hushsecrets your AI agent can use but never readGitHub

What hush does not do

Read SECURITY.md before trusting it with anything real, and docs/SAFETY.md for which of it matters in your situation — alone, with an agent, or as a team. The most important line in both: with a software identity, anything running as your user can invoke hush and read the vault — including a shell command from an agent. The policy gates hush's own tools and CLI; it cannot gate a process that goes around hush, and policy.json is a file in your repo that an agent with write access can loosen. Use a hardware identity if that matters to you.