Offsend CLI

Open-source CLI that keeps secrets out of AI coding agents

Intermediate
Screenshot of Offsend CLI, Open-source CLI that keeps secrets out of AI coding agents

What is Offsend CLI?

Offsend CLI is an open-source, local-first tool that defines what AI coding agents can see through one .offsend.yml file, tokenizing secrets, syncing ignore files, gating prompts and tools, and checking policy in CI.

Offsend CLI is an open-source, local-first boundary layer that sits between a developer's projects and the AI coding agents that read them. A single policy file, .offsend.yml, committed to git, describes what the agent may see. Once installed, secrets are swapped for tokens, so the agent continues to work on the code while the plaintext values stay out of its context. The tool is aimed at developers and teams who use Cursor, Claude Code, Windsurf or Codex and want a practical guardrail against leaking keys, credentials and sensitive files into prompts. Installation is a single shell command (also available through Homebrew on macOS and Linux), which runs the setup step automatically. That step creates a seal key and installs user-level Cursor and Claude hooks that work in any folder, with no YAML needed. In a repository the team owns, init writes the policy file, protect adds exposed paths, and sync generates AI ignore files plus git and editor hooks. A GitHub Action runs the same check in CI and can fail a build on secrets or ignore drift. Runtime gates inspect prompts, file reads, writes, shell commands and MCP arguments on editors that expose those hooks. Cursor and Claude Code can also seal secrets inside MCP responses, and sealed values can be restored from an agent reply with the unseal command through clipboard, file or pipe. Without the key, secret-bearing MCP output is withheld rather than passed through. Local transcripts can be audited and scrubbed afterward, and all checks run locally without uploading code. Offsend is candid about its limits. It is defense-in-depth rather than a guarantee, coverage varies by editor (Codex is prompt-only, Windsurf lacks MCP response sealing), and cloud agent sessions bypass local hooks. It includes content scanning but is not a replacement for history-focused scanners such as Gitleaks, TruffleHog or GitGuardian, and is best used alongside them. Companion pieces include a macOS desktop app, a browser extension, an online repository check and a research feed called Radar.

How do you use Offsend CLI?

  1. 1Install the CLI
    Run the curl install command from the homepage, or use Homebrew on macOS or Linux. The installer also runs offsend setup, which creates the seal key and user-level Cursor and Claude hooks.
    Offsend CLI — Install the CLI
  2. 2Check the machine with doctor
    Run offsend doctor to confirm the CLI, seal key and user hooks are in place. No .offsend.yml is needed at this stage.
  3. 3Initialize a policy in your repo
    In a repository you own, run offsend init with a template such as node to write .offsend.yml. Then run offsend protect to add exposed paths to the policy.
  4. 4Sync ignore files and hooks
    Run offsend sync to generate AI ignore files and install git and editor hooks, then commit .offsend.yml. After cloning a repo that already has the file, run sync again.
  5. 5Add the GitHub Action
    Add the Offsend ai-hygiene action to your workflow with fail-on set to block and policy enabled, so CI fails on secrets and ignore drift.
    Offsend CLI — Add the GitHub Action
  6. 6Audit a public repo without installing
    Use the online Check page to run a quick repository audit before committing to a local install.
    Offsend CLI — Audit a public repo without installing

Pros and cons

Pros

  • Runs locally and does not upload code, so no cloud scanning account is neededAI
  • One committed .offsend.yml gives a team a single source of truth for AI context rulesAI
  • Secrets become tokens, so agents keep working and replies can be restored with unsealAI
  • Runtime gates cover prompts, file access, shell and MCP on Cursor and Claude CodeAI
  • Open source with a GitHub Action, so the same check runs in CIAI

Cons

  • Defense-in-depth only: the vendor states it cannot guarantee an agent never reads a fileAI
  • Codex support is prompt-only, with no file or MCP gates yetAI
  • Windsurf has no MCP response seal, and Claude subagents are not gatedAI
  • Cloud agent sessions never run local hooks, so they sit outside its protectionAI
  • Not a substitute for deep git-history secret scanning; pairing with other scanners is advisedAI

How much does Offsend CLI cost?

Support

The homepage points to CLI documentation hosted on GitHub. No dedicated support channel is described.

Integrations

Works with Cursor, Claude Code, Windsurf and Codex through hooks, generates ignore files for Copilot, Continue, Gemini, Aider, Cline, Roo, Zed and Cody, and ships a GitHub Action. Related products include a macOS desktop app and browser extension.

Learn more

Features

Single .offsend.yml policy, seal key and secret tokenization, AI ignore file sync, runtime gates for prompts, reads, writes, shell and MCP, MCP response sealing on Cursor and Claude Code, unseal restore, content scanning, transcript audit, git hooks and a CI check.

Frequently asked questions about Offsend CLI

  • How do you use Offsend CLI?
    The walkthrough on this page covers 6 steps: 1. Install the CLI 2. Check the machine with doctor 3. Initialize a policy in your repo 4. Sync ignore files and hooks 5. Add the GitHub Action 6. Audit a public repo without installing.
  • What platforms does Offsend CLI support?
    Offsend CLI is available on MacOS and Linux.
  • What does Offsend CLI integrate with?
    Works with Cursor, Claude Code, Windsurf and Codex through hooks, generates ignore files for Copilot, Continue, Gemini, Aider, Cline, Roo, Zed and Cody, and ships a GitHub Action. Related products include a macOS desktop app and browser extension.
  • What are the limitations of Offsend CLI?
    Defense-in-depth only: the vendor states it cannot guarantee an agent never reads a file. Codex support is prompt-only, with no file or MCP gates yet. Windsurf has no MCP response seal, and Claude subagents are not gated.

Status

StatusActive
Views0
Outbound clicks0
Added10/8/2026

Platforms

MacOSLinux

Pricing

Free

Categories