LLM Secret Manager — AI skill for Claude Code
The secret manager for LLM agents: create, rotate, and use secrets they can never read.
How to install LLM Secret Manager
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open NG-Bullseye/llm-secret-manager and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What LLM Secret Manager does
The secret manager for LLM agents: create, rotate, and use secrets they can never read. OS-native keyvault (macOS Keychain) + zero-dependency MCP server + Claude Code guard hook. No get verb, by design.
Alternatives in AI
- WindsurfAPI — Turn Windsurf / Devin Desktop's 100+ AI models (Claude, GPT, Gemini, DeepSeek, Kimi, GLM, SWE) into OpenAI-, A 3k ★
- Nodeterm — Node-based terminal manager for AI coding agents — tmux-backed terminals and parallel agent sessions as dragga 1.3k ★
- Hol Guard — Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, M 485 ★
README
llm-secret-manager
**The secret manager for LLM agents: they can create, rotate, and use your secrets — without ever being able to read them.**
[](LICENSE) [](mcp/nv-mcp.py) [](bin/nv) [](https://modelcontextprotocol.io)
LLM agents are great at ops work — deploying, rotating credentials, wiring up services. But every secret that enters an agent's context lives on in transcripts, logs, and telemetry you don't control. The usual fix is "be careful". This is a better fix: **make it impossible.**
`llm-secret-manager` turns your OS keyvault into something an agent operates **like an HSM**: it can order secrets into existence, rotate them, and run programs with them — but there is *no operation that returns a secret*. Not to the agent, not to a log, not "just for debugging". Three layers, use any or all: the **`nv` CLI**, a zero-dependency **MCP server**, and a Claude Code **guard hook** that blocks commands which would print a secret.
you $ claude "create a DB password and run the migration with it"
agent → secret_generate("db-password") ⇒ ok, length 32 (value never seen)
agent → secret_run(["python","manage.py","migrate"],
env={"DB_PASSWORD": "db-password"})
⇒ exit 0 (value went kernel → process env)
you $ nv run DB_PASSWORD=db-password -- psql # same reference, your shell
Why you can trust it (hint: you don't have to)
There is nothing here *to* trust. No custom crypto, no storage format, no server state, no dependencies. Storage, encryption, locking, and session binding are the **OS keyvault's own** (macOS login Keychain).
Related Skills
CoalGob
Recoverable-delete guard for AI coding agents - BETA, classifier only: a pure zero-dependency parser that read
Hush
a secret store for ai agents with one rule: the agent never sees the plaintext. get a secret once into the os
Aigate
AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs
Secretctl
The simplest AI-ready secrets manager. Local-first, single-binary CLI & Desktop app with MCP integration. Neve
AI Secret Scout
Zero-dependency heuristic secret scanner & redaction tool for AI coding assistant histories (Claude Code, Anti
Agent Beacon
🛰️ Real-time presence & collision-avoidance for parallel AI coding agents. See what every Claude Code / MCP a
Related Agents
Byok Token Security Expert
BYOK (Bring-Your-Own-Key) and OAuth token security expert. Deep on cross-platform OS keychain integration (mac
Secret Guard
MUST be used whenever the user asks to scan for secrets, API keys, credentials, or tokens before a commit or i
Sf Security Engineer
Security Engineer of the Software Factory cell. Use to run SAST/dependency/secret scans, verify zero-trust sec