
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
secrets-le-mcp
Advanced tools
Detect hardcoded secrets in source and config, reporting masked previews and never the values themselves.
An MCP server that extracts URLs from documentation, configuration and code — the extraction engine behind the Secrets-LE editor extension, exposed as a tool an agent can call.
No dependencies, no network calls, no filesystem access. Content goes in, structured results come out.
Point any MCP host at npx secrets-le-mcp.
Claude Code
claude mcp add secrets-le -- npx -y secrets-le-mcp
Anything with a JSON config — Cursor, Windsurf, Claude Desktop:
{
"mcpServers": {
"secrets-le": {
"command": "npx",
"args": ["-y", "secrets-le-mcp"]
}
}
}
VS Code and Zed need nothing here. Install the extension instead — it carries this server and registers it for you: VS Code Marketplace · Open VSX · Zed (no listing yet — add it by hand)
No Node? The same detect_secrets tool ships in a static Rust
binary: cargo install secrets-le, then secrets-le mcp
(crates.io). The two servers
answer identically — one fixture corpus runs against both and CI fails
if they diverge — and both mask the same way. The binary additionally
offers secrets_le_scan, which walks a tree; this server reads no
files, which is what lets an agent call it anywhere.
Prefer a global install to npx on every launch:
npm install -g secrets-le-mcp
{
"mcpServers": {
"secrets-le": { "command": "secrets-le-mcp" }
}
}
No environment variables, no API key, no configuration of its own. To check it before wiring it into anything:
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | npx -y secrets-le-mcp
If that prints the tool name, the server works.
detect_secrets| argument | type | |
|---|---|---|
content | string | required. The text to scan. |
format | string | The language: markdown, yaml, json, typescript… Required unless filename is given. |
filename | string | Used to infer format when it is absent — README.md resolves to markdown. |
dedupe | boolean | Collapse repeats. Default false. |
maxResults | number | Default 500, ceiling 5000. |
Returns each URL with its protocol and 1-based line and column, plus
meta.truncated so a capped result is never mistaken for a complete one.
{
"ok": true,
"data": {
"secrets": [
{ "value": "https://example.com/guide", "protocol": "https", "line": 2, "column": 15 }
]
},
"meta": { "count": 1, "truncated": false }
}
Extraction is heuristic, and what it deliberately does not match is documented as carefully as what it does — see the extension README.
io.github.nolindnaidoo/secrets-le —
registry.modelcontextprotocol.io
One tool each, same shape: content in, structured data out, no network and no
filesystem. Every one is on npm as <name>-mcp and in the MCP registry as
io.github.nolindnaidoo/<name>.
| Package | Tool | Extracts |
|---|---|---|
urls-le-mcp | extract_urls | URLs, with protocol and position |
colors-le-mcp | extract_colors | colors from stylesheets and code |
dates-le-mcp | extract_dates | dates and timestamps |
paths-le-mcp | extract_paths | file and directory paths |
numbers-le-mcp | extract_numbers | numeric values |
string-le-mcp | extract_strings | string values |
regex-le-mcp | extract_patterns | regexes, with a ReDoS verdict |
envsync-le-mcp | compare_env_files | dotenv key drift, names only |
scrape-le-mcp | analyze_robots_txt | whether a path may be crawled |
Every tool in the family, one page: letools.dev
Nolin Naidoo — Chief Engineer, AI/ML & Platform Architecture. nolindnaidoo.com · GitHub · LinkedIn
Twelve Rust tools built the same way: small, single-purpose, and driven by a machine rather than a person. pixelcoords and pixelactions make up one loop — pixelcoords answers where, pixelactions acts there. The nine LE crates are the terminal half of the extensions they sit in: the same detection, held to the extension's own corpus, and an exit code instead of a results editor.
| pixelcoords | Freeze your screen, mark regions, get pixel-exact coordinates and crops | site · crates.io · docs.rs |
| pixelactions | Consume human-verified coordinates, perform the interaction, confirm it landed | site · crates.io · docs.rs |
| paths-le | Find every path in a codebase and report whether it still points at anything | crates.io |
| secrets-le | Find hardcoded credentials, and never print one | crates.io |
| urls-le | Extract every URL from a codebase, with its protocol and exact position | crates.io |
| regex-le | Find every regex in a codebase and report which can be driven into catastrophic backtracking | crates.io |
| string-le | Get every string in a codebase out where a person can read them | crates.io |
| numbers-le | Find every hardcoded number in a codebase so a person can check them | crates.io |
| envsync-le | Compare the dotenv files in a tree and say which keys are missing from which | crates.io |
| colors-le | Find every colour in a codebase, and say which are not in your palette | crates.io |
| scrape-le | Check whether a page is scrapeable before the scraper is written | crates.io |
MIT © Nolin Naidoo
FAQs
Detect hardcoded secrets in source and config, reporting masked previews and never the values themselves.
We found that secrets-le-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.