Sensitive Data Exposure Detector

Sensitive Data Exposure Detector MCP Connector for Claude

A+

Intercepts and redacts sensitive information from file reads and tool outputs.

3 tools Official Updated Oct 1, 2026 Official Vinkius Partner

This MCP server acts as a security layer that intercepts, analyzes, and redacts sensitive information from file reads and tool outputs before they enter the LLM context. It uses deterministic regex patterns to detect AWS keys, GitHub tokens, private keys, database connection strings, and JWTs. It also identifies high-entropy strings using Shannon entropy calculation. By using scan_content, users can clean raw text, while get_redaction_audit provides a traceable history of all redactions. The validate_safety_threshold tool allows for automated security enforcement based on exposure risk scores.

securityredactionprivacyregexentropy

3 tools expose this connector's capabilities to your AI agent.

validate_safety_threshold

Checks if risk meets a threshold

get_redaction_audit

Retrieves the history of redactions

scan_content

Analyzes a raw string for sensitive information

See how to talk to your AI agent using Sensitive Data Exposure Detector.

Scan this text for secrets: AKIAIOSFODNN7EXAMPLE

The content contains a sensitive AWS key: [REDACTED_AWS:AKIA...XPLE]

Check if this content is safe to use with a threshold of 0.5

The content is not allowed because the exposure risk score exceeds the threshold.

Show me the recent redaction logs.

The recent redaction logs show 2 events: one AWS key redaction and one GitHub token redaction.

The `scan_content` tool identifies sensitive patterns and replaces them with a placeholder in the format `[REDACTED_TYPE:prefix4...suffix4]`. This allows for debugging without exposing the actual secret.

Related Connectors