Trestle is a Model Context Protocol (MCP) server: Detects leaked secrets (API keys, tokens, private keys) in source code. In practice that means any MCP-compatible AI assistant can call Trestle's tools directly — the model decides when to use them in a conversation or agent run.
It runs locally: the npm package @trestlescan/mcp speaks MCP over stdio on your machine. No credentials are required — it works out of the box. The current release is v1.4.1, published under the Apache-2.0 license, with source at toro-guapo/trestle on GitHub.
Trestle is listed under Development on mcp.site and works with any MCP client — Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Zed and the rest of the ecosystem — using the install snippets below. If you maintain Trestle for trestlescan.com, claim this listing to verify ownership, earn the Verified badge, and keep the details current.