Secret keys
API keys, tokens, passwords, SSH keys, cloud credentials. Stripe will not answer without the key.
Open source · by Mandu Security
Mandu keeps your secrets for you, and keeps your AI agent useful. Run Claude Code, Codex and other coding agents next to your real keys and secret files. The AI sees your secrets masked. You, and the programs that need them, still get the real values.
DATABASE_URL=$MDU:nomodel_Read[4c1e].DATABASE_URL STRIPE_KEY=$MDU:nomodel_Read[9bbd].STRIPE_KEY GH_TOKEN=$MDU:nomodel_Read[71a0].GH_TOKEN DEBUG=1
Masked. The AI can pass these placeholders around, put them in a command and tell which variable is which. The real values never reach it.
The problem
Whatever a coding agent reads goes into the AI's context, and from there to the company that runs the AI. To use a secret, the agent has to read it.
Secret keys
API keys, tokens, passwords, SSH keys, cloud credentials. Stripe will not answer without the key.
Personal documents
Health records, tax returns, a lease, a diary. The agent needs the content to do the job. The question is which AI may read it.
Company documents
Contracts, plans, financials, customer lists. Company policy often says no outside AI, or only the one the company runs.
curl with the key, to whatever host the command names.any server: a gist, a webhook, a tunnelMandu stops the secret from leaving, whoever asked for it.
Why Mandu
Other tools act in one place each. They keep the secret by taking work away from the AI, or keep the work and let the secret through. Pick an approach to see where it acts and what it leaves open.
Acts around the agent's commands
What it does. Box in the agent's commands and ask before risky steps.
The catch. Whatever the agent reads still goes to the AI.
Also in this family: Docker Sandboxes (one microVM per agent), and cloud sandboxes such as E2B.
Acts on the network path
What it does. Give the agent a stand-in key; the real one is added on the way out.
The catch. Only keys, mostly over HTTP; files and output the agent reads still reach the AI.
Also in this family: 1Password's agentic autofill, which fills a browser login without the agent or its model seeing the password.
Acts on the path to the AI
What it does. Spot sensitive content on its way to the AI, and block or redact it.
The catch. Blocked data can't be used, detectors miss things, and the agent's own traffic goes unchecked.
Also in this family: Skyflow's LLM privacy vault (tokens it can turn back into values), and the AI data-loss features of network security suites such as Netskope, Zscaler and Palo Alto Prisma.
Acts inside the agent, or in place of the AI provider
What it does. Split the agent so the planner is kept from the data, or run the model yourself.
The catch. Means a new agent or a weaker model, and leaves most of the network side open.
Acts on the path to the AI, around the tools and on the network path
What it does. The AI sees your secrets masked; the programs you name and the hosts a rule lists get the real value.
The catch. Its limits have their own section, below.
| Product | Covers | Blind spot | Kept from the AI | Kept off the network | Still usable |
|---|---|---|---|---|---|
| A · Fence the agent | |||||
| Claude Code: sandbox and auto mode | Bash and its children; a classifier on risky actions | the Read tool, and so the AI, sees every file | No | Partly | Yes |
| Codex: sandbox and auto-review | commands, offline by default; asks you for more | commands may read any file; output reaches the AI | No | Partly | Partly |
| B · Swap the credential | |||||
| Claude Code: credential mask | sandboxed Bash; HTTP hosts you list | the Read tool shows the real file | Partly | Partly | Partly |
| NVIDIA OpenShell | the whole agent in a box; keys added for allowed endpoints | files the box may read; what goes to an allowed host | Partly | Partly | Partly |
| nono | the whole agent; home-directory credentials denied; phantom tokens | a project's .env, the environment, command output | Partly | Partly | Partly |
| C · Filter the content | |||||
| Microsoft Purview | Microsoft 365 Copilot, Microsoft-built agents, browsers on managed devices | blocks rather than masks; not a coding agent's shell or MCP | Yes | Partly | No |
| AI gateways and LLM DLPLiteLLM + Presidio, Portkey, Nightfall, Prompt Security, Lakera, AWS Bedrock Guardrails, Skyflow, PrivAiTe | the prompt on its way to the AI | secrets in formats the detector does not know; the tools' own traffic | Partly | No | Yes |
| D · Rebuild the agent or move the model | |||||
| Information-flow control: dual LLM, CaMeL, FIDES | a planner kept from the data, or tracked when it looks; labels checked at tool calls | a new agent design; the quarantined model still reads the data | Partly | Partly | Partly |
| Local models and confidential inference | the model itself, run locally or in an attested enclave | weaker models; what tools send out | Yes | No | Partly |
| M · Mandu: all three places, one set of rules | |||||
| Mandu | the path to the AI, the tools and the network, for the secrets it knows | see Limits, below | Yes | Yes | Partly |
From each product's public documentation, read 2026-10-11. Each verdict is about the documented default or a documented opt-in.
How it works
Each secret Mandu knows about reaches the AI as a placeholder like this one. Only Mandu's local table turns it back into the real value, and the agent can neither read nor change that table.
curl api.stripe.com/v1/charges \
-u $MDU:nomodel_Read[9bbd].STRIPE_KEY:
api.stripe.com gets the real key, and only that request.ssh may open your key, but only when git started it. Your deploy tool opens its token on your word. Every other program is refused or gets the masked copy.# ~/.mandu/policy.yaml paths: - path: ~/proj/.env level: no-model # 1: No AI bindings: [api.stripe.com] # 2: Listed hosts - path: ~/.ssh/id_ed25519 level: no-model readers: [{ app: ssh, from: git }] - path: ~/work/board-memo-q4.md level: local-model # 1: Your own AI only models: - { name: ollama, local: true, … }
1Which AI may read it?
no-modelNo AI. Every AI sees it masked, Mandu's own helper included.local-modelYour own AI only. Only an AI you run and list, such as Ollama, may read it, when it asks. It can be your agent's main AI too.any-modelAny AI, when it asks. The AI first sees it masked. Mandu's helper reads it for the AI, or the AI reads it into the conversation. The read is logged, and your AI provider gets the text.publicNot secret. An ordinary file, even if it looks like a secret.2Where may it be sent?
(default)Needs your OK. Every send of the real value waits on the Approvals page.
Allow onceAlways allowBlockbindingsListed hosts without asking. The hosts you list get the real value, so list only hosts you trust.valuesPer value. In a file of several secrets, such as a .env, each value has its own hosts.Your OK never lets an AI past the first question; only changing the rule does. Answer both on the dashboard's Rules page, one menu each, or in ~/.mandu/policy.yaml.
mandu demo plays this on your computer, offline, with no API key.Evidence
Use a .env without seeing it, run a deploy script, use a cloud profile, commit and push, dry-run a package publish. Sonnet 5 and Opus 5.5, three runs each: 36 sessions per side.
Mandu with Protection on (secrets mode) against Claude Code's sandbox.credentials mask. All four leaks went through the agent's own Read tool, which the mask does not cover. The check looks for the secret verbatim, in base64, hex, reversed and rot13. Everyday tasks, no attacks. Method and raw numbers are in the repository's design docs.
Fits the way you work
mandu in front of your agent. That is the whole change.The agents above, and programs built on the Claude or Codex SDK. No plugin, and no changes to the agent.
Your credential files stay where they are, in the format they have. Mandu finds the usual ones by itself, and a rule protects any other file.
Everything runs as your user. Kernel hardening (seccomp, Landlock, a sandbox for commands) is added wherever your kernel allows it without root.
There is no Mandu server. Everything Mandu stores is in one folder, ~/.mandu, that only you can open.
On the Rules page, Who may get your secrets shows your rules per program, per host and per AI.
If Mandu cannot decide, the value stays masked or the action is blocked. It never falls back to sending the real value.
Limits
Knowing exactly what is covered is part of the product.
With Protection on, a web page, an issue comment or a file from someone else reaches the AI as written. A hidden instruction in it can still steer the agent, for example into sending out your source code, which is not a registered secret. The modes that also mask untrusted content are frozen and experimental, behind MANDU_EXPERIMENTAL_INTEGRITY=1.
Those are the credential files it finds and the files your rules name. Anything else is ordinary data to it. mandu doctor --secrets lists what the scan could not check.
ssh, the programs you name and HTTPS token tools such as gh, npm and curl work. Database password logins fail and need a workaround, and aws, kubectl and docker need your word.
Linux x64, tested on Ubuntu 24.04 and 26.04. 64-bit ARM is built but not yet tested on hardware; WSL2 is tested in simulation only; macOS is experimental.
Get started
Mandu uses your agent's own login, Claude Pro and Max included, and needs no API key of its own.
Mandu is in an invited beta. Invited accounts download the latest release from GitHub and run sh install.sh (no sudo). At the public launch this becomes npm install -g @mandusec/mandu. To join the beta, write to us (see Company).
# check this computer: Node, git, your agent, your secrets $ mandu doctor # your agent, protected (or: mandu codex) $ mandu claude mandu: mode secrets (14 credential files masked, 3 env vars masked) mandu: dashboard http://127.0.0.1:38121/ # what was protected, and what waits for your OK $ mandu dashboard # make it the default $ alias claude="mandu claude"
Open source
Security software that guards your secrets should be readable by the people it guards. Mandu is open source under the Apache License 2.0.
Mask a secret wherever it enters the agent's world; put the real value back only where it leaves for where it belongs.
| Boundary | On the way in | On the way out |
|---|---|---|
| The AI's context | Secrets in tool results are masked before the AI sees them. | Tool calls carry placeholders; they turn real only at the exits below. |
| Network | Every connection passes Mandu's network guards. | The real value goes only to a host its rule lists, or with your OK, one value at a time. |
| Files | A secret file opens as a masked copy. | Programs its rule names get the real bytes; files they write are secret too. |
| Commands | What such a program prints reaches the AI masked. | Such a program may connect only to the hosts its rule lists. |
connect(2) guardLandlock files and TCP portsno_new_privs
A layer your kernel does not support is skipped with a notice. Anything that needs host root, or changes the computer for other users, is left out by design.
Every end-to-end test checks the same thing: a planted secret never shows up in anything the AI sees, verbatim or encoded.
arbiter/The protection service: placeholder table, rules, eventsinterceptors/The guards on the way to the AI, the network and your screen (TypeScript), and in the kernel (Rust)launcher/The mandu command and all the wiringfs-sync/The two-view workspace on git worktreesdashboard/Approvals, Rules, Settings and a full trace inspectortests/End to end, sandbox, conformanceResearch
Prompt Flow Integrity (arXiv:2503.15547) isolates an LLM agent from untrusted content and guards against privilege escalation. DualView (arXiv:2607.03821) follows it with a defense that keeps two views of an agent's data and routes every action to one of them.
Mandu implements DualView at the operating-system level instead of inside one agent framework, and uses its placeholder machinery to protect secrets. It carries forward DualView's placeholder table, policy engine and two-view workspace.
Cite
@misc{dualview2026,
title = {DualView: Preventing Indirect Prompt
Injection in Personal AI Agents},
author = {Kim, Juhee and Choi, Woohyuk and
Kang, Taehyun and Kim, Youngmin and
Lee, Byoungyoung},
year = {2026},
eprint = {2607.03821},
archivePrefix = {arXiv},
primaryClass = {cs.CR}
}
@misc{pfi2025,
title = {Prompt Flow Integrity to Prevent
Privilege Escalation in LLM Agents},
author = {Kim, Juhee and Choi, Woohyuk and
Lee, Byoungyoung},
year = {2025},
eprint = {2503.15547},
archivePrefix = {arXiv},
primaryClass = {cs.CR}
}
Mandu Security
Mandu Security builds Mandu and keeps it open. We started from systems-security research on keeping AI agents away from data they should not hold, and we are turning that research into something you can install next to the agent you already use.
A mandu is a Korean dumpling. The agent handles the wrapper; the filling, your secrets, stays with you.
Open source · free
Everything on this page, on your own computers.
Now · beta
We are working with a small group of early teams whose agents run next to real credentials. If that is you, write to us.