Skip to main content

MCP server for n0s1 — scan Jira, Confluence, Slack, GitHub, GitLab, Zendesk, Linear, Asana, Wrike, and local files for leaked secrets

Project description

n0s1-mcp

An MCP server that exposes n0s1 secret-scanning capabilities as tools for AI assistants (Claude, Cursor, etc.).

Scan Jira, Confluence, Slack, GitHub, GitLab, Zendesk, Linear, Asana, Wrike, and local filesystems for leaked secrets — directly from your AI workflow.

Quickstart

No install required. Add this to your MCP client config and run via uvx:

{
  "mcpServers": {
    "n0s1": {
      "command": "uvx",
      "args": ["n0s1-mcp"]
    }
  }
}

For Claude Desktop: ~/Library/Application Support/Claude/claude_desktop_config.json
For Claude Code: .claude/mcp.json in your project, or ~/.claude/mcp.json globally.

Available Tools

Tool Description Required params
scan_jira Scan Jira tickets server, email, api_key
scan_confluence Scan Confluence pages server, email, api_key
scan_slack Scan Slack channels api_key
scan_github Scan GitHub repositories api_key, owner
scan_gitlab Scan GitLab projects api_key, owner
scan_zendesk Scan Zendesk tickets server, email, api_key
scan_linear Scan Linear issues api_key
scan_asana Scan Asana tasks api_key
scan_wrike Scan Wrike tasks api_key
scan_local Scan local filesystem scan_path
get_scan_status Get status of a running/completed scan report_uuid
get_scan_findings Get paginated findings for a completed scan report_uuid
analyze_report Submit or advance async AI credential validation report_uuid

All scan_* tools accept these optional parameters:

Parameter Description
report_uuid UUID to assign to the scan report. When set, overrides the auto-generated UUID written to the report JSON.
ai_analysis Queue async AI credential validation after the scan (requires n0s1 Professional)
n0s1_api_key n0s1 API key; overrides N0S1_TOKEN env var
allow_secret_upload Allow encrypted secrets to be uploaded to the n0s1 backend (default: false)

Pass wait_minutes to analyze_report (or directly on a scan tool alongside ai_analysis) to block until analysis completes.

Environment Variables

Credentials can be passed as tool arguments or pre-set as environment variables:

Variable Used by
N0S1_TOKEN All scan tools with ai_analysis — Professional mode uploads and AI analysis
JIRA_TOKEN scan_jira, scan_confluence
JIRA_EMAIL scan_jira, scan_confluence
SLACK_TOKEN scan_slack
GITHUB_TOKEN scan_github
GITLAB_TOKEN scan_gitlab
ZENDESK_TOKEN scan_zendesk
ZENDESK_EMAIL scan_zendesk
LINEAR_TOKEN scan_linear
ASANA_TOKEN scan_asana
WRIKE_TOKEN scan_wrike

Example with env vars pre-configured:

{
  "mcpServers": {
    "n0s1": {
      "command": "uvx",
      "args": ["n0s1-mcp"],
      "env": {
        "GITHUB_TOKEN": "ghp_...",
        "JIRA_TOKEN": "ATATT..."
      }
    }
  }
}

Usage Examples

Once connected, ask your AI assistant:

  • "Scan my Jira project SEC for leaked secrets"
  • "Check the GitHub org mycompany for exposed API keys"
  • "Scan the /home/user/project directory for secrets"
  • "Run an AI analysis on the scan report abc123"

For full parameter reference and AI analysis workflow details, see docs/ai.md.

Publishing to PyPI

pip install hatch
hatch build
hatch publish

License

GNU General Public License v3 — same as n0s1.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

n0s1_mcp-1.1.4.tar.gz (39.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

n0s1_mcp-1.1.4-py3-none-any.whl (32.3 kB view details)

Uploaded Python 3

File details

Details for the file n0s1_mcp-1.1.4.tar.gz.

File metadata

  • Download URL: n0s1_mcp-1.1.4.tar.gz
  • Upload date:
  • Size: 39.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for n0s1_mcp-1.1.4.tar.gz
Algorithm Hash digest
SHA256 1be450ff35492a400d1b14b1df947707eca3bca8dbfd7ed1ac9c19d10226687e
MD5 e8175bdf680c7ff240236109ad2e9f99
BLAKE2b-256 8e41f971f4a9106c6cf213d9e757b9b566745faa731d11343d49bba0df150aaf

See more details on using hashes here.

Provenance

The following attestation bundles were made for n0s1_mcp-1.1.4.tar.gz:

Publisher: publish.yml on spark1security/n0s1-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file n0s1_mcp-1.1.4-py3-none-any.whl.

File metadata

  • Download URL: n0s1_mcp-1.1.4-py3-none-any.whl
  • Upload date:
  • Size: 32.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for n0s1_mcp-1.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 bf332327c2930841e1d0092215d149084dfc2723a81e7e988eced380f4110f83
MD5 3d5e3037228129487aefb7ba7617586d
BLAKE2b-256 45bb11e5a24d55f5b39201dcb189edffaad6eb3aadd539194d48634c4cc74364

See more details on using hashes here.

Provenance

The following attestation bundles were made for n0s1_mcp-1.1.4-py3-none-any.whl:

Publisher: publish.yml on spark1security/n0s1-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page