Discover secrets
ShellFrame scans local project configuration before the agent starts and asks the developer what should be protected.
Local-first security for AI coding agents
ShellFrame AI gives Claude, Codex, Cursor, and other coding agents short-lived virtual credentials while real API keys stay protected on the developer machine.
$ agentsecure run claude
found .env secrets
DATABASE_URL=virt_database_J8s...
STRIPE_API_KEY=virt_stripe_N4d...
runtime: command-guard
network: credential-aware
cloud: reporting security events only
How it works
ShellFrame scans local project configuration before the agent starts and asks the developer what should be protected.
The agent sees temporary virtual values. Real credentials are resolved locally only when policy allows the request.
Credential-bearing network calls are checked before they leave the machine, with security events sent to the console.
Trust model
ShellFrame is built around a local-first boundary. The cloud console manages policy, devices, sessions, and security events. Secret material stays on the developer machine.
For teams
Configure default protection for every enrolled machine, see which agents are running, review blocked requests, and clean up stale devices from one cloud console.
Go to console