# GitGuardian MCP for AI Agents AI Agent Connect

> GitGuardian lets you manage secret incidents, deploy honeytokens, and audit workspace security directly through your AI agent. It handles the heavy lifting of secret detection and incident response so you can stay focused on shipping code. Stop jumping between dashboards to find leaked keys or manage team access.

## Overview
- **Category:** fort-knox
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_NQtV8WXJZTZDwZLKUu4JIzBlR9PvO6RL6VjurLD6/ai-agent-connect
- **Tags:** secret-detection, vulnerability-scanning, incident-response, cybersecurity, honeytokens, code-security

## Description

Most security teams spend their days chasing ghosts in logs or frantically triaging leaked API keys. When a secret gets pushed to a public repo, the clock starts ticking. You need to know exactly what happened, who's involved, and how to shut it down before someone exploits it. GitGuardian changes that by bringing your entire security posture into your daily workspace. Instead of hunting for information in a separate dashboard, you can just ask your agent to find active incidents or tell it to create a decoy credential to catch intruders. It makes your AI act like a dedicated security operations center assistant that never sleeps. You'll find that managing your security becomes a conversation rather than a chore. Because Vinkius hosts this Connector, you get a reliable bridge that connects your workspace to your preferred tools. You can triage alerts, manage team permissions, and keep your infrastructure safe without ever leaving your IDE or chat window. It’s about making security a part of your workflow, not a hurdle to it. You can handle everything from identifying high-risk leaks to managing the specific permissions of your security teams, all while keeping your focus on the code you need to write. It turns a reactive, stressful process into a proactive, managed one.

## Tools

### get_secret_incident
Retrieve detailed information about a specific secret incident. Use this to get the full context of a leak.

### get_self_api_token
Retrieve the details of your current API token. This helps you manage your own credentials for the Connector.

### list_sources
List all sources currently being monitored for secrets. Use this to see the scope of your security coverage.

### list_team_memberships
List team members to see who belongs to which security groups. This helps with auditing internal permissions.

### resolve_secret_incident
Resolve a secret incident to clear it from your active alert list. Use this once a leak has been fixed.

### revoke_honeytoken
Revoke a honeytoken to remove it from your environment. Use this if a decoy is no longer needed or is compromised.

### ignore_secret_incident
Ignore a secret incident if it's a false positive or already handled. This keeps your active alert list clean.

### list_api_tokens
List all active API tokens for your workspace. Use this to audit who has access to your GitGuardian account.

### list_audit_log_event_names
List all existing event names for your audit logs. This helps you understand what actions can be tracked.

### list_audit_logs
List audit logs for your workspace to monitor recent activity. This is essential for compliance and security audits.

### list_custom_tags
List all custom tags currently in use. Use this to see how your incidents are being organized.

### list_health_check_history
List health check history for a specific instance. This helps identify any recurring connectivity issues.

### list_health_checks
List all current health checks for your workspace. Use this to monitor the status of your security instances.

### list_honeytoken_events
List all honeytoken events to see when decoys were triggered. This provides a timeline of unauthorized access attempts.

### list_honeytoken_notes
List honeytoken notes to see context for your decoys. This helps your team understand the purpose of different traps.

### list_honeytoken_sources
List sources where specific honeytokens appear. Use this to track where your decoys are being deployed.

### list_honeytokens
List all honeytokens in your workspace. This gives you a full overview of your active decoy credentials.

### list_ips
List the IP addresses for the provider to help with firewall configuration. Use this to whitelist the necessary traffic.

### list_members
List all members of your workspace. Use this to verify who has access to your security tools.

### list_scim_groups
List groups via SCIM for automated user management. This helps with large-scale organization syncing.

### list_scim_users
List members via SCIM to keep user access in sync. Use this for automated provisioning and deprovisioning.

### list_secret_incidents
List all secret incidents to see what needs attention. This is your primary way to view active security leaks.

### list_teams
List all teams in your organization. Use this to manage your security department's structure.

### multiscan_content
Scan multiple pieces of content at once for secrets to save time. This is great for checking multiple files quickly.

### reset_honeytoken
Reset a honeytoken to its original state after it's been triggered. This allows you to keep using the same decoy.

### revoke_self_api_token
Revoke your current API token immediately if it's compromised. This is a critical safety feature for your account.

### scan_and_create_incidents
Scan content and automatically create incidents for any secrets found. This automates the discovery and logging process.

### scan_content
Scan a specific piece of content for secrets and sensitive data. Use this to check code snippets before they go live.

### create_honeytoken
Create a new honeytoken to act as a decoy for unauthorized access. This is a core defense for your private infrastructure.

### create_honeytoken_with_context
Create a honeytoken within a specific context for better tracking. This allows for more granular decoy management.

### create_team
Create a new team to organize security operations and permissions. Use this to structure your organization's security roles.

### delete_custom_tag
Delete a custom tag that is no longer needed for your workflow. Keep your workspace metadata clean and relevant.

### delete_custom_tags_key
Delete a custom tags key to clean up your workspace metadata. This helps manage your organizational taxonomy.

### get_custom_tag
Retrieve a custom tag to check its details or status. Use this to verify how specific incidents are categorized.

### get_health
Check the current API health status to ensure your connection is active. This is a quick way to verify your setup.

### get_honeytoken
Retrieve a specific honeytoken to see its current status. This helps you monitor which decoys are being targeted.

### get_quotas
Retrieve a quota overview to monitor your usage limits. Stay on top of your account's capacity and limits.

### assign_secret_incident
Assign a specific secret incident to a team member for faster remediation. This helps keep your triage workflow organized.

### bulk_prefix_lookup
Perform a bulk lookup for honeytoken HMSL hashes to identify compromised decoys. Use this to quickly audit multiple entries.

### create_custom_tag
Create a custom tag to organize and filter your security incidents. This helps group similar types of leaks together.

### create_honeytoken_note
Create a note for a honeytoken to provide extra context on its purpose. This is useful for keeping your team informed.

### list_ip_allowlist
List IP allowlist rules to manage access to your workspace. This is key for securing your administrative access.

### trigger_health_check
Trigger a manual health check to verify your workspace connection. Use this to test your setup on demand.

### trigger_source_scans
Trigger new scans on your sources to find recent leaks. Use this to manually refresh your security data.

### update_custom_tag_full
Perform a full update on a custom tag's metadata. This helps you refine how you categorize security incidents.

### update_custom_tag_partial
Perform a partial update on a custom tag. Use this to quickly change a single piece of tag information.

### update_custom_tags_key
Update a custom tags key to reflect new organizational rules. This keeps your metadata in sync with company policy.

### update_honeytoken
Update a honeytoken's configuration or details. Use this to modify your decoys without creating new ones.

### update_secret_incident
Update a secret incident with new details or status. This helps keep your incident records accurate and current.

## Prompt Examples

**Prompt:** 
```
List the most recent secret incidents in my workspace.
```

**Response:** 
```
I've retrieved the latest incidents for you. Here is the current status:

| Severity | Incident Type | Source | Status |
| :--- | :--- | :--- | :--- |
| **High** | GitHub Personal Access Token | `web-app` | Open |
| **Medium** | AWS Keys | `legacy-service` | Open |
| **Medium** | AWS Keys | `staging-bucket` | Open |

Would you like me to assign one of these to a team member or get more details?
```

**Prompt:** 
```
Create a new AWS honeytoken named 'Internal-Dev-Decoy'.
```

**Response:** 
```
Successfully created the honeytoken **Internal-Dev-Decoy**. 

**Details:**
- **AWS Access Key ID:** `AKIA...` 
- **Secret Key:** Provided in the metadata.
- **Status:** Active

You can now place this in your environment to detect intruders. Would you like me to add a note to this decoy?
```

**Prompt:** 
```
Scan this code for secrets: 'const apiKey = "sk_live_51MzX..."'
```

**Response:** 
```
Scan complete. I detected a **Stripe Live Secret Key** in the provided string.

**Finding Details:**
- **Severity:** High
- **Type:** Production Secret

I recommend rotating this key immediately and removing it from your source code. Would you like me to create an incident for this?
```

## Capabilities

### Triage secret incidents
Identify, assign, and resolve security leaks using natural language.

### Deploy honeytokens
Create decoy credentials to detect unauthorized access to your infrastructure.

### Scan code for secrets
Check code snippets in real-time to prevent sensitive data from being committed.

### Audit workspace logs
Monitor activity logs to ensure your team stays compliant with security policies.

### Manage security teams
Organize members and permissions for your security operations.

## Use Cases

### Fast-tracking incident remediation
A security engineer needs to find all active leaks. They ask the agent to list secret incidents and then use `assign_secret_incident` to give them to the right developer.

### Checking code for hardcoded keys
A developer wants to check a snippet before a commit. They paste it and the agent uses `scan_content` to confirm there are no secrets.

### Setting up decoy credentials
A DevOps lead wants to set up decoys. They ask the agent to `create_honeytoken` for an AWS environment to monitor for intruders.

### Verifying workspace connectivity
An admin needs to check health. They ask the agent to `get_health` to make sure the connection is solid before a big audit.

## Benefits

- Triage alerts faster by using `list_secret_incidents` to see every active leak in one place without switching tabs.
- Deploy decoys instantly with `create_honeytoken` to catch unauthorized access before it causes real damage.
- Prevent leaks before they happen by using `scan_content` to check code snippets directly in your IDE.
- Audit your workspace easily with `list_audit_logs` to ensure your team stays compliant with security policies.
- Manage team access with `list_members` and `create_team` to keep your security operations organized and secure.

## How It Works

The bottom line is you get a hands-on security assistant that handles the grunt work of secret management.

1. Subscribe to the Connector and grab your API key from the GitGuardian dashboard.
2. Plug that key into your AI client settings to establish the connection.
3. Start asking your agent to list incidents, scan code, or deploy decoys.

## Frequently Asked Questions

**Can GitGuardian MCP help me find leaked keys?**
Yes, it lets your AI agent list all active secret incidents in your workspace so you can see what needs attention immediately.

**How do I use GitGuardian MCP for honeytokens?**
You can ask your agent to create decoys that alert you when someone tries to use them, helping you catch intruders early.

**Does GitGuardian MCP support team management?**
Yes, it lets you manage members and teams to organize how your organization handles security and incident response.

**Can I scan code for secrets with GitGuardian MCP?**
You can ask your agent to scan specific code snippets or content for sensitive data before you commit them to your repository.

**Is GitGuardian MCP good for audit logs?**
It allows you to retrieve workspace activity logs to ensure your team stays compliant with your internal security policies.

**How does GitGuardian MCP handle secret incidents?**
Your agent can list, retrieve, and resolve incidents, making it much easier to triage high-priority leaks without leaving your workflow.

**Can I resolve a secret incident directly through the AI?**
Yes. You can use the `resolve_secret_incident` tool by providing the incident ID. You can also use `assign_secret_incident` to delegate the fix to a specific team member.

**How do I create a decoy credential to catch attackers?**
Use the `create_honeytoken` tool. You can specify the type and name of the honeytoken, and GitGuardian will generate a decoy that alerts you if it's ever used.

**Is it possible to scan a text block for secrets before I commit it?**
Absolutely. Use the `scan_content` tool. Provide the document content and a filename, and the AI will return any detected secrets or policy violations found by GitGuardian's engine.