Skip to main content

MCP server for n0s1 — scan Jira, Confluence, Slack, GitHub, GitLab, Zendesk, Linear, Asana, Wrike, and local files for leaked secrets

Project description

n0s1-mcp

An MCP server that exposes n0s1 secret-scanning capabilities as tools for AI assistants (Claude, Cursor, etc.).

Scan Jira, Confluence, Slack, GitHub, GitLab, Zendesk, Linear, Asana, Wrike, and local filesystems for leaked secrets — directly from your AI workflow.

Quickstart

No install required. Add this to your MCP client config and run via uvx:

{
  "mcpServers": {
    "n0s1": {
      "command": "uvx",
      "args": ["n0s1-mcp"]
    }
  }
}

For Claude Desktop: ~/Library/Application Support/Claude/claude_desktop_config.json
For Claude Code: .claude/mcp.json in your project, or ~/.claude/mcp.json globally.

Available Tools

Tool Description Required params
scan_jira Scan Jira tickets server, email, api_key
scan_confluence Scan Confluence pages server, email, api_key
scan_slack Scan Slack channels api_key
scan_github Scan GitHub repositories api_key, owner
scan_gitlab Scan GitLab projects api_key, owner
scan_zendesk Scan Zendesk tickets server, email, api_key
scan_linear Scan Linear issues api_key
scan_asana Scan Asana tasks api_key
scan_wrike Scan Wrike tasks api_key
scan_local Scan local filesystem scan_path
get_scan_status Get status of a running/completed scan report_uuid
get_scan_findings Get paginated findings for a completed scan report_uuid
analyze_report Submit or advance async AI credential validation report_uuid

All scan_* tools accept these optional parameters:

Parameter Description
report_uuid UUID to assign to the scan report. When set, overrides the auto-generated UUID written to the report JSON.
ai_analysis Queue async AI credential validation after the scan (requires n0s1 Professional)
n0s1_api_key n0s1 API key; overrides N0S1_TOKEN env var
allow_secret_upload Allow encrypted secrets to be uploaded to the n0s1 backend (default: false)

Pass wait_minutes to analyze_report (or directly on a scan tool alongside ai_analysis) to block until analysis completes.

Environment Variables

Credentials can be passed as tool arguments or pre-set as environment variables:

Variable Used by
N0S1_TOKEN All scan tools with ai_analysis — Professional mode uploads and AI analysis
JIRA_TOKEN scan_jira, scan_confluence
JIRA_EMAIL scan_jira, scan_confluence
SLACK_TOKEN scan_slack
GITHUB_TOKEN scan_github
GITLAB_TOKEN scan_gitlab
ZENDESK_TOKEN scan_zendesk
ZENDESK_EMAIL scan_zendesk
LINEAR_TOKEN scan_linear
ASANA_TOKEN scan_asana
WRIKE_TOKEN scan_wrike

Example with env vars pre-configured:

{
  "mcpServers": {
    "n0s1": {
      "command": "uvx",
      "args": ["n0s1-mcp"],
      "env": {
        "GITHUB_TOKEN": "ghp_...",
        "JIRA_TOKEN": "ATATT..."
      }
    }
  }
}

Usage Examples

Once connected, ask your AI assistant:

  • "Scan my Jira project SEC for leaked secrets"
  • "Check the GitHub org mycompany for exposed API keys"
  • "Scan the /home/user/project directory for secrets"
  • "Run an AI analysis on the scan report abc123"

For full parameter reference and AI analysis workflow details, see docs/ai.md.

Publishing to PyPI

pip install hatch
hatch build
hatch publish

License

GNU General Public License v3 — same as n0s1.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

n0s1_mcp-1.1.2.tar.gz (39.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

n0s1_mcp-1.1.2-py3-none-any.whl (32.1 kB view details)

Uploaded Python 3

File details

Details for the file n0s1_mcp-1.1.2.tar.gz.

File metadata

  • Download URL: n0s1_mcp-1.1.2.tar.gz
  • Upload date:
  • Size: 39.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for n0s1_mcp-1.1.2.tar.gz
Algorithm Hash digest
SHA256 11e5905fa0c2129cb0476194b82b0485be7e1f266a0afa3ce375f8a7f6cc8126
MD5 643f09f062f506a77de972b41494435b
BLAKE2b-256 5f5896c33d6f5de3fc512bc8a6afe9590136b7f2a8f08c5b69d2adfa16767cce

See more details on using hashes here.

Provenance

The following attestation bundles were made for n0s1_mcp-1.1.2.tar.gz:

Publisher: publish.yml on spark1security/n0s1-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file n0s1_mcp-1.1.2-py3-none-any.whl.

File metadata

  • Download URL: n0s1_mcp-1.1.2-py3-none-any.whl
  • Upload date:
  • Size: 32.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for n0s1_mcp-1.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 6c3520a15613685554fc59287d27dc1ad86bfaf4a649104a8807535d2b4546da
MD5 67a4c80d619d92a8ffdad944acdf5ae1
BLAKE2b-256 4b15e4134e0112f6b20af748deb63007cc850479b0d93beb79e2a1b9110b239e

See more details on using hashes here.

Provenance

The following attestation bundles were made for n0s1_mcp-1.1.2-py3-none-any.whl:

Publisher: publish.yml on spark1security/n0s1-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page