Observed arrival · 2026-10-06
hush: encrypted secrets for AI coding agents
A command-line tool stores team secrets in an encrypted repository vault and injects them into a chosen process without exposing them as readable files.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Teams using AI coding agents with repository secrets
- Worth noticing
- Installers verify release SHA-256 sums and can check GitHub build-provenance attestations; the project has not had an external security review.
Field notes
The documented workflow keeps the vault in the repository, then supplies secrets to a launched process rather than exposing them as ordinary files. Installation instructions cover macOS, Linux, and Windows, though Windows is marked beta; the page also points to a review-scope document and requests private reports of vulnerabilities.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
One card from the complete issue