ShadowPaste: Open-Source Local MCP Proxy to Keep .env Secrets Safe from AI
shadowpaste · reddit · 2026-08-07
A developer has open-sourced ShadowPaste, a local-first, zero-trust MCP gateway designed to protect .env files during AI-assisted coding. It prevents tools like Cursor and ChatGPT from accessing real secrets.
How it works:
- Scans over 500 secret patterns and encrypts real keys into a local AES-256 vault.
- Feeds format-compatible fake keys to AI agents, allowing them to function normally without exposing actual credentials.
- Restores real secrets byte-for-byte once the task is complete.
More from coding & agent
- Cutting API Costs: Demoting Boring Tasks Like Classification to Smaller Models — Necessary_Bison_2804 · 2026-08-07
- Open-source memory tool daimon tags agent memories as verbatim, inferred, or unverified; forget actually deletes — Sea-Perception1619 · 2026-08-07
- Open-Source Web 3D Robot Viewer: Supports URDF and MuJoCo Formats — tom_doerr · 2026-08-07
- Developer builds tool to catch AI agent decision drift before CI build fails — Original_Iron7191 · 2026-08-07
- Small business owner seeks AI automation advice for orders, emails, social media — Low_Barber3002 · 2026-08-07
- Frustration: Current AI Agents Still Can't Properly Find and Book Flights — braelyn_ai · 2026-08-07