BlindEnv: Secret Isolation for Autonomous AI Coding Agents

As AI coding agents like OpenCode, Cursor, and Model Context Protocol (MCP) clients become integral to daily software development, we routinely grant them permission to execute terminal commands, run tests, and manage infrastructure. However, this workflow introduces a recurring friction and security risk: managing sensitive credentials across multiple projects and environments without exposing raw API keys directly to the LLM’s context window.

To keep credentials out of the prompt context, the typical workaround is configuring environment variables on the local system. But as project complexity grows, managing environment variables across different environments (staging, production, development) and multiple tools quickly becomes tedious and error-prone. More critically, configuring environment variables does not fully solve the security problem: an unhandled command error, a verbose debug log, or a prompt injection attempt can easily dump env variables into stdout or stderr, leaking raw secrets into the LLM context or third-party loggers.

To address these challenges, I built BlindEnv: an open-source, local secret-isolation proxy written in Go.

The Core Concept: «Blind» Secret Usage

The design philosophy behind BlindEnv is straightforward: agents should be able to execute tools and commands using your environment variables, but they should never see the raw secret values themselves.

Instead of exposing credentials directly to the LLM context window or populating global system environment variables, BlindEnv acts as a local intermediary proxy:

  1. BlindEnv stores your credentials in a encrypted local vault.
  2. When an agent requests a command execution, BlindEnv resolves the required keys and injects them exclusively into the environment space of the child process.
  3. If the executed command outputs a secret string by mistake, BlindEnv intercepts and redacts it in real time before returning the output to the agent context.

Architectural Breakdown

BlindEnv is distributed as an open-source Go module under the MIT License (github.com/fernandoris/blindenv). The architecture is divided into specialized packages designed for zero external network dependencies, minimal runtime overhead, and local-first operation.

Go PackagePathResponsibility
cmd/blindenvgithub.com/fernandoris/blindenv/cmd/blindenvCLI entrypoint and command handling (main.go, commands.go).
pkg/dbgithub.com/fernandoris/blindenv/pkg/dbEncrypted SQLite vault, scope hierarchy engine, and MCP audit logging.
pkg/backupgithub.com/fernandoris/blindenv/pkg/backupAtomic, passphrase-encrypted vault exports and imports independent of OS keyrings.

Key Technical Features

1. Embedded Encrypted Vault (pkg/db)

BlindEnv stores all secrets in an embedded SQLite database managed by db.Open(path, key). This eliminates dependencies on cloud services or external daemons while avoiding platform-specific OS keyring limitations.

2. Hierarchical Scope Resolution

To eliminate configuration duplication across projects and deployment stages, BlindEnv implements a 4-tier scoping resolution model via EffectiveScopes(ctx, project, environment):

  • Project + Environment (ProjectEnvironments): Environment-specific overrides for a specific project.
  • Project Global (Project): Shared keys across all environments within a project.
  • Environment Global (Environments): Generic keys shared across projects for a given environment name (e.g., global staging keys).
  • Global (Global): Universal keys accessible across all projects.

The ScopedKeys structure allows agents and CLI tools to inspect configuration topology (which keys exist in which scope) without ever retrieving the secret values.

3. Real-Time Stream Redaction & Audit Trail

When executing subcommands or handling Model Context Protocol (MCP) tool invocations, BlindEnv monitors process output channels. If a secret string appears inside stdout or stderr, the stream interceptor automatically redacts the sensitive substring before passing the response back to the agent.

Additionally, every MCP tool execution is recorded in the vault using AppendAudit as an AuditEntry. This audit record captures essential execution metadata—client ID, project, environment, tool name, command executed, exit code, and total redaction count—without ever storing the raw secret data.

4. Portable Encrypted Backups (pkg/backup)

Transferring secret vault state across developer workstations is handled via backup.Export and backup.Import. The vault is packaged into a passphrase-encrypted file that verifies payload integrity prior to writing to the destination database, ensuring protection against corruption or incorrect passphrases.

How It Was Built

BlindEnv was designed and built using a modern AI-assisted engineering workflow:

  • Specification & Architecture: Drafted using OpenSpec for clear conceptual boundaries.
  • Development Environment: Developed inside OpenCode.
  • Code Generation & Refactoring: Powered by DeepSeek 4.1 Flash.

Getting Started

BlindEnv is 100% open-source under the MIT License. You can inspect the source code, install the CLI, or contribute on GitHub:

👉 github.com/fernandoris/blindenv

[cite: 2]

Feel free to try it out in your local agent workflows, open issues, or share feedback!

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *

You may use these HTML tags and attributes:

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong> 

Este sitio usa Akismet para reducir el spam. Aprende cómo se procesan los datos de tus comentarios.