Skip to content

Build1 publisher3 min readPublished Updated

Decoys in the .env file: Jitpass bets on lying to your coding agent

A Mac utility replaces plaintext credentials with fake ones and injects the real value into an approved process after Touch ID. The pattern is now on every security team's evaluation list.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Meni Tasa (@menitasa) is building Jitpass, the maker of jit, a security layer for credentials scattered across a developer's Mac: it finds plaintext secrets, moves them into an encrypted local vault and releases each value only when an approved process needs it.
  • API keys and cloud credentials still sit in .env files, shell history, AWS configuration, .npmrc files and MCP server settings, and any program running under the developer's account can usually read them.
  • An AI agent can copy credential values into a transcript, log or remote model request.
  • Jitpass replaces exposed values with decoys, redactions or hooks, then injects the real secret into an authorized process after a Touch ID prompt.
  • The public repository showed active development on August 15, 2026, with 587 commits listed on GitHub.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

Jitpass, a Mac tool from Meni Tasa, scans a developer's home directory for plaintext credentials, moves them into a locally encrypted vault, and leaves decoys, redactions or hooks behind in the files that used to hold the real values, injecting the real secret into an authorized process after a Touch ID prompt [1][4]. That design matters because of how the operating system sees a coding agent: it is just another local process running with the developer's permissions, so when it opens `.env` the file returns the production key exactly as it would for the developer's own application [13].

The underlying weakness is old. API keys and cloud credentials still live in `.env` files, shell history, AWS configuration, `.npmrc` and MCP server settings, and any program running under the developer's account can usually read them [2]. What changed is that one of those programs now writes things down elsewhere: an agent can copy a value into a transcript, a log, or a remote model request [3].

The mechanics are three commands. `jit scan` searches the home directory without modifying files or printing secret values; `jit migrate` moves supported credentials into the vault and rewrites their original locations; `jit run -- <command>` supplies selected values to one process while other software still sees the decoys [7]. The supported inventory covers at least ten credential locations, including `.env` files, shell exports and history, AWS and Terraform credentials, Kubernetes configuration, Docker registry logins, Google Cloud application-default credentials, `.npmrc`, `.netrc` and MCP configuration [8][18]. Documented wrappers cover seven command-line tools, among them GitHub CLI, Stripe, Vercel, Claude, Codex, Gemini and Cursor Agent [9][19].

There are two injection paths, and the distinction is the part worth reading closely. Tools that can ask for a credential do so natively: AWS through `credential_process`, Docker through a credential helper [10]. Tools that only know how to read a file run under `jit run`, which places values into that process's environment [7]. Reads, rejections and unlocks land in a local audit log [11]. According to jit's security architecture, each secret is an individually encrypted file with a separate data key wrapped by a master key in the macOS login Keychain, gated by Touch ID or the device passcode, and the vault does not sync; jitpass says the product needs no account and sends no telemetry [12].

Two things stop this from being a clean boundary. First, jitpass documents rather than denies that a real value can still reach an agent's transcript if the developer authorizes a process that prints it [15]. Second, unattended agents cannot answer a biometric prompt after the screen locks, so jitpass supports time-bounded grants approved in advance: `jit grant --process claude --profile deploy --for 8h` authorizes named secrets for processes descending from a particular terminal session, with each use logged and the grant expiring or revocable [16]. A pre-approved eight-hour window is a smaller hole than a plaintext file, but it is the hole an attacker will aim at.

Tasa describes himself as a cybersecurity operations leader with over a decade across networking, IT and security, and founded the educational CyberBrief Project [6]. The repository showed active development on August 15, 2026, with 587 commits listed [5].

Watch whether the decoy-at-rest plus approved-injection pattern gets adopted by the incumbents. 1Password expanded runtime access for local tools, CI systems and AI-assisted development in February 2026 and ships a Developer Watchtower component [17]. Also watch how grant scoping holds up under process descendants that a developer did not anticipate.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories