NG-Bullseye

LLM Secret Manager — AI skill for Claude Code

AI community

The secret manager for LLM agents: create, rotate, and use secrets they can never read.

How to install LLM Secret Manager

This entry records only its repository, not the path inside it, so there is no exact command to give. Open NG-Bullseye/llm-secret-manager and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What LLM Secret Manager does

The secret manager for LLM agents: create, rotate, and use secrets they can never read. OS-native keyvault (macOS Keychain) + zero-dependency MCP server + Claude Code guard hook. No get verb, by design.

Alternatives in AI

  • WindsurfAPI — Turn Windsurf / Devin Desktop's 100+ AI models (Claude, GPT, Gemini, DeepSeek, Kimi, GLM, SWE) into OpenAI-, A 3k ★
  • Nodeterm — Node-based terminal manager for AI coding agents — tmux-backed terminals and parallel agent sessions as dragga 1.3k ★
  • Hol Guard — Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, M 485 ★

README

llm-secret-manager

**The secret manager for LLM agents: they can create, rotate, and use your secrets — without ever being able to read them.**

[![License: MIT](https://img.shields.io/badge/license-MIT-green.svg)](LICENSE) [![Python ≥ 3.9, stdlib only](https://img.shields.io/badge/python-%E2%89%A5%203.9%20%C2%B7%20zero%20deps-blue.svg)](mcp/nv-mcp.py) [![macOS Keychain](https://img.shields.io/badge/backend-macOS%20Keychain-black.svg)](bin/nv) [![MCP](https://img.shields.io/badge/protocol-MCP-purple.svg)](https://modelcontextprotocol.io)

LLM agents are great at ops work — deploying, rotating credentials, wiring up services. But every secret that enters an agent's context lives on in transcripts, logs, and telemetry you don't control. The usual fix is "be careful". This is a better fix: **make it impossible.**

`llm-secret-manager` turns your OS keyvault into something an agent operates **like an HSM**: it can order secrets into existence, rotate them, and run programs with them — but there is *no operation that returns a secret*. Not to the agent, not to a log, not "just for debugging". Three layers, use any or all: the **`nv` CLI**, a zero-dependency **MCP server**, and a Claude Code **guard hook** that blocks commands which would print a secret.

you      $ claude "create a DB password and run the migration with it"

agent    → secret_generate("db-password")        ⇒ ok, length 32   (value never seen)
agent    → secret_run(["python","manage.py","migrate"],
                      env={"DB_PASSWORD": "db-password"})
                                                 ⇒ exit 0          (value went kernel → process env)

you      $ nv run DB_PASSWORD=db-password -- psql   # same reference, your shell

Why you can trust it (hint: you don't have to)

There is nothing here *to* trust. No custom crypto, no storage format, no server state, no dependencies. Storage, encryption, locking, and session binding are the **OS keyvault's own** (macOS login Keychain).