JFSecure

io.github.theone55v2.6.1更新於 Oct 11, 2026

Let AI agents use secrets without seeing them: masked output, every use approved in JFSecure.

已驗證STDIO僅桌面開發者工具安全與監控

概覽

AI 產生的概覽

讓助理以環境變數或範本值的方式使用已儲存的密鑰,而不會取得密鑰本身的值。

功能
JFSecure 的 jfs MCP 伺服器是一個輕量本機用戶端,透過本機管道與正在執行且已解鎖的 JFSecure 應用程式通訊。它提供 list_secrets(僅回傳名稱)、run_with_secrets(以密鑰的鍵作為環境變數執行命令,輸出被遮蔽為 [JFSecure: NAME])以及 render_template(將 {{Secret:key}} 佔位符填入 .env 等檔案)。它刻意不提供回傳密鑰值的工具;每次使用都會在應用程式中開啟核准視窗,顯示程式、確切命令與密鑰。
適用情境
當助理需要憑證來驗證或執行命令,而你不希望這些值出現在模型脈絡、對話紀錄或日誌中時使用。適合以權杖呼叫 API、產生 .env 檔案或使用 Git 認證協助程式等情境,並在桌面應用程式中逐次核准。
執行需求
需要在本機桌面安裝 JFSecure 應用程式(macOS、Windows 或 Linux),並保持保存庫已開啟且解鎖;jfs 命令需在 PATH 中(隨應用程式安裝,或透過 Homebrew、.deb、應用程式設定安裝)。以 stdio 方式加入 MCP 伺服器,例如命令 jfs、參數 mcp。未宣告環境變數、標頭或個別的身分驗證。
安裝前請注意
核准某個命令即允許其使用密鑰,而遮蔽被描述為安全帶而非圍牆:已核准的命令仍可能把值傳送出去,因此核准前請閱讀確切命令。核准可僅一次或 15 分鐘,且限定於該命令與該密鑰。伺服器本身不會開啟保存庫檔案,也看不到保存庫密碼。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 JFSecure,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

jfs — secrets for AI agents that never see them

jfs is the command line and MCP server of JFSecure, an offline password and snippet manager. It lets Claude Code, Cursor or any MCP agent use a secret without ever getting it — and you approve every use in the app.

This repository is the source of jfs itself, so you can read exactly what an agent talks to. It is a thin client: it sends one JSON request over a local pipe to the running, unlocked JFSecure app and prints the answer. It never opens vault files, never sees the vault password and has no crypto. (The app is a separate download; jfs ships with it.)

[Claude Code asks, JFSecure shows the exact command, the agent gets the output with the token masked]

MCP tools

ToolWhat it doesWhat the agent gets back
list_secretsLists secret and key names, with the environment variable each key becomesNames only
run_with_secretsRuns a command with a secret's keys as environment variables (all, some, or one on stdin)Exit code and output, every value masked as [JFSecure: NAME]
render_templateFills {{Secret:key}} in a template and writes the file (e.g. .env)Which names were filled in

There is no "get" tool, on purpose. Every use opens an approval window in JFSecure that shows the program, the exact command and the secret: allow once, allow 15 minutes, or deny. For Claude Code a 15-minute approval covers only that command and that secret.

# the agent called run_with_secrets(secret: "github", command: …)exit code 0variables set: TOKEN--- stdout ---token is [JFSecure: TOKEN]{"login": "octocat", "plan": {"name": "pro"}}

Set up

  1. Install JFSecure and open your vault: brew install theone55/jfsecure/jfsecure (macOS), scoop bucket add jfsecure https://github.com/theone55/scoop-jfsecure; scoop install jfsecure/jfsecure (Windows), or the installer (Windows, macOS, Linux). jfs comes with it: on Windows the app puts it on PATH at its first start (open a new terminal afterwards); on macOS (.dmg) and the Linux AppImage use Settings → Install the jfs command; Homebrew and the .deb install it for you.
  2. Add the MCP server:
sh
claude mcp add --scope user jfsecure -- jfs mcp

Cursor (~/.cursor/mcp.json), Claude Desktop, Windsurf, VS Code — any stdio MCP client:

json
{ "mcpServers": { "jfsecure": { "command": "jfs", "args": ["mcp"] } } }

More: https://secure.jfolio.org/agents

Also as an MCP bundle (.mcpb, Windows / macOS / Linux) on the releases page, and in the official MCP Registry as io.github.theone55/jfs.

Command line

jfs status                       is the app running and unlockedjfs ls [secret|folder]           names only, no approval neededjfs get github/token             print a value (approved in the app)jfs copy github/token            to the clipboard, nothing printedjfs run github -- gh api user    run with the secret's keys as env vars ($token → TOKEN); output masked when pipedjfs render .env.tpl -o .env      fill {{Secret:key}} into a filegit config --global credential.helper "!jfs git-credential"

Full guide: https://secure.jfolio.org/cli

What it protects — and what it doesn't

  • The model never receives a value, so it can't end up in a transcript or a log.
  • A prompt-injected agent can only ask; you see the exact command.
  • The pipe is your OS user's only, and the app identifies the caller through the OS, not by what it says.
  • Masking is a seatbelt, not a wall: a command you approve can still send a value away. Read the command.

Build

sh
cargo build --release   # Rust stable; Windows, macOS, Linuxcargo test

The copy here follows each JFSecure release (version in Cargo.toml = the app's version it shipped with). Issues and questions are welcome here.

MIT License.

來源:README.md,提交 8f2cab3

工具

0
工具後設資料尚未被收錄。

版本歷史

2
  1. v2.6.1最新Oct 11, 2026
  2. v2.6.0Oct 11, 2026