JaneeBLOCK
Secrets management for AI agents via MCP • @janeesecure
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Secrets management for AI agents via MCP
[](https://www.npmjs.com/package/@true-and-useful/janee) [](https://www.npmjs.com/package/@true-and-useful/janee) [](https://opensource.org/licenses/MIT) [](https://github.com/rsdouglas/janee)
Your AI agents need API access to be useful. But they shouldn't have your raw API keys. Janee sits between your agents and your APIs — injecting credentials, enforcing policies, and logging everything.
✨ Features
The Problem
AI agents need API access to be useful. The current approach is to give them your keys and hope they behave.
- 🔓 Agents have full access to Stripe, Gmail, databases
- 📊 No audit trail of what was accessed or why
- 🚫 No kill switch when things go wrong
- 💉 One prompt injecti
d568536016f3OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add janee -- npx -y @true-and-useful/[email protected]
Exposed tools (41)
34 read · 7 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
airtable | read | Spreadsheet-database hybrid |
anthropic | read | Anthropic Claude API |
aws-s3 | read | Amazon S3 — object storage |
aws-ses | write | Amazon Simple Email Service — send and receive email |
bybit | read | Cryptocurrency derivatives exchange |
cal | read | Cal.com scheduling API |
cloudflare | read | CDN and edge computing platform |
coinbase | read | Cryptocurrency exchange (Advanced Trade API) |
discord | read | Chat platform for communities |
doctor | write | Run runner-to-authority diagnostics. Checks authority reachability, authentication, tool forwarding, and identity parity. Only available when running in runner mode. |
execute | write | Execute an API request through Janee proxy |
explain_access | read | Trace exactly why a given agent can or cannot access a capability. Returns step-by-step policy evaluation (capability exists, mode, allowedAgents, defaultAccess, ownership, rules). Use for debugging access issues. |
github | read | Code hosting and collaboration |
github-app | read | GitHub App with installation tokens (for autonomous agents) |
google-analytics | read | Google Analytics Data API |
janee_exec | write | Execute a CLI command with credentials injected via environment variables. The agent never sees the actual credential — Janee injects it and scrubs output. |
janee_execute | write | Execute an API request through Janee with stored credentials. Use janee_list_services first to see available services. All requests are logged for audit. |
janee_list_services | read | List available API services managed by Janee. Shows which services have stored credentials. |
janee_reload_config | read | Reload Janee configuration from disk. Use after adding or modifying services in ~/.janee/config.yaml to pick up changes without restarting. |
linear | read | Issue tracking for software teams |
list_services | read | List available API capabilities managed by Janee |
manage_credential | read | View or manage access policies for agent-scoped credentials. Agents can check who has access, grant access to other agents, or revoke access. |
mexc | read | Cryptocurrency exchange |
mixpanel | read | Product analytics |
notion | read | All-in-one workspace |
okx | read | Cryptocurrency exchange |
openai | read | OpenAI API for GPT and DALL-E |
planetscale | read | Serverless MySQL platform |
posthog | read | Product analytics platform |
reload_config | read | Reload Janee configuration from disk without restarting the server. Use after adding new services or capabilities. |
replicate | write | Run ML models in the cloud |
resend | read | Modern email API |
sendgrid | read | Email delivery service |
slack | read | Team communication platform |
stripe | read | Payment processing platform |
supabase | read | Open source Firebase alternative |
test_service | read | Test connectivity and authentication for a configured service. Verifies that Janee can reach the service and that credentials are valid. |
twilio | read | Communication APIs (SMS, Voice) |
twitter | write | Twitter/X API v2 — post tweets, read timeline |
vercel | read | Frontend deployment platform |
whoami | read | Show your resolved agent identity as Janee sees it, which capabilities you can access, and the server access policy. Useful for understanding allowedAgents restrictions. |
Trust audit
BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
"private_key": "-----BEGIN PRIVATE KEY-----\nMIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQC7VJTUt9Us8cKj\nMzEfYyjiWA4R4/M2bS1+fWIcPm15j7A9kNK8wH2bapLW+fYUb3kDpKQDTQFT+7TI\nmTqKQdZx9Xfp6hqW9aRMC8V
const raw = yaml.load(content) as any;
const rawConfig = yaml.load(rawContent) as any;
const config = yaml.load(content) as JaneeYAMLConfig;
Manage access to agent-scoped credentials.
console.log(data.token);
console.log(` Token: ${token1.substring(0, 20)}...`);const secret = 'super-secret-token-12345';
const API_KEY = "test-runner-key-12345678";
"private_key": "-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----\n",
private_key: '-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----\n',
private_key: '-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----\n',
private_key: '-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----\n',
"SLACK_BOT_TOKEN": "xoxb-your-actual-token-here" // ❌ Exposed
- Key: `xoxb-your-bot-token` (or `xoxp-` for user token)
-k xoxb-your-bot-token
Authorization: Bearer xoxb-your-token
janee add work-slack -u https://slack.com/api -t bearer -k xoxb-work-token
const parsedYaml = yaml.load(yamlOnDisk) as any;
vi.mock('../../core/directory', () => ({} from '../../core/directory';
} from '../../core/github-app';
} from '../../core/service-account';
import { AuditLogger } from '../../core/audit';let reqPath = 'https://evil.com/exfiltrate';
Gates applied: critical_finding, no_behavioural_pass.
d568536016f3full audit observations/trust-audit/mcp-server/rsdouglas__janee.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | d568536016f3 | BLOCK | F | 46 | first audit |
Questions
What is the Janee MCP server?
Secrets management for AI agents via MCP • @janeesecure
What tools does Janee expose?
41 in total: 34 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Janee safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (46/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Janee need?
It reads JANEE_DB_PASSWORD, JANEE_RUNNER_KEY, STRIPE_API_KEY and TEST_SECRET_VALUE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Janee run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @true-and-useful/janee-openclaw at 0.3.2.
How current is this page?
The grade is for one exact copy of the source (d568536016f3), read on 2026-10-08. The repository is watched and re-audited when it changes.