Skip to main content

Rust-backed secrets detection plugin for MCP Gateway

Project description

Secrets Detection (Rust)

Rust-backed secrets detection and redaction for ContextForge and MCP Gateway.

Features

  • Detects likely credentials in prompt arguments, tool inputs, tool outputs, and resource content
  • Built-in detectors for AWS keys, Google API keys, GitHub tokens, Stripe keys, Slack tokens, and private key blocks
  • Optional broad detectors for generic API key assignments, JWT-like strings, long hex strings, and base64-like secrets
  • Blocking, redaction, or metadata-only reporting modes
  • Recursive scanning for nested dicts, lists, tuples, Pydantic-style objects, __dict__, and __slots__
  • Sanitized outward metadata that reports finding types and counts, not original secret values

Build

make install

Runtime Requirements

This plugin depends on cpex>=0.1.0,<0.2 and imports hook models from cpex.framework. The compiled Rust extension is mandatory; there is no Python fallback implementation.

Usage

The plugin scans these hooks:

  • prompt_pre_fetch: scans payload.args
  • tool_pre_invoke: scans tool invocation payloads before execution
  • tool_post_invoke: scans payload.result
  • resource_post_fetch: scans payload.content.text

Typical uses:

  • block requests that contain likely credentials before they reach tools or prompts
  • redact secrets from returned tool or resource payloads
  • surface sanitized findings metadata for observability and tuning

Detection Coverage

Enabled by default:

  • aws_access_key_id
  • aws_secret_access_key
  • google_api_key
  • github_token
  • stripe_secret_key
  • slack_token
  • private_key_block

Disabled by default because they are broader and more false-positive-prone:

  • generic_api_key_assignment
  • jwt_like
  • hex_secret_32
  • base64_24

The detectors are regex-based. They do not verify whether a credential is real, active, or revoked.

Configuration

config:
  enabled:
    aws_access_key_id: true
    aws_secret_access_key: true
    google_api_key: true
    github_token: true
    stripe_secret_key: true
    slack_token: true
    private_key_block: true
    generic_api_key_assignment: false
    jwt_like: false
    hex_secret_32: false
    base64_24: false
  redact: false
  redaction_text: "***REDACTED***"
  block_on_detection: true
  min_findings_to_block: 1
Field Type Default Description
enabled dict built-in defaults Per-detector enable flags; unspecified detectors inherit defaults
redact bool false Replace matched secret values in returned payloads
redaction_text string "***REDACTED***" Replacement text used when redact=true
block_on_detection bool true Return a violation when enough findings are present
min_findings_to_block integer 1 Minimum finding count required before blocking

Behavior Notes

  • Redaction preserves payload shape where possible instead of flattening everything to plain dicts.
  • aws_secret_access_key recognizes = and : assignments with optional single or double quotes around the value.
  • base64_24 uses capture-group redaction so leading non-base64 boundary characters are preserved.
  • Broad detectors remain opt-in to reduce noisy matches on ordinary identifiers.
  • Binary resource bodies are not scanned; resource_post_fetch only scans text content exposed as payload.content.text.
  • The plugin does not decode archives, compressed data, or arbitrary encoded blobs before scanning.

Returned Metadata

prompt_pre_fetch, tool_pre_invoke, tool_post_invoke, and resource_post_fetch accept an optional extensions parameter carrying OpenTelemetry trace context. When a trace context is present (via extensions.request.trace_id), the plugin emits operational metrics on result.metadata["secrets_detection"] with the following schema:

result.metadata["secrets_detection"] = {
    "total_detections": 2,   # int — total number of findings in this call
    "total_masked": 2,       # int — number redacted (masking action taken)
    "total_blocked": 0,      # int — number that caused a block (blocking action taken)
    "secret_types": ["aws_access_key_id", "slack_token"],  # list[str] — distinct type names, sorted, deduped
}

total_masked and total_blocked are mutually exclusive per call: exactly one of them carries the finding count (the other is 0), depending on whether the redaction branch or the blocking branch executed. If neither redaction nor blocking is configured, both are 0 and only total_detections/secret_types are non-zero (findings-only reporting mode).

Gating: Metrics are only emitted when a valid trace_id is present in the trace context (extensions.request.trace_id). No trace context means no result.metadata write at all, regardless of any config flag — this keeps the untraced path byte-for-byte identical to before metrics existed.

Security Note (S1): The plugin never includes raw secret values in result.metadata, logs, or any other output. Only counts and type-category names (e.g. "aws_access_key_id") are reported.

tool_pre_invoke is in scope for this metrics contract on the same terms as the other 3 hooks: it accepts extensions and emits result.metadata["secrets_detection"] under the identical gating/schema once a valid trace_id is present.

Blocking responses use the SECRETS_DETECTED violation code.

Migration Note

Version 0.3.7 is a breaking change for any existing consumer reading detection metadata:

  • The old flat result.metadata keys — secrets_redacted, count (redaction path) and secrets_findings, count (findings-only path) — have been removed entirely. There is no compatibility shim; code reading those keys will silently stop receiving data.
  • Detection/redaction/blocking metrics are now emitted on result.metadata["secrets_detection"] instead, with keys total_detections, total_masked, total_blocked, and secret_types (see Returned Metadata above for the full schema).
  • All 4 hooks — prompt_pre_fetch, tool_pre_invoke, tool_post_invoke, and resource_post_fetch — now accept a new optional extensions parameter carrying OpenTelemetry trace context. Emission to result.metadata["secrets_detection"] is gated solely on extensions.request.trace_id being present and valid — if no trace context is supplied, no metrics are written at all, regardless of any config flag.
  • Consumers that previously read result.metadata["secrets_redacted"] / result.metadata["secrets_findings"] unconditionally must migrate to reading result.metadata["secrets_detection"] and must pass a trace_id via extensions to receive metrics.
  • tool_pre_invoke previously never received extensions and could never emit metrics (a regression introduced earlier on this branch, since fixed) — it now follows the exact same contract as the other 3 hooks.

Security Notes

  • Outward-facing findings metadata and violation examples do not include original matched secret values.
  • Enable broad detectors only after testing against representative payloads.
  • The detector is best-effort pattern matching and should complement, not replace, upstream secret management controls.

Testing

make ci

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

cpex_secrets_detection-0.3.8.tar.gz (52.8 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

cpex_secrets_detection-0.3.8-cp311-abi3-win_amd64.whl (767.4 kB view details)

Uploaded CPython 3.11+Windows x86-64

cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_x86_64.whl (839.4 kB view details)

Uploaded CPython 3.11+manylinux: glibc 2.34+ x86-64

cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_s390x.whl (873.9 kB view details)

Uploaded CPython 3.11+manylinux: glibc 2.34+ s390x

cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_ppc64le.whl (865.8 kB view details)

Uploaded CPython 3.11+manylinux: glibc 2.34+ ppc64le

cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_aarch64.whl (783.2 kB view details)

Uploaded CPython 3.11+manylinux: glibc 2.34+ ARM64

cpex_secrets_detection-0.3.8-cp311-abi3-macosx_11_0_arm64.whl (741.9 kB view details)

Uploaded CPython 3.11+macOS 11.0+ ARM64

File details

Details for the file cpex_secrets_detection-0.3.8.tar.gz.

File metadata

  • Download URL: cpex_secrets_detection-0.3.8.tar.gz
  • Upload date:
  • Size: 52.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for cpex_secrets_detection-0.3.8.tar.gz
Algorithm Hash digest
SHA256 f1b810218f5d09c4b4ebac60b21f3ef1ffb7d25ca88cbe26315650499d8349d9
MD5 921ef7530e32e892b61e0b0773cdab0d
BLAKE2b-256 7dc01a7bf87cbc8764dd9ccb004c1c75f0469ceb65b9589d1eb49937ac1f6e18

See more details on using hashes here.

Provenance

The following attestation bundles were made for cpex_secrets_detection-0.3.8.tar.gz:

Publisher: release-rust-python-package.yaml on IBM/cpex-plugins

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file cpex_secrets_detection-0.3.8-cp311-abi3-win_amd64.whl.

File metadata

File hashes

Hashes for cpex_secrets_detection-0.3.8-cp311-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 d1b812d9151dce8ed555401967d4b2af6b28f187c9e4e5d45aefe07128d9118d
MD5 4f023af3a96eb27d3aff17195aab7bb9
BLAKE2b-256 c66898a1a776e43e7475398b811f5bee205fbcf8f19147f0c7dde27ec6386f9b

See more details on using hashes here.

Provenance

The following attestation bundles were made for cpex_secrets_detection-0.3.8-cp311-abi3-win_amd64.whl:

Publisher: release-rust-python-package.yaml on IBM/cpex-plugins

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_x86_64.whl.

File metadata

File hashes

Hashes for cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_x86_64.whl
Algorithm Hash digest
SHA256 653b589a3892d098f527e0b21fd609caa06bd9e43000b7fd14caab24fa62d6c3
MD5 4f0c184679d400900a169de011f55ca0
BLAKE2b-256 75ed93f5f3a494f0cbb910ff8589d3935226fced3a185434900f1348ef1625be

See more details on using hashes here.

Provenance

The following attestation bundles were made for cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_x86_64.whl:

Publisher: release-rust-python-package.yaml on IBM/cpex-plugins

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_s390x.whl.

File metadata

File hashes

Hashes for cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_s390x.whl
Algorithm Hash digest
SHA256 f76e9349aa12c49a4cb038900efaedc0da6aac896b0d61b939f2621cd30152e0
MD5 91d1e317ea61876c38cc089bf79f3351
BLAKE2b-256 265114ec7b766775ad491061199c4ae01fe5090cf080743825c9fa01fc7fb98b

See more details on using hashes here.

Provenance

The following attestation bundles were made for cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_s390x.whl:

Publisher: release-rust-python-package.yaml on IBM/cpex-plugins

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_ppc64le.whl.

File metadata

File hashes

Hashes for cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_ppc64le.whl
Algorithm Hash digest
SHA256 f6e11e09d53760809d5b577d3d54ba4ce2783bf19e27b07c20d2248d0399948a
MD5 b31bc18d1bd998c8da122d46db322775
BLAKE2b-256 5d58f3f31c06615632d5c2dc34113e914c4fd19530f88a87fc2d4990f1f31476

See more details on using hashes here.

Provenance

The following attestation bundles were made for cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_ppc64le.whl:

Publisher: release-rust-python-package.yaml on IBM/cpex-plugins

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_aarch64.whl.

File metadata

File hashes

Hashes for cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_aarch64.whl
Algorithm Hash digest
SHA256 dd85fd0eda5870d9dc1f1d6df15ee614b27af88ffc491655a389f2d08439e367
MD5 ac5083fe54f6296675c1c389022d1a49
BLAKE2b-256 71f653271d878cf6e3be5087bbfbb8aae0756f0a081cff0f0dd73ba81696e31e

See more details on using hashes here.

Provenance

The following attestation bundles were made for cpex_secrets_detection-0.3.8-cp311-abi3-manylinux_2_34_aarch64.whl:

Publisher: release-rust-python-package.yaml on IBM/cpex-plugins

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file cpex_secrets_detection-0.3.8-cp311-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for cpex_secrets_detection-0.3.8-cp311-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 92ab77b3ed9cf4ecbc5c84a8715a7c2ce4469f91c6227345bc9da212c17f105e
MD5 ccc7801534596b741515deadc63bd375
BLAKE2b-256 249ddca5c9b123f12a3e84901daeb9de8df70a6849edb657175b0b2e9b9e4fc8

See more details on using hashes here.

Provenance

The following attestation bundles were made for cpex_secrets_detection-0.3.8-cp311-abi3-macosx_11_0_arm64.whl:

Publisher: release-rust-python-package.yaml on IBM/cpex-plugins

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page