hushsecrets your AI agent can use but never readGitHub

CI

Give CI an identity of its own that reads only what the jobs need:

hush ci create github --sets ci,staging | gh secret set HUSH_IDENTITY
git commit -am "CI can read ci and staging"

Piped, it prints the private key alone, straight into the secret store, and keeps it nowhere. A CI identity is a scoped member marked as a machine: never an admin, never able to sign, and hush ci rm github rotates only the sets it could read.

In GitHub Actions:

- uses: omarei-omoto/hush@v1
  with:
    identity: ${{ secrets.HUSH_IDENTITY }}
    version: 1.0.0
- run: hush run -- npm test

The action masks the identity, installs the hush binary for the runner — no Node needed; the sha256 and the build-provenance attestation are checked before it runs (install: npm uses the npm package instead) — and checks the identity can read the vault before any later step needs it. In a job, hush run also has GitHub mask every injected value line by line, so GitHub's own log redaction applies on top of hush's — only for a CI identity, so an agent on a laptop setting GITHUB_ACTIONS itself gets nothing printed. Anywhere else, HUSH_IDENTITY=… hush run -- npm test works the same way.