Open source · by Mandu Security

Your agent sees the dumpling, never the filling.

Mandu keeps your secrets for you, and keeps your AI agent useful. Run Claude Code, Codex and other coding agents next to your real keys and secret files. The AI sees your secrets masked. You, and the programs that need them, still get the real values.

Works with Claude CodeCodexOpenCodeOpenClawGoose
~/proj/.env
DATABASE_URL=$MDU:nomodel_Read[4c1e].DATABASE_URL
STRIPE_KEY=$MDU:nomodel_Read[9bbd].STRIPE_KEY
GH_TOKEN=$MDU:nomodel_Read[71a0].GH_TOKEN
DEBUG=1

Masked. The AI can pass these placeholders around, put them in a command and tell which variable is which. The real values never reach it.

The problem

To use your secret, the agent reads it.

Whatever a coding agent reads goes into the AI's context, and from there to the company that runs the AI. To use a secret, the agent has to read it.

Secret keys

> how much did we charge on Stripe last week? ● Read(.env) STRIPE_KEY=sk_live_•••••••••••• ● Bash(curl api.stripe.com/v1/charges \ -u sk_live_••••••••••••:) ● Last week: $12,480 across 37 payments.

API keys, tokens, passwords, SSH keys, cloud credentials. Stripe will not answer without the key.

Personal documents

> summarize my blood test, draft a note ● Read(~/Documents/health/lab-results.md) Patient: J. Doe · born 1988-04-12 HbA1c 7.9 % (above range) Insurer: member no. 4471-02 ● Here is a summary and a draft note…

Health records, tax returns, a lease, a diary. The agent needs the content to do the job. The question is which AI may read it.

Company documents

> draft the all-hands update from the memo ● Read(~/work/board-memo-q4.md) # Q4 board memo · CONFIDENTIAL Project Falcon: acquisition at $42M Runway: 14 months at current burn ● Here is a draft of the update…

Contracts, plans, financials, customer lists. Company policy often says no outside AI, or only the one the company runs.

Three ways a secret leaves your computer

1In every request to the AIThe secret sits in the agent's context and goes out with each call.the AI provider
2In a command the agent runscurl with the key, to whatever host the command names.any server: a gist, a webhook, a tunnel
3On someone else's ordersA hidden instruction in an issue, a README or an email tells the agent where to send it.someone else

Mandu stops the secret from leaving, whoever asked for it.

Why Mandu

Today you pick a useful agent or a safe secret.

Other tools act in one place each. They keep the secret by taking work away from the AI, or keep the work and let the secret through. Pick an approach to see where it acts and what it leaves open.

YOUR COMPUTEROUTSIDESandboxAsk youAI agentClaude Code · CodexTools & files.env · ssh · deployAI providerthe cloud AI serviceInternetAPIs · hostssk-live…✕ unlistedAskAgentToolsAIInternet!✕

AFence the agent

Acts around the agent's commands

What it does. Box in the agent's commands and ask before risky steps.

The catch. Whatever the agent reads still goes to the AI.

  • NoKept from the AIfile reads reach the AI
  • PartlyKept off the networkallowlist, or ask
  • YesStill usablenothing is masked

Also in this family: Docker Sandboxes (one microVM per agent), and cloud sandboxes such as E2B.

YOUR COMPUTEROUTSIDESwap keystand-in → real keyAI agentClaude Code · CodexTools & files.env · ssh · deployAI providerthe cloud AI serviceInternetAPIs · hostssk-live…via file reads✓ sk-live…SwapAgentToolsAIInternet!✓

BSwap the credential

Acts on the network path

What it does. Give the agent a stand-in key; the real one is added on the way out.

The catch. Only keys, mostly over HTTP; files and output the agent reads still reach the AI.

  • PartlyKept from the AIkeys yes, file reads no
  • PartlyKept off the networkreal key to its host only
  • PartlyStill usableHTTP APIs work

Also in this family: 1Password's agentic autofill, which fills a browser login without the agent or its model seeing the password.

YOUR COMPUTEROUTSIDEFilterblock or redactAI agentClaude Code · CodexTools & files.env · ssh · deployAI providerthe cloud AI serviceInternetAPIs · hosts✕ blockedsk-live…FilterAgentToolsAIInternet✕!

CFilter the content

Acts on the path to the AI

What it does. Spot sensitive content on its way to the AI, and block or redact it.

The catch. Blocked data can't be used, detectors miss things, and the agent's own traffic goes unchecked.

  • PartlyKept from the AIwhat is labelled or detected
  • NoKept off the networkagent traffic unchecked
  • PartlyStill usableblocked means unusable

Also in this family: Skyflow's LLM privacy vault (tokens it can turn back into values), and the AI data-loss features of network security suites such as Netskope, Zscaler and Palo Alto Prisma.

YOUR COMPUTEROUTSIDESplit agentplanner kept from dataTools & files.env · ssh · deployYour own modellocal or enclaveInternetAPIs · hostsunreadablesk-live…PlannerToolsLocalInternet✓!

DRebuild the agent or move the model

Acts inside the agent, or in place of the AI provider

What it does. Split the agent so the planner is kept from the data, or run the model yourself.

The catch. Means a new agent or a weaker model, and leaves most of the network side open.

  • PartlyKept from the AIyes with a local model
  • PartlyKept off the networkonly label checks
  • PartlyStill usablenew agent or weaker model
YOUR COMPUTEROUTSIDEKernel guardMasksecret → $MDU:…Unmaskreal value to its hostAI agentClaude Code · CodexTools & files.env · ssh · deployAI providerthe cloud AI serviceInternetAPIs · hosts$MDU:…✓ sk-live…MaskUnmaskAgentToolsAIInternet✓✓

MMandu: all three places, one set of rules

Acts on the path to the AI, around the tools and on the network path

What it does. The AI sees your secrets masked; the programs you name and the hosts a rule lists get the real value.

The catch. Its limits have their own section, below.

  • YesKept from the AIplaceholders only
  • YesKept off the networkreal value to its host only
  • PartlyStill usablessh, HTTPS tools, named programs
  • the real secret, where it should not be
  • the real secret, sent where it belongs
  • masked: a placeholder in its place
  • stopped
  • a protection

Every product, side by side

ProductCoversBlind spotKept from the AIKept off the networkStill usable
A · Fence the agent
Claude Code: sandbox and auto modeBash and its children; a classifier on risky actionsthe Read tool, and so the AI, sees every fileNoPartlyYes
Codex: sandbox and auto-reviewcommands, offline by default; asks you for morecommands may read any file; output reaches the AINoPartlyPartly
B · Swap the credential
Claude Code: credential masksandboxed Bash; HTTP hosts you listthe Read tool shows the real filePartlyPartlyPartly
NVIDIA OpenShellthe whole agent in a box; keys added for allowed endpointsfiles the box may read; what goes to an allowed hostPartlyPartlyPartly
nonothe whole agent; home-directory credentials denied; phantom tokensa project's .env, the environment, command outputPartlyPartlyPartly
C · Filter the content
Microsoft PurviewMicrosoft 365 Copilot, Microsoft-built agents, browsers on managed devicesblocks rather than masks; not a coding agent's shell or MCPYesPartlyNo
AI gateways and LLM DLPLiteLLM + Presidio, Portkey, Nightfall, Prompt Security, Lakera, AWS Bedrock Guardrails, Skyflow, PrivAiTethe prompt on its way to the AIsecrets in formats the detector does not know; the tools' own trafficPartlyNoYes
D · Rebuild the agent or move the model
Information-flow control: dual LLM, CaMeL, FIDESa planner kept from the data, or tracked when it looks; labels checked at tool callsa new agent design; the quarantined model still reads the dataPartlyPartlyPartly
Local models and confidential inferencethe model itself, run locally or in an attested enclaveweaker models; what tools send outYesNoPartly
M · Mandu: all three places, one set of rules
Manduthe path to the AI, the tools and the network, for the secrets it knowssee Limits, belowYesYesPartly

From each product's public documentation, read 2026-10-11. Each verdict is about the documented default or a documented opt-in.

How it works

A placeholder carries everything but the secret.

Each secret Mandu knows about reaches the AI as a placeholder like this one. Only Mandu's local table turns it back into the real value, and the agent can neither read nor change that table.

$MDU:Prefix, easy to find in any text
nomodel_Which AI may read it: No AI
ReadThe tool that read it
[9bbd]Id, meaningless outside Mandu
.STRIPE_KEYName, so the agent knows which secret it is

Where the real value goes

curl api.stripe.com/v1/charges \
  -u $MDU:nomodel_Read[9bbd].STRIPE_KEY:
✓A host its rule lists. The request to api.stripe.com gets the real key, and only that request.
✓A program its rule names. ssh may open your key, but only when git started it. Your deploy tool opens its token on your word. Every other program is refused or gets the masked copy.
✓You. The agent's replies show you the real values; the AI keeps the placeholders.
# ~/.mandu/policy.yaml
paths:
  - path: ~/proj/.env
    level: no-model             # 1: No AI
    bindings: [api.stripe.com]  # 2: Listed hosts
  - path: ~/.ssh/id_ed25519
    level: no-model
    readers: [{ app: ssh, from: git }]
  - path: ~/work/board-memo-q4.md
    level: local-model          # 1: Your own AI only
models:
  - { name: ollama, local: true, … }

A rule answers two questions

1Which AI may read it?

no-modelNo AI. Every AI sees it masked, Mandu's own helper included.
local-modelYour own AI only. Only an AI you run and list, such as Ollama, may read it, when it asks. It can be your agent's main AI too.
any-modelAny AI, when it asks. The AI first sees it masked. Mandu's helper reads it for the AI, or the AI reads it into the conversation. The read is logged, and your AI provider gets the text.
publicNot secret. An ordinary file, even if it looks like a secret.

2Where may it be sent?

(default)Needs your OK. Every send of the real value waits on the Approvals page. Allow onceAlways allowBlock
bindingsListed hosts without asking. The hosts you list get the real value, so list only hosts you trust.
valuesPer value. In a file of several secrets, such as a .env, each value has its own hosts.

Your OK never lets an AI past the first question; only changing the rule does. Answer both on the dashboard's Rules page, one menu each, or in ~/.mandu/policy.yaml.

See it for yourself

A recorded terminal session of mandu demo: the agent reads a .env file and sees placeholders, while the user sees the real values.
mandu demo plays this on your computer, offline, with no API key.

Evidence

Measured on six everyday secret-key tasks.

Use a .env without seeing it, run a deploy script, use a cloud profile, commit and push, dry-run a package publish. Sonnet 5 and Opus 5.5, three runs each: 36 sessions per side.

Secret kept from the AI

Mandu36/36
Claude Code credential mask32/36

Task done

Mandu36/36
Claude Code credential mask19/36

Mandu with Protection on (secrets mode) against Claude Code's sandbox.credentials mask. All four leaks went through the agent's own Read tool, which the mask does not cover. The check looks for the secret verbatim, in base64, hex, reversed and rot13. Everyday tasks, no attacks. Method and raw numbers are in the repository's design docs.

Fits the way you work

Put mandu in front of your agent. That is the whole change.

Your agents, unchanged

The agents above, and programs built on the Claude or Codex SDK. No plugin, and no changes to the agent.

Nothing to migrate

Your credential files stay where they are, in the format they have. Mandu finds the usual ones by itself, and a rule protects any other file.

No root

Everything runs as your user. Kernel hardening (seccomp, Landlock, a sandbox for commands) is added wherever your kernel allows it without root.

No account, no telemetry

There is no Mandu server. Everything Mandu stores is in one folder, ~/.mandu, that only you can open.

Who gets what, at a glance

On the Rules page, Who may get your secrets shows your rules per program, per host and per AI.

Fails closed

If Mandu cannot decide, the value stays masked or the action is blocked. It never falls back to sending the real value.

Limits

What Mandu does not do.

Knowing exactly what is covered is part of the product.

It does not stop prompt injection

With Protection on, a web page, an issue comment or a file from someone else reaches the AI as written. A hidden instruction in it can still steer the agent, for example into sending out your source code, which is not a registered secret. The modes that also mask untrusted content are frozen and experimental, behind MANDU_EXPERIMENTAL_INTEGRITY=1.

It protects only the secrets it knows

Those are the credential files it finds and the files your rules name. Anything else is ordinary data to it. mandu doctor --secrets lists what the scan could not check.

Some tools need extra steps

ssh, the programs you name and HTTPS token tools such as gh, npm and curl work. Database password logins fail and need a workaround, and aws, kubectl and docker need your word.

Linux first

Linux x64, tested on Ubuntu 24.04 and 26.04. 64-bit ARM is built but not yet tested on hardware; WSL2 is tested in simulation only; macOS is experimental.

Get started

Four commands.

Mandu uses your agent's own login, Claude Pro and Max included, and needs no API key of its own.

Mandu is in an invited beta. Invited accounts download the latest release from GitHub and run sh install.sh (no sudo). At the public launch this becomes npm install -g @mandusec/mandu. To join the beta, write to us (see Company).

# check this computer: Node, git, your agent, your secrets
$ mandu doctor

# your agent, protected (or: mandu codex)
$ mandu claude
mandu: mode secrets (14 credential files masked, 3 env vars masked)
mandu: dashboard http://127.0.0.1:38121/

# what was protected, and what waits for your OK
$ mandu dashboard

# make it the default
$ alias claude="mandu claude"

Open source

Built in the open, so you can check every promise.

Security software that guards your secrets should be readable by the people it guards. Mandu is open source under the Apache License 2.0.

One rule, at every boundary

Mask a secret wherever it enters the agent's world; put the real value back only where it leaves for where it belongs.

BoundaryOn the way inOn the way out
The AI's contextSecrets in tool results are masked before the AI sees them.Tool calls carry placeholders; they turn real only at the exits below.
NetworkEvery connection passes Mandu's network guards.The real value goes only to a host its rule lists, or with your OK, one value at a time.
FilesA secret file opens as a masked copy.Programs its rule names get the real bytes; files they write are secret too.
CommandsWhat such a program prints reaches the AI masked.Such a program may connect only to the hosts its rule lists.

The kernel hardening, layer by layer

Bubblewrap command boxPID, IPC, UTS, cgroup namespacesAll capabilities droppedseccomp deny-filterseccomp connect(2) guardLandlock files and TCP portsno_new_privs

A layer your kernel does not support is skipped with a notice. Anything that needs host root, or changes the computer for other users, is left out by design.

Every promise names the test that breaks

160+test suites in one manifest; a test file no entry claims fails the build
55+sandbox suites: the kernel guards and the command box, without root
5suite kinds on every push, in a throwaway KVM guest
1script runs exactly what CI runs, on your laptop

Every end-to-end test checks the same thing: a planted secret never shows up in anything the AI sees, verbatim or encoded.

Find your way around

arbiter/The protection service: placeholder table, rules, events
interceptors/The guards on the way to the AI, the network and your screen (TypeScript), and in the kernel (Rust)
launcher/The mandu command and all the wiring
fs-sync/The two-view workspace on git worktrees
dashboard/Approvals, Rules, Settings and a full trace inspector
tests/End to end, sandbox, conformance

Research

Built on two papers

Prompt Flow Integrity (arXiv:2503.15547) isolates an LLM agent from untrusted content and guards against privilege escalation. DualView (arXiv:2607.03821) follows it with a defense that keeps two views of an agent's data and routes every action to one of them.

Mandu implements DualView at the operating-system level instead of inside one agent framework, and uses its placeholder machinery to protect secrets. It carries forward DualView's placeholder table, policy engine and two-view workspace.

github.com/compsec-snu/dualview

Cite

@misc{dualview2026,
  title  = {DualView: Preventing Indirect Prompt
            Injection in Personal AI Agents},
  author = {Kim, Juhee and Choi, Woohyuk and
            Kang, Taehyun and Kim, Youngmin and
            Lee, Byoungyoung},
  year   = {2026},
  eprint = {2607.03821},
  archivePrefix = {arXiv},
  primaryClass  = {cs.CR}
}

@misc{pfi2025,
  title  = {Prompt Flow Integrity to Prevent
            Privilege Escalation in LLM Agents},
  author = {Kim, Juhee and Choi, Woohyuk and
            Lee, Byoungyoung},
  year   = {2025},
  eprint = {2503.15547},
  archivePrefix = {arXiv},
  primaryClass  = {cs.CR}
}

Mandu Security

The company behind Mandu.

Mandu Security builds Mandu and keeps it open. We started from systems-security research on keeping AI agents away from data they should not hold, and we are turning that research into something you can install next to the agent you already use.

A mandu is a Korean dumpling. The agent handles the wrapper; the filling, your secrets, stays with you.

$MDU:…

Open source · free

Mandu

Everything on this page, on your own computers.

Now · beta

Design partners

We are working with a small group of early teams whose agents run next to real credentials. If that is you, write to us.