) and a count by severity. Run this first to see if you have a problem.
Example prompt: "Give me a quick GhostHunt health check"
Example Output
# GhostHunt Scan Report
**Health Score: 37/100** (Critical)
- Secrets found: **12**
- Critical: 3 | High: 5 | Medium: 2 | Low: 2
- Locations scanned: 47
- Scan time: 142ms
## Environment Files (.env)
- **[CRITICAL]** Stripe Live Secret Key
- File: `/Users/you/project-a/.env:4`
- Context: `STRIPE_SECRET_KEY`
- Value: `sk_l****_8xQ`
- **[CRITICAL]** OpenAI API Key
- File: `/Users/you/side-project/.env.local:12`
- Context: `OPENAI_API_KEY`
- Value: `sk-p****kFJ9`
## Shell History
- **[HIGH]** Bearer Token in Header
- File: `/Users/you/.zsh_history:8847`
- Context: `curl -H "Authorization: Bearer sk_live_...`
- Value: `sk_l****_m3K`
## Recommendations
1. **Rotate critical secrets immediately.** Any API key marked CRITICAL
should be revoked and regenerated from the provider's dashboard.
2. **Clear your shell history** of sensitive commands.
3. **Audit your .env files.** Ensure they are in .gitignore.
Health Score
Your score starts at 100 and drops based on what GhostHunt finds:
| Finding | Penalty |
|---|---|
| Critical secret | -15 |
| High severity | -8 |
| Medium severity | -3 |
| Low severity | -1 |
A score below 50 means you have secrets that need immediate attention.
Privacy
GhostHunt runs entirely on your local machine. It does not:
- Send any data to any server
- Phone home or track usage
- Store scan results anywhere
- Access the internet
Your secrets stay on your machine. The scan results stay in your Claude conversation.
License
MIT
Related Servers
Alpha Vantage MCP Server
sponsorAccess financial market data: realtime & historical stock, ETF, options, forex, crypto, commodities, fundamentals, technical indicators, & more
Universal Crypto MCP
Enable AI agents to interact with any EVM blockchain through natural language.
Glider
Roslyn-powered C# code analysis server for LLMs. Supports stdio and HTTP transports.
Clangaroo
Provides fast C++ code intelligence for LLMs using the clangd language server.
Postman MCP Server
Run Postman collections using Newman, with support for environment and global variables.
Unity-MCP
A bridge between the Unity game engine and AI assistants using the Model Context Protocol (MCP).
Remote Terminal MCP for Cursor
A remote terminal tool for Cursor to manage and connect to remote servers via SSH, jump hosts, and Docker containers.
Yapi
An MCP server for the Yapi API management platform.
MCP QEMU VM Control
Give your AI full computer access — safely. Let Claude (or any MCP-compatible LLM) see your screen, move the mouse, type on the keyboard, and run commands — all inside an isolated QEMU virtual machine. Perfect for AI-driven automation, testing, and computer-use experiments without risking your host system.
TypeScript MCP Server
TypeScript MCP server for AI-powered refactoring. Rename symbols, extract functions, move declarations, inline variables, find references, and fix diagnostics — strictly via the native tsserver
OneTool MCP
🧿 One MCP for developers - No tool tax, no context rot. 100+ tools including Brave, Gemini, Context7, Version Checker, Excel, File Ops, Database, Chrome DevTools.