Atlas / MCP servers / rsdouglas / Janee

JaneeBLOCK

mcp/rsdouglas/janee

Secrets management for AI agents via MCP • @janeesecure

Verdict
BLOCK
Grade
F
Trust score
46 /100
Exposed tools
41 34r · 7w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
30
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Secrets management for AI agents via MCP

[](https://www.npmjs.com/package/@true-and-useful/janee) [](https://www.npmjs.com/package/@true-and-useful/janee) [](https://opensource.org/licenses/MIT) [](https://github.com/rsdouglas/janee)

Your AI agents need API access to be useful. But they shouldn't have your raw API keys. Janee sits between your agents and your APIs — injecting credentials, enforcing policies, and logging everything.

✨ Features

The Problem

AI agents need API access to be useful. The current approach is to give them your keys and hope they behave.

  • 🔓 Agents have full access to Stripe, Gmail, databases
  • 📊 No audit trail of what was accessed or why
  • 🚫 No kill switch when things go wrong
  • 💉 One prompt injecti
Read from source at commit d568536016f3OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add janee -- npx -y @true-and-useful/[email protected]
03

Exposed tools (41)

34 read · 7 write · 0 destructive.

ToolRiskDescription
airtablereadSpreadsheet-database hybrid
anthropicreadAnthropic Claude API
aws-s3readAmazon S3 — object storage
aws-seswriteAmazon Simple Email Service — send and receive email
bybitreadCryptocurrency derivatives exchange
calreadCal.com scheduling API
cloudflarereadCDN and edge computing platform
coinbasereadCryptocurrency exchange (Advanced Trade API)
discordreadChat platform for communities
doctorwriteRun runner-to-authority diagnostics. Checks authority reachability, authentication, tool forwarding, and identity parity. Only available when running in runner mode.
executewriteExecute an API request through Janee proxy
explain_accessreadTrace exactly why a given agent can or cannot access a capability. Returns step-by-step policy evaluation (capability exists, mode, allowedAgents, defaultAccess, ownership, rules). Use for debugging access issues.
githubreadCode hosting and collaboration
github-appreadGitHub App with installation tokens (for autonomous agents)
google-analyticsreadGoogle Analytics Data API
janee_execwriteExecute a CLI command with credentials injected via environment variables. The agent never sees the actual credential — Janee injects it and scrubs output.
janee_executewriteExecute an API request through Janee with stored credentials. Use janee_list_services first to see available services. All requests are logged for audit.
janee_list_servicesreadList available API services managed by Janee. Shows which services have stored credentials.
janee_reload_configreadReload Janee configuration from disk. Use after adding or modifying services in ~/.janee/config.yaml to pick up changes without restarting.
linearreadIssue tracking for software teams
list_servicesreadList available API capabilities managed by Janee
manage_credentialreadView or manage access policies for agent-scoped credentials. Agents can check who has access, grant access to other agents, or revoke access.
mexcreadCryptocurrency exchange
mixpanelreadProduct analytics
notionreadAll-in-one workspace
okxreadCryptocurrency exchange
openaireadOpenAI API for GPT and DALL-E
planetscalereadServerless MySQL platform
posthogreadProduct analytics platform
reload_configreadReload Janee configuration from disk without restarting the server. Use after adding new services or capabilities.
replicatewriteRun ML models in the cloud
resendreadModern email API
sendgridreadEmail delivery service
slackreadTeam communication platform
stripereadPayment processing platform
supabasereadOpen source Firebase alternative
test_servicereadTest connectivity and authentication for a configured service. Verifies that Janee can reach the service and that credentials are valid.
twilioreadCommunication APIs (SMS, Voice)
twitterwriteTwitter/X API v2 — post tweets, read timeline
vercelreadFrontend deployment platform
whoamireadShow your resolved agent identity as Janee sees it, which capabilities you can access, and the server access policy. Useful for understanding allowedAgents restrictions.
04

Trust audit

BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
scripts/test-add-service-account.sh:17
"private_key": "-----BEGIN PRIVATE KEY-----\nMIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQC7VJTUt9Us8cKj\nMzEfYyjiWA4R4/M2bS1+fWIcPm15j7A9kNK8wH2bapLW+fYUb3kDpKQDTQFT+7TI\nmTqKQdZx9Xfp6hqW9aRMC8V
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/cli/config-yaml.ts:308
const raw = yaml.load(content) as any;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/cli/config-yaml.ts:357
const rawConfig = yaml.load(rawContent) as any;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/cli/config-yaml.ts:364
const config = yaml.load(content) as JaneeYAMLConfig;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SKILL.md:47
Manage access to agent-scoped credentials.
Why it matters. asks the agent to read credentials
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/create-gh-app/create-gh-app.mjs:262
console.log(data.token);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/test-service-account.ts:112
console.log(`   Token: ${token1.substring(0, 20)}...`);
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/core/exec.test.ts:199
const secret = 'super-secret-token-12345';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/core/timeout-propagation.test.ts:28
const API_KEY = "test-runner-key-12345678";
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/rfcs/0002-service-account-auth.md:131
"private_key": "-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----\n",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/core/service-account.test.ts:22
private_key: '-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----\n',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/core/service-account.test.ts:72
private_key: '-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----\n',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/core/service-account.test.ts:82
private_key: '-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----\n',
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/integration-slack-mcp.md:19
"SLACK_BOT_TOKEN": "xoxb-your-actual-token-here"  // ❌ Exposed
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/integration-slack-mcp.md:60
- Key: `xoxb-your-bot-token` (or `xoxp-` for user token)
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/integration-slack-mcp.md:67
-k xoxb-your-bot-token
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/integration-slack-mcp.md:128
Authorization: Bearer xoxb-your-token
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/integration-slack-mcp.md:161
janee add work-slack -u https://slack.com/api -t bearer -k xoxb-work-token
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/cli/config-yaml.test.ts:366
const parsedYaml = yaml.load(yamlOnDisk) as any;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/add-headers.test.ts:16
vi.mock('../../core/directory', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/add.ts:15
} from '../../core/directory';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/add.ts:19
} from '../../core/github-app';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/add.ts:23
} from '../../core/service-account';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/authority.ts:2
import { AuditLogger } from '../../core/audit';
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
src/cli/commands/serve-mcp.test.ts:19
let reqPath = 'https://evil.com/exfiltrate';

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha d568536016f3full audit observations/trust-audit/mcp-server/rsdouglas__janee.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08d568536016f3BLOCKF46first audit
06

Questions

What is the Janee MCP server?

Secrets management for AI agents via MCP • @janeesecure

What tools does Janee expose?

41 in total: 34 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Janee safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (46/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Janee need?

It reads JANEE_DB_PASSWORD, JANEE_RUNNER_KEY, STRIPE_API_KEY and TEST_SECRET_VALUE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Janee run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @true-and-useful/janee-openclaw at 0.3.2.

How current is this page?

The grade is for one exact copy of the source (d568536016f3), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement