Skip to main content
Getly

Authentication & Security Tools

Security Posture Auditor

Find the secret you already shipped before somebody else does.

$39.00

Product Description

# Security Posture Auditor Find the secret you already shipped before somebody else does. | | | | --- | --- | | Version | 1.0.0 | | Price | 39 USD | | Licence | Single-seat | | Entry point | `server.py` | | Source | Reimplemented from scratch in English; logic referenced from the local vendor toolkit without modifying it | ## What it does Read-only MCP server that scans repositories for leaked secrets, checks role permissions, audits URLs against SSRF rules, and reports a wallet read-only posture. ## Tools | Tool | Description | | --- | --- | | `scan_secrets` | Scan a directory tree for API keys, private keys and credentials. Returns redacted findings. | | `check_permissions` | Compare declared role permissions against a least-privilege policy. | | `ssrf_audit` | Audit URLs against a policy that denies private, loopback and link-local targets. | | `read_only_report` | Report the read-only posture of a directory and an optional permissions manifest. | ## Network No outbound network requests. ## Security - Read-only: no file is written and no process is started. - Findings are redacted before they are returned. - Paths are confined to the root you pass. ## Requirements - Python 3.10 or above - No account, no API key, no telemetry ## Agent Skills | Skill | Purpose | | --- | --- | | `pre-publish-security-gate` | Run the leak and permission checks before anything is published. | ## Tests ```bash python -m pytest -q # suite tests for this server ``` Every security claim above names a test that exists: - `test_path_traversal_blocked` - `test_no_subprocess_spawn` - `test_placeholder_is_not_a_finding` ## Licence and exclusions - Single-seat licence unless a team licence is stated above. - No shell execution, no browser or account automation, no key custody. - The exclusion list is published in `security/EXCLUSIONS.md` in the team bundle so a reviewer can check it independently.

What you get

1 file · 207.15 KB

  • security-posture_v1.zipZIP · 207.15 KB
LicencePersonal use only
PublishedOct 2, 2026
File size207.15 KB
File formatZIP
Versionv1.0

Tags

security auditsecret scannermcp serverleaked credentialsssrfread-only mcpai agent securitypermission review
O
OllamaExperts

Frequently asked questions

Do I get access instantly?

Yes. This is a digital product - you can download it right after checkout, straight from your library.

Can I use it for commercial projects?

Personal use only. Use it for yourself - not in work you sell or hand to a client - and do not resell or redistribute the file.

What's your refund policy?

You're covered by a 30-day money-back guarantee. If something isn't right, request a refund from your order and the Getly team reviews it.

What file formats and sizes will I get?

You'll download 1 file - ZIP - 207.15 KB in total.

Do I get free updates?

Yes - when the seller ships a new version, you can re-download the latest files from your library at no extra cost. Check the changelog for recent updates.

Price

$39.00