pastewatch-mcpSecret redaction MCP server for OpenClaw agents. Prevents API keys, DB credentials, SSH keys, emails, IPs, JWTs, and 30+ other secret types from leaking to L...
Install via ClawdBot CLI:
clawdbot install ppiankov/pastewatch-mcpGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses system directories or attempts privilege escalation
/var/log/Calls external URL not in known-safe list
https://github.com/ppiankov/pastewatchUses known external API (expected, informational)
api.anthropic.comAI Analysis
The skill's stated purpose is secret redaction and local security scanning, which aligns with its external API usage (Anthropic API proxy). However, it downloads and executes external binaries from GitHub, introduces a local proxy that intercepts all LLM traffic, and requires broad system permissions including audit log access to /var/log/, creating potential for privilege escalation or data interception if compromised.
Generated Mar 21, 2026
Development teams building AI agents that read and write code or configuration files can use Pastewatch MCP to prevent accidental leakage of API keys, database credentials, and other secrets into LLM prompts. The MCP tools like pastewatch_read_file and pastewatch_write_file automatically replace secrets with placeholders during agent operations, ensuring sensitive data stays local while maintaining workflow integrity.
DevOps engineers can integrate Pastewatch into CI/CD pipelines to scan repositories for exposed secrets before deployments. Using git history scanning and directory scans, it identifies credentials in code commits and configuration files, helping organizations comply with security policies and prevent breaches in cloud infrastructure.
Financial institutions handling sensitive customer data can deploy Pastewatch to audit internal tools and scripts for credential exposure. The API proxy acts as a last line of defense, scanning outbound requests to LLM providers, while the encrypted vault secures secrets used in automated financial reporting or trading algorithms.
Healthcare organizations using AI for patient data analysis can leverage Pastewatch to redact PHI and access tokens in files processed by agents. The guard command blocks secret-leaking shell commands, and the file watcher provides real-time monitoring of directories containing medical records or research data.
E-commerce companies managing multiple microservices and APIs can use Pastewatch to prevent leakage of payment gateway keys and database credentials. The org posture scanning feature audits all repositories across teams, and canary tokens help detect unauthorized access attempts in logs from production environments.
Offer tiered subscriptions based on features like org posture scanning, encrypted vault capacity, and audit log retention. Enterprises pay annually for advanced security, compliance reporting, and priority support, targeting large tech and financial firms with stringent data protection needs.
Provide a cloud-hosted dashboard with real-time scanning, alerts, and integration APIs for DevOps teams. Revenue comes from monthly per-user or per-repository fees, with add-ons for custom secret types and advanced proxy configurations, appealing to mid-sized companies without on-premise infrastructure.
Distribute the core tool as open source to build community adoption, then monetize through paid support, training, and consulting services. Offer custom integrations, security audits, and managed deployments for clients in regulated industries like healthcare and finance.
💬 Integration Tip
Start by running pastewatch-cli setup for your agent environment to automatically configure hooks and MCP tools, then test with the scan_file tool to verify secret detection before enabling the API proxy for production use.
Scored Apr 19, 2026
Audited Apr 17, 2026 · audit v1.0
Use the mcporter CLI to list, configure, auth, and call MCP servers/tools directly (HTTP or stdio), including ad-hoc servers, config edits, and CLI/type generation.
Secure, sandboxed filesystem access enabling agents to list, read, write, create, move, delete, search files and directories within allowed paths.
Provides access to MCP tools for web search, advanced search, code context, deep research, crawling, company research, and LinkedIn search.
Use Model Context Protocol servers to access external tools and data sources. Enable AI agents to discover and execute tools from configured MCP servers (legal databases, APIs, database connectors, weather services, etc.).
Use the mcporter CLI to list, configure, auth, and call MCP servers/tools directly (HTTP or stdio), including ad-hoc servers, config edits, and CLI/type gene...
Crypto news search, AI ratings, trading signals, and real-time updates via the OpenNews 6551 API. Supports keyword search, coin filtering, source filtering,...