For a BYO-keys tool whose entire pitch is "never leak keys," a secret-scan step is on-brand, cheap, and a trust signal. mcp-warden already runs gitleaks in CI.
Scope
- Add a gitleaks GitHub Action on PRs.
- Config is keys-free by construction, so it should find nothing — this is a guardrail/parity item.
Acceptance
- gitleaks runs on PRs and reports no secrets.
Source: pre-dev planning audit 2026-06-08 (finding C-4).
For a BYO-keys tool whose entire pitch is "never leak keys," a secret-scan step is on-brand, cheap, and a trust signal. mcp-warden already runs gitleaks in CI.
Scope
Acceptance
Source: pre-dev planning audit 2026-06-08 (finding C-4).