hushsecrets your AI agent can use but never readGitHub

How safe is this for me?

hush works at every level of care, including the lowest, and it never blocks you to make you climb. That is deliberate — a tool that refuses to run until you buy a hardware key gets uninstalled, and the plaintext .env comes back. The cost of that choice is that you have to know which situation you are in and what it needs. This page is that, in three situations. Find yours.

The one sentence that applies to all three: with a software identity, anything running as you can read the vault. Your private key sits in the OS keychain (or ~/.hush/identity); any process you run — including a shell command an AI agent runs — can retrieve it the same way hush does and decrypt everything. Policies and approval prompts constrain hush. They cannot constrain a process that goes around hush. Only a hardware identity (rung 5) changes what is cryptographically possible. Everything below is honest about where that line falls.


1. Just me, no AI agent

What you get for free

Turn on: nothing. This is rung 1. hush secure will offer rung 2 (key in the OS keychain instead of a loose file) — take it; it costs nothing.

What it does not protect against


2. Me and an AI agent

This is what hush is for. The agent gets tools that can use a secret and no tool that returns one.

What you get

Turn on

Understand


3. A team

What you get

Turn on

Understand


The ladder

rungwhat it gives youhow
1secrets are encrypted at rest; no plaintext .env in the projecthush init, hush add .env --as …, delete the file
2your key is in the OS keychain, not a loose filehush secure
3using a credential needs your approval, and your own floor keeps it onanswer yes to the agent question, or hush secure
4approval needs your fingerprint, not a clickhush biometry setup, "biometry": "required"
5your key cannot be copied off this machinehush age with a hardware plugin

hush level shows where you are and the one command for the next rung. The rung is a strict checklist: a later check never lifts you past an earlier gap.


What has been tried against it

docs/RED-TEAM.md is the log of an adversarial pass over every surface hush exposes — what got a value out (and was fixed), what could not, and what is accepted and why. Read it before deciding how much to trust the prompts.

Where hush stops

SECURITY.md is the full threat model and how to report a problem privately.