0
/ 100
2 days ago
glama

aarifmms/keyblind

Encrypted secrets vault that blinds AI agents to API keys. Stores secrets in AES-256-GCM encrypted SQLite vault, resolves them at runtime via MCP values never appear in LLM conversation transcripts. Sandbox .env files with deterministic fakes.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: STRIPE_SECRET_KEY. We can’t prove the destination matches the brand the credential belongs to.
🚨
Reads files from sensitive locations
Touches: .env, .env
⚠️
Tests do not pass
Either the test suite is broken or the code regressed. Either way the published behaviour can’t be verified by the publisher’s own tests.
🔐
You'll be asked for 6 credentials: JWT_SECRET, KEYBLIND_PUBLIC_KEY, KEYBLIND_SIGNING_KEY, RESEND_API_KEY, STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAZURE_KEY_VAULT
configHOSTNAME
🔐 secretJWT_SECRET
configKEYBLIND_AUTO_INIT
configKEYBLIND_AZURE_VAULT
configKEYBLIND_DEV
🔐 secretKEYBLIND_PUBLIC_KEY
🔐 secretKEYBLIND_SIGNING_KEY
🔐 secretRESEND_API_KEY
configSHELL
🔐 secretSTRIPE_SECRET_KEY
🔐 secretSTRIPE_WEBHOOK_SECRET
config__KEYBLIND_TEST_VAR
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/aarifmms-keyblind-qbtk4g)](https://m8ven.ai/mcp/aarifmms-keyblind-qbtk4g)
commit: 89179ad1864fce087e00c380134d1bb0bb7a8ba4
code hash: b41431bd8573bf222f955d1c0ee640ed857a7b9161bc8a769494242d0b15d546
verified: 6/2/2026, 12:18:40 PM
view raw JSON →