Envelope-encrypted team secrets your AI agent can use but never read. Zero dependencies, zero servers — your git repo is the backend.
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
hush_list_secretsList the NAMES of secrets available in one named set of the current project's vault.List the NAMES of secrets available in one named set of the current project's vault.
No input schema was published for this tool.
hush_list_setsList every named set the agent could use with this project: sets in the user's ownList every named set the agent could use with this project: sets in the user's own
No input schema was published for this tool.
hush_list_accountsDeprecated (removed in hush 2.0), use hush_list_sets — this returns exactly the same thing. Kept registeredDeprecated (removed in hush 2.0), use hush_list_sets — this returns exactly the same thing. Kept registered
No input schema was published for this tool.
hush_check_repoScan the current codebase for the environment variables it references, and report whichScan the current codebase for the environment variables it references, and report which
No input schema was published for this tool.
hush_runRun a shell command with the project's secrets injected as environment variables.Run a shell command with the project's secrets injected as environment variables.
No input schema was published for this tool.
hush_requestMake an authenticated HTTP request without the credential ever entering thisMake an authenticated HTTP request without the credential ever entering this
No input schema was published for this tool.
hush_add_secretAdd a credential to the vault WITHOUT it passing through this conversation.Add a credential to the vault WITHOUT it passing through this conversation.
No input schema was published for this tool.
hush_provisionPrepare a CLI or codebase to run with the right credentials. Give it a tool namePrepare a CLI or codebase to run with the right credentials. Give it a tool name
No input schema was published for this tool.
hush_describe_secretDescribe one secret without revealing it: whether it exists, its length, a maskedDescribe one secret without revealing it: whether it exists, its length, a masked
No input schema was published for this tool.
9 of 9 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Envelope-encrypted team secrets your AI agent can use but never read. Zero dependencies, zero servers — your git repo is the backend.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.