{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=dotisacat/mcp-config-secrets-audit@0.1.0","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/dotisacat/mcp-config-secrets-audit@0.1.0","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/dotisacat/mcp-config-secrets-audit@0.1.0","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/dotisacat/mcp-config-secrets-audit@0.1.0 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"mcp-context-tax (already published, ours) MEASURES the token cost of what your MCP servers advertise; mcp-doctor (already published, ours) DIAGNOSES their health -- this completes the trilogy: mcp-config-secrets-audit reports SECRET POSTURE across the exact same discovered configs, never cost, never health, never a value. Three jobs, in order: (1) reads the same fixed, well-known set of harness-owned config files its siblings already read (Claude Code global + per-project mcpServers, Claude Desktop, Cursor, Codex config.toml mcp_servers tables -- incl. a narrow TOML fallback reader for interpreters without stdlib tomllib -- Windsurf; never a filesystem walk for a stray project .mcp.json) and classifies EVERY env var value each declared server carries by SHAPE, at the exact moment it is read off disk and before anything is packed into this play's own inter-step data or printed anywhere: a literal secret-shape (an OpenAI-style sk- key, a GitHub ghp_ token, an AWS AKIA access key id, a JWT, or a 40+ character hi","distribution":{"digest":"sha256:8cd0ed40ea914ec48e620089655547d0947b5a86ad48305b2edb39792441e8b3","mediaType":"application/vnd.modiqo.rote-flow","size":30239,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/dotisacat/mcp-config-secrets-audit@0.1.0","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/dotisacat/mcp-config-secrets-audit@0.1.0","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/dotisacat/mcp-config-secrets-audit@0.1.0.json"},"name":"mcp-config-secrets-audit","owner":{"kind":"user","slug":"dotisacat"},"parameters":[{"default":0,"description":"(0-1) include a per-entry detail row for every env var examined, not only the secret-shaped ones","example":0,"input":{"allowCustom":true,"choices":[],"label":"Verbose"},"name":"verbose","required":false,"type":"integer"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/dotisacat/mcp-config-secrets-audit@0.1.0 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/dotisacat/mcp-config-secrets-audit@0.1.0","headlessCommandTemplate":"rote play run https://play.modiqo.ai/dotisacat/mcp-config-secrets-audit@0.1.0 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.77.0"},"publishedAt":"2026-09-02T21:19:08.674506+00:00","reference":"dotisacat/mcp-config-secrets-audit@0.1.0","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"localTools":["python3"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":2,"installs":0},"steps":{"count":2,"names":["audit","discover_configs"]},"title":"mcp-config-secrets-audit","type":"play","version":"0.1.0","visibility":"public"}