As AI coding agents like OpenCode, Cursor, and Model Context Protocol (MCP) clients become integral to daily software development, we routinely grant them permission to execute terminal commands, run tests, and manage infrastructure. However, this workflow introduces a recurring friction and security risk: managing sensitive credentials across multiple projects and environments without exposing raw API keys directly to the LLM’s context window.
To keep credentials out of the prompt context, the typical workaround is configuring environment variables on the local system. But as project complexity grows, managing environment variables across different environments (staging, production, development) and multiple tools quickly becomes tedious and error-prone. More critically, configuring environment variables does not fully solve the security problem: an unhandled command error, a verbose debug log, or a prompt injection attempt can easily dump env variables into stdout or stderr, leaking raw secrets into the LLM context or third-party loggers.
To address these challenges, I built BlindEnv: an open-source, local secret-isolation proxy written in Go.
The Core Concept: «Blind» Secret Usage
The design philosophy behind BlindEnv is straightforward: agents should be able to execute tools and commands using your environment variables, but they should never see the raw secret values themselves.
Instead of exposing credentials directly to the LLM context window or populating global system environment variables, BlindEnv acts as a local intermediary proxy:
- BlindEnv stores your credentials in a encrypted local vault.
- When an agent requests a command execution, BlindEnv resolves the required keys and injects them exclusively into the environment space of the child process.
- If the executed command outputs a secret string by mistake, BlindEnv intercepts and redacts it in real time before returning the output to the agent context.
Architectural Breakdown
BlindEnv is distributed as an open-source Go module under the MIT License (github.com/fernandoris/blindenv). The architecture is divided into specialized packages designed for zero external network dependencies, minimal runtime overhead, and local-first operation.
| Go Package | Path | Responsibility |
cmd/blindenv | github.com/fernandoris/blindenv/cmd/blindenv | CLI entrypoint and command handling (main.go, commands.go). |
pkg/db | github.com/fernandoris/blindenv/pkg/db | Encrypted SQLite vault, scope hierarchy engine, and MCP audit logging. |
pkg/backup | github.com/fernandoris/blindenv/pkg/backup | Atomic, passphrase-encrypted vault exports and imports independent of OS keyrings. |
Key Technical Features
1. Embedded Encrypted Vault (pkg/db)
BlindEnv stores all secrets in an embedded SQLite database managed by db.Open(path, key). This eliminates dependencies on cloud services or external daemons while avoiding platform-specific OS keyring limitations.
2. Hierarchical Scope Resolution
To eliminate configuration duplication across projects and deployment stages, BlindEnv implements a 4-tier scoping resolution model via EffectiveScopes(ctx, project, environment):
- Project + Environment (
ProjectEnvironments): Environment-specific overrides for a specific project. - Project Global (
Project): Shared keys across all environments within a project. - Environment Global (
Environments): Generic keys shared across projects for a given environment name (e.g., global staging keys). - Global (
Global): Universal keys accessible across all projects.
The ScopedKeys structure allows agents and CLI tools to inspect configuration topology (which keys exist in which scope) without ever retrieving the secret values.
3. Real-Time Stream Redaction & Audit Trail
When executing subcommands or handling Model Context Protocol (MCP) tool invocations, BlindEnv monitors process output channels. If a secret string appears inside stdout or stderr, the stream interceptor automatically redacts the sensitive substring before passing the response back to the agent.
Additionally, every MCP tool execution is recorded in the vault using AppendAudit as an AuditEntry. This audit record captures essential execution metadata—client ID, project, environment, tool name, command executed, exit code, and total redaction count—without ever storing the raw secret data.
4. Portable Encrypted Backups (pkg/backup)
Transferring secret vault state across developer workstations is handled via backup.Export and backup.Import. The vault is packaged into a passphrase-encrypted file that verifies payload integrity prior to writing to the destination database, ensuring protection against corruption or incorrect passphrases.
How It Was Built
BlindEnv was designed and built using a modern AI-assisted engineering workflow:
- Specification & Architecture: Drafted using OpenSpec for clear conceptual boundaries.
- Development Environment: Developed inside OpenCode.
- Code Generation & Refactoring: Powered by DeepSeek 4.1 Flash.
Getting Started
BlindEnv is 100% open-source under the MIT License. You can inspect the source code, install the CLI, or contribute on GitHub:
👉 github.com/fernandoris/blindenv
[cite: 2]
Feel free to try it out in your local agent workflows, open issues, or share feedback!
