Skip to content

AVP

AI Agents & Assistants

A local HTTPS proxy that injects real secrets into outbound requests so callers only ever see placeholders, protecting against credential‑stealing attacks.

Python Latest v0.9.0 · 1d ago Security brief →

Features

  • Just‑in‑time injection of API keys and other secrets via a loopback HTTPS proxy
  • Supports multiple vault backends (Bitwarden Secrets Manager, Google Secret Manager, static YAML)
  • Zero‑trust audit logging with optional off‑box shipping
  • CLI (`avp`) for adding secrets, generating env files, and launching agents securely
  • Skill integration (`avp-bindings`) lets AI assistants provision bindings without editing config

Recent releases

View all 7 releases →
Review required
v0.9.0 Breaking risk
Auth RBAC

Stored placeholders + scoped TLS

Review required
v0.8.0 Breaking risk
Auth RBAC Breaking upgrade

GSM backend + honeytoken + healthz

Review required
v0.7.0 Breaking risk
Auth

Host validation + OAuth2 refresh + templating

No immediate action
v0.4.3 Bug fix

Version sync + smoke test

No immediate action
v0.4.2 Bug fix

Smoke test assertion fix + TEST_SECRET handling

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
24
Forks
1
Languages
Python Shell Dockerfile

Install & Platforms

Install via
pipx brew docker
Platforms
linux macos

Alternative to

Vault Agent Doppler op (1password CLI) superfly/tokenizer

Beta — feedback welcome: [email protected]