Trestle
Detects leaked secrets (API keys, tokens, private keys) in source code.
Install
npmstdio
npx -y @trestlescan/mcp Client config (Claude Desktop, Cursor, Windsurf and most MCP clients)
{
"mcpServers": {
"com-trestlescan-trestle": {
"command": "npx",
"args": [
"-y",
"@trestlescan/mcp"
]
}
}
} Source: official MCP Registry record · registry name com.trestlescan/trestle · published 2026-06-29 · updated 2026-06-29. Not an endorsement; review the code before connecting it to anything sensitive.