# Trestle (slim) > Trestle, an MCP server by trestlescan.com, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. Detects leaked secrets (API keys, tokens, private keys) in source code. - Full: https://www.anchorterminal.com/tools/trestlescan-trestle.md (~450 tokens) · this version ~380 tokens · JSON https://www.anchorterminal.com/tools/trestlescan-trestle.json · canonical https://www.anchorterminal.com/tools/trestlescan-trestle - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 # Trestle > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by trestlescan.com (https://trestlescan.com) - Category: Secrets & credential vaults (https://www.anchorterminal.com/categories/secrets.md) - Listed because: It's published in the registry under trestlescan.com, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: Detects leaked secrets (API keys, tokens, private keys) in source code. ## Facts - MCP registry: `com.trestlescan/trestle` 1.4.1 - Package: npm `@trestlescan/mcp` (stdio) - Source: https://github.com/toro-guapo/trestle - Website: https://trestlescan.com - npm downloads a week: 39 - GitHub stars: 2 - Registry entry updated: 2026-06-29 - JSON: https://www.anchorterminal.com/api/v1/tools/trestlescan-trestle.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming