AgentSecure Community
By ShellFrame AI
AgentSecure lets AI coding agents use credentials without exposing the real secret values to the agent.
Why AgentSecure
AI coding agents can access .env files, shell environments, MCP
configuration, and local credentials. Ignore files are not a security boundary.
AgentSecure keeps real secrets outside the agent's normal project and MCP
context.
Quick Start
Run these commands from the project you want to protect.
1. Install AgentSecure
uv tool install agentsecure
2. Optionally scan the project
agentsecure scan .
The scan is local and does not change the project.
3. Run guided setup once
For Claude Code:
agentsecure start --client claude
Follow the printed MCP configuration step, then start Claude Code normally:
claude
For Codex:
agentsecure start --client codex --install-mcp
Then start Codex normally:
codex
agentsecure start is guided one-time project setup. It initializes the
project, offers to move .env secrets into the local vault, writes persistent
agent guidance, and prints or installs the selected MCP configuration.
It is not a persistent background service. After setup finishes, start Claude
Code or Codex normally. You do not normally wrap the agent with
agentsecure run.
How It Works
- During setup, real secrets are moved into the local AgentSecure vault.
- Project files receive aliases or safe placeholders instead of real values.
- The coding agent starts and runs normally.
- Secret-bearing requests use the AgentSecure MCP tool.
- AgentSecure validates the destination and injects the real secret while sending the request outside the agent's context.
Security Boundaries
AgentSecure helps protect against:
- exposing raw secrets to the coding agent through the default MCP flow;
- keeping real secrets in agent-readable project files;
- sending protected secrets to destinations that are not approved by policy.
AgentSecure is not:
- a complete operating-system sandbox;
- a VM or container;
- protection from an attacker who already controls the local user or machine;
- a replacement for endpoint, identity, network, or cloud security controls.
The local user and machine remain inside the trust boundary. See the security model and limitations for the full threat model.
Documentation
- Default workflow
- Claude Code setup
- Codex setup
- Secret management
- MCP usage
- Network policy
- Security model and limitations
- Vault and backup behavior
- Scanner reference
- Advanced runtime mode
- CLI reference
- Implementation architecture
- Uninstall and restore
License
Licensed under the Apache License 2.0. See LICENSE.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file agentsecure-0.1.23.tar.gz.
File metadata
- Download URL: agentsecure-0.1.23.tar.gz
- Upload date:
- Size: 139.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
80342478c7d6ae45af14e4d54328ad9515bfbde25652c537c76a08c64153f790
|
|
| MD5 |
fdba26d9621360fb32f94d185396fdee
|
|
| BLAKE2b-256 |
393984d3ff11c181fc53835642931c1b3e888becbb447a81847192f14343bf94
|
Provenance
The following attestation bundles were made for agentsecure-0.1.23.tar.gz:
Publisher:
publish-pypi.yml on ShellFrameAI/agentsecure-community
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
agentsecure-0.1.23.tar.gz -
Subject digest:
80342478c7d6ae45af14e4d54328ad9515bfbde25652c537c76a08c64153f790 - Sigstore transparency entry: 2300042984
- Sigstore integration time:
-
Permalink:
ShellFrameAI/agentsecure-community@e2338b5d48dbbdf17eb9264d31419e6022f2cdf9 -
Branch / Tag:
refs/tags/v0.1.23 - Owner: https://github.com/ShellFrameAI
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@e2338b5d48dbbdf17eb9264d31419e6022f2cdf9 -
Trigger Event:
release
-
Statement type:
File details
Details for the file agentsecure-0.1.23-py3-none-any.whl.
File metadata
- Download URL: agentsecure-0.1.23-py3-none-any.whl
- Upload date:
- Size: 141.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
cda330241d616d91d40b3d331dc1ca2225adf2c871e9ea0361ced58d48ad9fef
|
|
| MD5 |
56427f2bd1fc97ab62aceee5e9eda38b
|
|
| BLAKE2b-256 |
b6c8cfe528ea04245bafe28b68f9a675f9cbb5c7c101205f72c3e9a037ac00c9
|
Provenance
The following attestation bundles were made for agentsecure-0.1.23-py3-none-any.whl:
Publisher:
publish-pypi.yml on ShellFrameAI/agentsecure-community
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
agentsecure-0.1.23-py3-none-any.whl -
Subject digest:
cda330241d616d91d40b3d331dc1ca2225adf2c871e9ea0361ced58d48ad9fef - Sigstore transparency entry: 2300043048
- Sigstore integration time:
-
Permalink:
ShellFrameAI/agentsecure-community@e2338b5d48dbbdf17eb9264d31419e6022f2cdf9 -
Branch / Tag:
refs/tags/v0.1.23 - Owner: https://github.com/ShellFrameAI
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@e2338b5d48dbbdf17eb9264d31419e6022f2cdf9 -
Trigger Event:
release
-
Statement type: