mintmcp/agent-security
mintmcp/agent-security · 1 plugin
Marketplace Hooks for Claude Code and Cursor for secrets scanning
Install
The repo has no one-line install. Follow its README.
Plugins 1
After adding the marketplace, install one with /plugin install <name>@agent-security.
- 1secrets-scannerScans for common credentials across cloud, source control, payment, and collaboration providers
/plugin install secrets-scanner@agent-security
Files
Security plugins for Claude Code and Cursor
This repository currently provides a secrets scanner plugin.
Motivation
Coding agents are powerful, but we've repeatedly seen them read and propagate sensitive data during everyday work. That can be acceptable for casual "vibe coding" experiments, but it's not acceptable for production software engineering. We built this to make accidental leakage much harder: a standalone, local-first scanner with minimal footprint (no external dependencies, regex-only), running as editor/agent hooks entirely on your machine, and easy to set up so teams can adopt it without friction.
Install
Claude Code Plugin Marketplace
Install via the Claude Code plugin marketplace:
/plugin marketplace add mintmcp/agent-security
/plugin install secrets-scanner@agent-securityPyPI (manual hooks)
pipx install claude-secret-scan
# or
python3 -m pip install --user claude-secret-scanAdd hooks to ~/.claude/settings.json if using PyPI:
{
"hooks": {
"UserPromptSubmit": [
{"hooks": [{"type": "command", "command": "claude-secret-scan --mode=pre"}]}
],
"PreToolUse": [
{"matcher": "Read|read", "hooks": [{"type": "command", "command": "claude-secret-scan --mode=pre"}]}
],
"PostToolUse": [
{"matcher": "Read|read", "hooks": [{"type": "command", "command": "claude-secret-scan --mode=post"}]},
{"matcher": "Bash|bash", "hooks": [{"type": "command", "command": "claude-secret-scan --mode=post"}]}
]
}
}Cursor
Copy examples/configs/cursor-hooks.json to ~/.cursor/hooks.json or configure similarly:
{
"version": 1,
"hooks": {
"beforeReadFile": [{"command": "cursor-secret-scan --mode=pre"}],
"beforeSubmitPrompt": [{"command": "cursor-secret-scan --mode=pre"}]
}
}Repository Layout
.
├── .claude-plugin/
│ └── marketplace.json
├── plugins/
│ └── secrets_scanner/
│ ├── .claude-plugin/
│ │ └── plugin.json
│ ├── hooks/
│ │ ├── hooks.json
│ │ └── secrets_scanner_hook.py
│ ├── tests/
│ │ └── read_hook_test.py
│ ├── TESTING.md
│ └── README.md
├── examples/
│ └── configs/
├── pyproject.toml
└── README.md
Notes
- Pre hooks block when secrets are detected. Post hooks print warnings.
- No external dependencies. The scanner uses only Python's built-in regexes and simple pattern matching.
- Runs completely locally. No code, prompts, or files leave your system.
- Curious how it works? See
plugins/secrets_scanner/hooks/secrets_scanner_hook.pyfor the core implementation and patterns. - No telemetry by default. For org-wide visibility and governance (dashboards, metrics, alerting), see https://mintmcp.com.
License
Apache License 2.0. See LICENSE.
Acknowledgements
Regex patterns were informed by or adapted from detect-secrets (Apache 2.0).
{
"$schema": "https://anthropic.com/claude-code/marketplace.schema.json",
"name": "agent-security",
"version": "0.1.14",
"description": "Security plugins for Claude Code and Cursor: secret scanning and safe coding patterns",
"owner": {
"name": "MintMCP",
"email": "support@mintmcp.com"
},
"plugins": [
{
"name": "secrets-scanner",
"description": "Scans for common credentials across cloud, source control, payment, and collaboration providers",
"version": "0.1.14",
"author": {
"name": "MintMCP",
"email": "support@mintmcp.com"
},
"source": "./plugins/secrets_scanner",
"category": "security",
"keywords": [
"security",
"secrets",
"credentials",
"scanning"
]
}
]
}Facts
- Kind
- Marketplace
- Repo
- mintmcp/agent-security
- Group
- Uncategorized
- Marketplace name
- agent-security
- Owner
- MintMCP
- License
- Apache-2.0
- Language
- Python
- Created
- 2025-10-06
- Forks
- 4
- Homepage
- mintmcp.com
- Topics
- claude, code, cursor, hooks, plugins, secret, security
- Plugins
- 1
- 1f/prompts.chatf/prompts.chatf.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
- 2affaan-m/everything-claude-codeaffaan-m/everything-claude-codeThe agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
- 3obra/superpowersobra/superpowersAn agentic skills framework & software development methodology that works.
- 4anthropics/skillsanthropics/skillsPublic repository for Agent Skills
- 5anthropics/claude-codeanthropics/claude-codeClaude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows - all through natural language commands.
- 6nextlevelbuilder/ui-ux-pro-max-skillnextlevelbuilder/ui-ux-pro-max-skillAn AI skill that provides design intelligence for building professional UI/UX across multiple platforms.
