Jitpass logo

Jitpass

A malicious NPM install reads your .env. On my Mac it reads a decoy

Share on:
Listing image

Find the plaintext secrets on your Mac and move them into an encrypted vault. Your files keep working, and only the command you run gets the real value.

jit · just-in-time passwords for developer endpoints jit _ why jit what it stops ai agents automation supported tools blog github follow Install ◐ free for personal & internal company use There is a live API key in plaintext on your Mac. It sits in .env , in ~/.aws/credentials , in ~/.zsh_history . One compromised package or one hijacked agent, and it is gone, silently. jit locks the real values away and leaves decoys in your files. Your tools keep working. Whatever gets stolen is worthless. jit protects your secrets from: prompt-injected agents compromised npm packages trojanized IDE exte

Related listings

See the trading patterns costing you money

Know Which Pull Request to Review Next

Make AI Markdown easier to read

Local static analysis for coding agents

Cinematic Travel Animations

An AI news API that returns events, not articles