LeakRank Guard
LeakRank Guard plugs continuous secret scanning into the coding agent you already use: Claude Code, Cursor, Codex or Windsurf. After your agent finishes a change, it calls guard_scan_diff. Guard collects the changed files from your git working tree, sends them to the LeakRank scanning service over an authenticated HTTPS API, runs a static pass followed by an LLM triage pass, and returns the findings: severity, file and line, masked evidence, a fix summary, a unified diff your agent can apply, and the exact secrets that need rotating. Analysis runs on LeakRank's servers and LeakRank's own model budget, so it never spends your agent's tokens. npx leakrank-guard init detects your agents, registers the MCP server, and drops a rules file so scanning becomes part of the agent's normal loop rather than a step you have to remember. The same CLI runs headless in CI with scan --fail-on high --json. Guard is not a penetration test and does not make an application secure. It finds one specific, expensive class of mistake: credentials and risky configuration committed into code. Requires Node.js 18+, a git repository, and a LeakRank Guard subscription.
First seen 2 Oct 2026. Evidence as of 5 Oct 2026.
Tools
No tool list captured yet.
Change history
No changes since the first observation. The first snapshot is the baseline.
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Smithery | leakrank/leakrank-guard | 2 Oct 2026 | 5 Oct 2026 | 1 |