General skillSecurity and privacy

blind-vault

Use macOS Keychain secrets without placing their values in agent context

Stars
0
Forks
0
License
MIT
Updated
Updated Jul 10, 2026

Checking live repository facts…

Project overview

blind-vault is a macOS-only local secret tool that stores credentials in Keychain and exposes only pointer metadata such as names, scopes, and dates to the agent. Its CLI injects a value into a child-process environment without printing it, and scope checks can block mismatched commands. It keeps secrets out of chats, files, and ordinary tool output, but it is not an HSM and does not protect against malware running as the same user, brief process observation, or clipboard sniffing.

Repository facts

Primary language
Python
License
MIT
Repository updated
Jul 10, 2026
Default branch
main

Resource types

General skill

Use cases

Security and privacyDevOps and deployment

Platforms

Claude Code, Codex, and more

Runtime

Command lineDesktopLocal

Capabilities

Security guardrailTool use

Audience

Developers

Related projects

Browse more similar projects