JFSecure

io.github.theone55v2.6.1更新于 Oct 11, 2026

Let AI agents use secrets without seeing them: masked output, every use approved in JFSecure.

已验证STDIO仅桌面开发者工具安全与监控

概览

AI 生成的概览

让助手以环境变量或模板值的方式使用已保存的密钥,而不会拿到密钥本身的值。

功能
JFSecure 的 jfs MCP 服务器是一个轻量本地客户端,通过本地管道与正在运行且已解锁的 JFSecure 应用通信。它提供 list_secrets(仅返回名称)、run_with_secrets(以密钥的键作为环境变量运行命令,输出被遮蔽为 [JFSecure: NAME])和 render_template(把 {{Secret:key}} 占位符填入 .env 等文件)。它刻意不提供返回密钥值的工具;每次使用都会在应用中弹出审批窗口,显示程序、确切命令和密钥。
适用场景
当助手需要凭据来认证或运行命令,而你不希望这些值出现在模型上下文、对话记录或日志中时使用。适合用令牌调用 API、生成 .env 文件或使用 Git 凭据助手等场景,并在桌面应用中逐次审批。
运行要求
需要在本地桌面安装 JFSecure 应用(macOS、Windows 或 Linux),并保持保险库已打开且解锁;jfs 命令需在 PATH 中(随应用安装,或通过 Homebrew、.deb、应用设置安装)。以 stdio 方式添加 MCP 服务器,例如命令 jfs、参数 mcp。未声明环境变量、请求头或单独的身份验证。
安装前请注意
批准某条命令即允许其使用密钥,而遮蔽被描述为安全带而非围墙:被批准的命令仍可能把值发送出去,因此批准前请阅读确切命令。审批可仅一次或 15 分钟,且限定于该命令和该密钥。服务器本身不会打开保险库文件,也看不到保险库密码。

安装

在 SourceWeft 中

  1. 打开 控制台中的 JFSecure,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

jfs — secrets for AI agents that never see them

jfs is the command line and MCP server of JFSecure, an offline password and snippet manager. It lets Claude Code, Cursor or any MCP agent use a secret without ever getting it — and you approve every use in the app.

This repository is the source of jfs itself, so you can read exactly what an agent talks to. It is a thin client: it sends one JSON request over a local pipe to the running, unlocked JFSecure app and prints the answer. It never opens vault files, never sees the vault password and has no crypto. (The app is a separate download; jfs ships with it.)

[Claude Code asks, JFSecure shows the exact command, the agent gets the output with the token masked]

MCP tools

ToolWhat it doesWhat the agent gets back
list_secretsLists secret and key names, with the environment variable each key becomesNames only
run_with_secretsRuns a command with a secret's keys as environment variables (all, some, or one on stdin)Exit code and output, every value masked as [JFSecure: NAME]
render_templateFills {{Secret:key}} in a template and writes the file (e.g. .env)Which names were filled in

There is no "get" tool, on purpose. Every use opens an approval window in JFSecure that shows the program, the exact command and the secret: allow once, allow 15 minutes, or deny. For Claude Code a 15-minute approval covers only that command and that secret.

# the agent called run_with_secrets(secret: "github", command: …)exit code 0variables set: TOKEN--- stdout ---token is [JFSecure: TOKEN]{"login": "octocat", "plan": {"name": "pro"}}

Set up

  1. Install JFSecure and open your vault: brew install theone55/jfsecure/jfsecure (macOS), scoop bucket add jfsecure https://github.com/theone55/scoop-jfsecure; scoop install jfsecure/jfsecure (Windows), or the installer (Windows, macOS, Linux). jfs comes with it: on Windows the app puts it on PATH at its first start (open a new terminal afterwards); on macOS (.dmg) and the Linux AppImage use Settings → Install the jfs command; Homebrew and the .deb install it for you.
  2. Add the MCP server:
sh
claude mcp add --scope user jfsecure -- jfs mcp

Cursor (~/.cursor/mcp.json), Claude Desktop, Windsurf, VS Code — any stdio MCP client:

json
{ "mcpServers": { "jfsecure": { "command": "jfs", "args": ["mcp"] } } }

More: https://secure.jfolio.org/agents

Also as an MCP bundle (.mcpb, Windows / macOS / Linux) on the releases page, and in the official MCP Registry as io.github.theone55/jfs.

Command line

jfs status                       is the app running and unlockedjfs ls [secret|folder]           names only, no approval neededjfs get github/token             print a value (approved in the app)jfs copy github/token            to the clipboard, nothing printedjfs run github -- gh api user    run with the secret's keys as env vars ($token → TOKEN); output masked when pipedjfs render .env.tpl -o .env      fill {{Secret:key}} into a filegit config --global credential.helper "!jfs git-credential"

Full guide: https://secure.jfolio.org/cli

What it protects — and what it doesn't

  • The model never receives a value, so it can't end up in a transcript or a log.
  • A prompt-injected agent can only ask; you see the exact command.
  • The pipe is your OS user's only, and the app identifies the caller through the OS, not by what it says.
  • Masking is a seatbelt, not a wall: a command you approve can still send a value away. Read the command.

Build

sh
cargo build --release   # Rust stable; Windows, macOS, Linuxcargo test

The copy here follows each JFSecure release (version in Cargo.toml = the app's version it shipped with). Issues and questions are welcome here.

MIT License.

来源:README.md,提交 8f2cab3

工具

0
工具元数据尚未被收录。

版本历史

2
  1. v2.6.1最新Oct 11, 2026
  2. v2.6.0Oct 11, 2026