yulinlina

envbouncer

Community yulinlina
Updated

A tiny local MCP server and CLI that lets AI agents read only allowlisted environment variables, redacts known secrets from text, and logs every access.

envbouncer

A tiny local MCP server and CLI that lets AI agents read only allowlisted environment variables, redacts known secrets from text, and logs every access.

License Language Status Python 3.11+ License: MIT MCP

๐ŸŽฏ Why?

AI coding agents and MCP servers often need environment variables, but giving them full shell or .env access risks leaking secrets. Existing guardrails mostly block dangerous shell commands or reduce context, but do not broker environment-variable access at runtime. EnvBouncer fills that gap with a declarative allowlist, redaction tooling, and an audit trail.

Target audience: Developers using Claude Code, Cursor, Codex, or custom MCP servers who want to grant agents limited access to environment configuration without exposing the entire .env file or shell environment.

โœจ Features

  • โœจ Declarative TOML allowlist for environment variables
  • โœจ MCP tools for listing, reading, and redacting allowed variables
  • โœจ CLI commands for init, check, redact, audit, and stdio MCP serving
  • โœจ JSONL audit trail for reads, denials, missing variables, and redactions

๐Ÿš€ Quick Start

# Install
pip install envbouncer

# Run
envbouncer --help

๐Ÿ“ฆ Installation

From Source

git clone https://github.com/YOUR_USERNAME/envbouncer.git
cd envbouncer
# Create virtual environment
python -m venv .venv
source .venv/bin/activate  # Windows: .venv\Scripts\activate

# Install in development mode
pip install -e ".[dev]"

# Run tests
pytest -v

๐ŸŽฌ Demo

The GIF above was recorded using Charm VHS:

vhs < demo.tape

๐Ÿ“– Usage

# Show help
envbouncer --help

# Common usage examples
envbouncer --example

๐Ÿ—๏ธ Architecture

graph LR
    A[Input] --> B[Core Engine]
    B --> C[Output]
    B --> D[Plugins]
    D --> E[Extensions]

๐Ÿค Contributing

Contributions are welcome! Please:

  1. Fork the repo
  2. Create a feature branch (git checkout -b feature/amazing-feature)
  3. Commit your changes (git commit -m 'Add amazing feature')
  4. Push to the branch (git push origin feature/amazing-feature)
  5. Open a Pull Request

๐Ÿ“„ License

MIT ยฉ 2026 โ€” See LICENSE for details.

If this project helped you, please โญ star it!

Made with โค๏ธ and AI

MCP Server ยท Populars

MCP Server ยท New

    DROOdotFOO

    Raxol

    Write one app, render it to a terminal, a browser, or as agent tools. The terminal for your Gundam.

    Community DROOdotFOO
    morluto

    REA: Reverse Engineer Anything

    Reverse engineer anything with agents, from app behavior down to native binaries.

    Community morluto
    nedlir

    MCPwner

    Model Context Protocol server for autonomous vulnerability discovery

    Community nedlir
    codegraph-ai

    CodeGraph

    CodeGraph builds a semantic graph of your codebase โ€” functions, classes, imports, call chains โ€” and exposes it through 42 MCP tools, 38 languages, a VS Code extension, and a persistent memory layer. AI agents get structured code understanding instead of grepping through files.

    Community codegraph-ai
    getArbor-dev

    Arbor

    Graph-native code intelligence that replaces embedding-based RAG with deterministic program understanding.

    Community getArbor-dev