{"_id":"@aictrl/hush","_rev":"5-d3ca997fad68dafecddbe3ce5aeb347c","name":"@aictrl/hush","dist-tags":{"latest":"0.1.8"},"versions":{"0.1.0":{"name":"@aictrl/hush","version":"0.1.0","keywords":["mcp","ai","security","redaction","pii","gateway"],"author":{"name":"AICtrl Team"},"license":"Apache-2.0","_id":"@aictrl/hush@0.1.0","maintainers":[{"name":"byapparov","email":"bulat@aictrl.dev"}],"bin":{"hush":"dist/cli.js"},"dist":{"shasum":"b4ea48b4fe1341153c74dc5fc86a09e20126eb13","tarball":"https://registry.npmjs.org/@aictrl/hush/-/hush-0.1.0.tgz","fileCount":27,"integrity":"sha512-z67iCytLMhJr+g/RF7+6OGz7LQlD4OgJdhcWJStqqFHSmXih9EdilCVu4H9Z8eUslF/BUISjqN7ilO4qu0pBvw==","signatures":[{"sig":"MEYCIQCnXVaj/hULB4cWl7erj7N6LONimGOwTS+lMogsWL5LBAIhAJfXvL6FbxrLxc6PFzBWvOtAZ5Ln06o4MyMMkPoLmXxX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":71366},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","gitHead":"a23dc00beadce126973c06a57b8c570f2c6ad0fe","scripts":{"dev":"tsx src/cli.ts","lint":"eslint src/**/*.ts","test":"vitest run --coverage","build":"tsc","start":"node dist/cli.js","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","test:e2e":"./scripts/e2e-opencode.sh","test:watch":"vitest"},"_npmUser":{"name":"byapparov","email":"bulat@aictrl.dev"},"_npmVersion":"10.8.2","description":"Hush: A Semantic Security Gateway for AI Agents. Redacts PII from prompts and tool outputs locally before they hit the cloud.","directories":{},"_nodeVersion":"20.19.5","dependencies":{"cors":"^2.8.6","pino":"^10.3.1","dotenv":"^17.3.1","blessed":"^0.1.81","express":"^5.2.1","pino-pretty":"^13.1.3","blessed-contrib":"^4.11.0","@modelcontextprotocol/sdk":"^1.27.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","nock":"^14.0.11","vitest":"^4.0.18","supertest":"^7.2.2","typescript":"^5.9.3","@types/cors":"^2.8.19","@types/node":"^25.3.3","@types/blessed":"^0.1.27","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/hush_0.1.0_1772384499566_0.061635520636785346","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@aictrl/hush","version":"0.1.5","keywords":["mcp","ai","security","redaction","pii","gateway"],"author":{"name":"AICtrl Team"},"license":"Apache-2.0","_id":"@aictrl/hush@0.1.5","maintainers":[{"name":"byapparov","email":"bulat@aictrl.dev"}],"homepage":"https://github.com/aictrl-dev/hush#readme","bugs":{"url":"https://github.com/aictrl-dev/hush/issues"},"bin":{"hush":"dist/cli.js"},"dist":{"shasum":"836003684e48f4989e4e2bae98c0048f6e09a41b","tarball":"https://registry.npmjs.org/@aictrl/hush/-/hush-0.1.5.tgz","fileCount":52,"integrity":"sha512-n4x41QVWWSDP+FYjX4GGK2ruuTL6Q2/g7AxL/H/IVihCAO9wGGZ4Iidmvhw6gcSl9tCmXUVIxfEvuRQtHBsrXA==","signatures":[{"sig":"MEYCIQC/FinizDLBA7vjeR2UFBT5YJe2pREYTKwS49jOL5SwRgIhAO9tY79hLCOorbRR51RQQGWu8QEFY43bUF9V+lY31Gu+","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aictrl%2fhush@0.1.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":159059},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","gitHead":"4ddbf11338d18969442d62127911bd7e63250d20","scripts":{"dev":"tsx src/cli.ts","lint":"eslint src/**/*.ts","test":"vitest run --coverage","build":"tsc","start":"node dist/cli.js","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","test:e2e":"./scripts/e2e-opencode.sh","test:watch":"vitest"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4ac1ea26-c61b-4279-9edc-f2b4e659a27e"}},"repository":{"url":"git+https://github.com/aictrl-dev/hush.git","type":"git"},"_npmVersion":"11.8.0","description":"Hush: A Semantic Security Gateway for AI Agents. Redacts PII from prompts and tool outputs locally before they hit the cloud.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"cors":"^2.8.6","pino":"^10.3.1","dotenv":"^17.3.1","blessed":"^0.1.81","express":"^5.2.1","pino-pretty":"^13.1.3","blessed-contrib":"^4.11.0","@modelcontextprotocol/sdk":"^1.27.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","nock":"^14.0.11","vitest":"^4.0.18","supertest":"^7.2.2","typescript":"^5.9.3","@types/cors":"^2.8.19","@types/node":"^25.3.3","@types/blessed":"^0.1.27","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/hush_0.1.5_1772399534811_0.4298856796748529","host":"s3://npm-registry-packages-npm-production"}},"0.1.6":{"name":"@aictrl/hush","version":"0.1.6","keywords":["mcp","ai","security","redaction","pii","gateway"],"author":{"name":"AICtrl Team"},"license":"Apache-2.0","_id":"@aictrl/hush@0.1.6","maintainers":[{"name":"byapparov","email":"bulat@aictrl.dev"}],"homepage":"https://github.com/aictrl-dev/hush#readme","bugs":{"url":"https://github.com/aictrl-dev/hush/issues"},"bin":{"hush":"dist/cli.js"},"dist":{"shasum":"d157a019061bbfd1233fbc4fdd528c09d9954b5c","tarball":"https://registry.npmjs.org/@aictrl/hush/-/hush-0.1.6.tgz","fileCount":52,"integrity":"sha512-7f6Bro34OjcqxCUtYBd19SpCXpX0JGgLL39+2ZHkuk92QZn3XpXHQr5LZ7ZwuSwN5K2hMkoNNET5u+PsAORvhg==","signatures":[{"sig":"MEYCIQCNQL3WJ7O478uYToQoKJnqc4Dzb7yezvRBpIuOEi8K1AIhAI8IG2TVyh3P3wpI0lOSWK8rP6bM+lRIXn59l7mvF2p/","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aictrl%2fhush@0.1.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":159962},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","gitHead":"c41ece9034a946d569165e6f1e651f2d9cb2daf4","scripts":{"dev":"tsx src/cli.ts","lint":"eslint src/**/*.ts","test":"vitest run --coverage","build":"tsc","start":"node dist/cli.js","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","test:e2e":"./scripts/e2e-opencode.sh","test:watch":"vitest"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4ac1ea26-c61b-4279-9edc-f2b4e659a27e"}},"repository":{"url":"git+https://github.com/aictrl-dev/hush.git","type":"git"},"_npmVersion":"11.8.0","description":"Hush: A Semantic Security Gateway for AI Agents. Redacts PII from prompts and tool outputs locally before they hit the cloud.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"cors":"^2.8.6","pino":"^10.3.1","dotenv":"^17.3.1","blessed":"^0.1.81","express":"^5.2.1","pino-pretty":"^13.1.3","blessed-contrib":"^4.11.0","@modelcontextprotocol/sdk":"^1.27.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","nock":"^14.0.11","vitest":"^4.0.18","supertest":"^7.2.2","typescript":"^5.9.3","@types/cors":"^2.8.19","@types/node":"^25.3.3","@types/blessed":"^0.1.27","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/hush_0.1.6_1772401835983_0.2296726960777784","host":"s3://npm-registry-packages-npm-production"}},"0.1.7":{"name":"@aictrl/hush","version":"0.1.7","keywords":["mcp","ai","security","redaction","pii","gateway"],"author":{"name":"AICtrl Team"},"license":"Apache-2.0","_id":"@aictrl/hush@0.1.7","maintainers":[{"name":"byapparov","email":"bulat@aictrl.dev"}],"homepage":"https://github.com/aictrl-dev/hush#readme","bugs":{"url":"https://github.com/aictrl-dev/hush/issues"},"bin":{"hush":"dist/cli.js"},"dist":{"shasum":"5873771284c43784ee26586f677857d326db5fcb","tarball":"https://registry.npmjs.org/@aictrl/hush/-/hush-0.1.7.tgz","fileCount":82,"integrity":"sha512-VfHLQUqeXODQ+WChLW01dHF4svEUeb8guejaPPVyG23vaYQRYDsqD6uMjLAxOY0jCAQ8AynP4QneOOP0S5MZqw==","signatures":[{"sig":"MEQCIHW+3XUNDB0CPNw9SlKL/VxtTfB81AzJXAauJTBQDBp1AiBJAQzjHN9ioK9dwuu+5x8zcgfcQ686teZPNaZBmyIJgA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aictrl%2fhush@0.1.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":238381},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./opencode-plugin":{"types":"./dist/plugins/opencode-hush.d.ts","import":"./dist/plugins/opencode-hush.js"}},"gitHead":"2543e868bb2fa7be1abbaf9ebb9b9637dddbcf14","scripts":{"dev":"tsx src/cli.ts","lint":"eslint src/**/*.ts","test":"vitest run --coverage","build":"tsc","start":"node dist/cli.js","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","test:e2e":"./scripts/e2e-opencode.sh","test:watch":"vitest"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4ac1ea26-c61b-4279-9edc-f2b4e659a27e"}},"repository":{"url":"git+https://github.com/aictrl-dev/hush.git","type":"git"},"_npmVersion":"11.8.0","description":"Hush: A Semantic Security Gateway for AI Agents. Redacts PII from prompts and tool outputs locally before they hit the cloud.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"cors":"^2.8.6","pino":"^10.3.1","dotenv":"^17.3.1","blessed":"^0.1.81","express":"^5.2.1","pino-pretty":"^13.1.3","blessed-contrib":"^4.11.0","@modelcontextprotocol/sdk":"^1.27.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","nock":"^14.0.11","vitest":"^4.0.18","supertest":"^7.2.2","typescript":"^5.9.3","@types/cors":"^2.8.19","@types/node":"^25.3.3","@types/blessed":"^0.1.27","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/hush_0.1.7_1772462350297_0.09248870479576565","host":"s3://npm-registry-packages-npm-production"}},"0.1.8":{"name":"@aictrl/hush","version":"0.1.8","description":"Hush: A Semantic Security Gateway for AI Agents. Redacts PII from prompts and tool outputs locally before they hit the cloud.","type":"module","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"},"./opencode-plugin":{"import":"./dist/plugins/opencode-hush.js","types":"./dist/plugins/opencode-hush.d.ts"}},"bin":{"hush":"dist/cli.js"},"scripts":{"build":"tsc","start":"node dist/cli.js","dev":"tsx src/cli.ts","test":"vitest run --coverage","test:e2e":"./scripts/e2e-opencode.sh","test:watch":"vitest","lint":"eslint src/**/*.ts","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\""},"keywords":["mcp","ai","security","redaction","pii","gateway"],"repository":{"type":"git","url":"git+https://github.com/aictrl-dev/hush.git"},"author":{"name":"AICtrl Team"},"license":"Apache-2.0","dependencies":{"@modelcontextprotocol/sdk":"^1.27.1","blessed":"^0.1.81","blessed-contrib":"^4.11.0","cors":"^2.8.6","dotenv":"^17.3.1","express":"^5.2.1","pino":"^10.3.1","pino-pretty":"^13.1.3"},"devDependencies":{"@types/blessed":"^0.1.27","@types/cors":"^2.8.19","@types/express":"^5.0.6","@types/node":"^25.3.3","@types/supertest":"^7.2.0","@vitest/coverage-v8":"^4.0.18","nock":"^14.0.11","supertest":"^7.2.2","tsx":"^4.19.2","typescript":"^5.9.3","vitest":"^4.0.18"},"gitHead":"0a64002d71b36da111f0eebe7d797482c74fc2a4","_id":"@aictrl/hush@0.1.8","bugs":{"url":"https://github.com/aictrl-dev/hush/issues"},"homepage":"https://github.com/aictrl-dev/hush#readme","_nodeVersion":"24.13.1","_npmVersion":"11.8.0","dist":{"integrity":"sha512-LN0OgeiRA4qM16ChbTNHxVl0MXbAzXv8FZ/wIr/drlIZulgnx6QSFFnJCzJNDfd9Ic4Fqcijoq8GixwtXmzhig==","shasum":"1cc0075d24000e89728fa2aa01b8a725e3738f3d","tarball":"https://registry.npmjs.org/@aictrl/hush/-/hush-0.1.8.tgz","fileCount":83,"unpackedSize":289953,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aictrl%2fhush@0.1.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD6BFc0Mw66/hBjp34bSzAQQr4QXyVD782EPI8K/GeyFgIgBrKSjnC8OElXIIQ5ucmOjrb9MtPe/v1QzXujJhZX+Vw="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4ac1ea26-c61b-4279-9edc-f2b4e659a27e"}},"directories":{},"maintainers":[{"name":"byapparov","email":"bulat@aictrl.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/hush_0.1.8_1772528854040_0.7122360526348417"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-01T17:01:39.471Z","modified":"2026-03-03T09:07:34.483Z","0.1.0":"2026-03-01T17:01:39.710Z","0.1.5":"2026-03-01T21:12:14.963Z","0.1.6":"2026-03-01T21:50:36.132Z","0.1.7":"2026-03-02T14:39:10.443Z","0.1.8":"2026-03-03T09:07:34.209Z"},"bugs":{"url":"https://github.com/aictrl-dev/hush/issues"},"author":{"name":"AICtrl Team"},"license":"Apache-2.0","homepage":"https://github.com/aictrl-dev/hush#readme","keywords":["mcp","ai","security","redaction","pii","gateway"],"repository":{"type":"git","url":"git+https://github.com/aictrl-dev/hush.git"},"description":"Hush: A Semantic Security Gateway for AI Agents. Redacts PII from prompts and tool outputs locally before they hit the cloud.","maintainers":[{"name":"byapparov","email":"bulat@aictrl.dev"}],"readme":"<p align=\"center\">\n  <img src=\"logo.svg\" width=\"400\" alt=\"hush Logo\" />\n</p>\n\n**hush** is a Semantic Security Gateway for AI agents.\nIt sits between your AI tools (Claude Code, Codex, OpenCode, Gemini CLI) and LLM providers, ensuring that sensitive data — emails, IP addresses, API keys, credit cards — never leaves your machine.\n\n## Quick Start\n\n```bash\nnpm install -g @aictrl/hush\nhush\n```\n\nHush starts on `http://127.0.0.1:4000`. Now point your AI tool at it:\n\n### Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"env\": {\n    \"ANTHROPIC_BASE_URL\": \"http://127.0.0.1:4000\"\n  }\n}\n```\n\n> **Note:** Claude Code subscription (OAuth) tokens are currently blocked by Anthropic for third-party proxies ([anthropics/claude-code#28091](https://github.com/anthropics/claude-code/issues/28091)). If you hit a 401, add `\"ANTHROPIC_AUTH_TOKEN\": \"sk-ant-...\"` to the env block above.\n\n### Codex (OpenAI)\n\nAdd to `~/.codex/config.toml` (or `.codex/config.toml` in your project):\n\n```toml\nmodel_provider = \"hush\"\n\n[model_providers.hush]\nbase_url = \"http://127.0.0.1:4000/v1\"\n```\n\n### OpenCode (ZhipuAI GLM-5)\n\nCreate `opencode.json` in your project root:\n\n```json\n{\n  \"provider\": {\n    \"zai-coding-plan\": {\n      \"options\": {\n        \"baseURL\": \"http://127.0.0.1:4000/api/coding/paas/v4\"\n      }\n    }\n  }\n}\n```\n\n### Gemini CLI\n\nAdd `.gemini/.env` to your project root (or set the env var directly):\n\n```bash\n# .gemini/.env\nCODE_ASSIST_ENDPOINT=http://127.0.0.1:4000\n```\n\nOr: `CODE_ASSIST_ENDPOINT=http://127.0.0.1:4000 gemini`\n\n### Verify it works\n\nWhen your AI tool sends a request containing PII, the hush terminal shows:\n\n```\nINFO: Redacted sensitive data from request  path=\"/v1/messages\"  tokenCount=2  duration=1\n```\n\nYour tool still sees the real data (rehydrated locally). The LLM provider only ever sees tokens like `[USER_EMAIL_f22c5a]`.\n\n## Enforce for Your Team\n\nCommit config files to your repo so every developer automatically routes through hush — no manual setup per person.\n\nCopy the files from [`examples/team-config/`](examples/team-config/) into your project root:\n\n```\nyour-project/\n├── .claude/settings.json     # Claude Code → hush\n├── .codex/config.toml        # Codex → hush\n├── .gemini/.env              # Gemini CLI → hush\n└── opencode.json             # OpenCode → hush\n```\n\n**Claude Code** — `.claude/settings.json`:\n```json\n{\n  \"env\": {\n    \"ANTHROPIC_BASE_URL\": \"http://127.0.0.1:4000\"\n  }\n}\n```\n\n**Codex** — `.codex/config.toml`:\n```toml\nmodel_provider = \"hush\"\n\n[model_providers.hush]\nbase_url = \"http://127.0.0.1:4000/v1\"\n```\n\n**OpenCode** — `opencode.json`:\n```json\n{\n  \"provider\": {\n    \"zai-coding-plan\": {\n      \"options\": {\n        \"baseURL\": \"http://127.0.0.1:4000/api/coding/paas/v4\"\n      }\n    }\n  }\n}\n```\n\n**Gemini CLI** — `.gemini/.env`:\n```\nCODE_ASSIST_ENDPOINT=http://127.0.0.1:4000\n```\n\nEach developer just needs `hush` running locally. All AI tools in the project will route through it automatically.\n\n## Hooks Mode (Claude Code)\n\nHush can also run as a **Claude Code hook** — redacting PII from tool outputs *before Claude ever sees them*. No proxy required.\n\n### Setup\n\n```bash\nhush init --hooks\n```\n\nThis adds a `PostToolUse` hook to `.claude/settings.json` that runs `hush redact-hook` after every `Bash`, `Read`, `Grep`, and `WebFetch` tool call.\n\nUse `--local` to write to `settings.local.json` instead (for personal overrides not committed to the repo).\n\n### How it works\n\n```\nLocal files/commands → [Hook: redact before Claude sees] → Claude's context\n                                                               ↓\n                                                          API request\n                                                               ↓\n                                                    [Proxy: redact before cloud]\n                                                               ↓\n                                                          LLM Provider\n```\n\nWhen a tool runs (e.g., `cat .env`), the hook inspects the response for PII. If PII is found, the hook **blocks** the raw output and provides Claude with the redacted version instead. Claude only ever sees `[USER_EMAIL_f22c5a]`, not `alice@company.com`.\n\n### Hooks vs Proxy\n\n| | Hooks Mode | Proxy Mode |\n|---|---|---|\n| **What's protected** | Tool outputs (before Claude sees them) | API requests (before they leave your machine) |\n| **Setup** | `hush init --hooks` | `hush` + point `ANTHROPIC_BASE_URL` |\n| **Works with** | Claude Code only | Any AI tool |\n| **Defense-in-depth** | Use both for maximum coverage | Use both for maximum coverage |\n\n### Defense-in-depth\n\nFor maximum protection, use both modes together. The team config example in [`examples/team-config/`](examples/team-config/) shows this setup — hooks redact tool outputs and the proxy redacts API requests.\n\n## OpenCode Plugin\n\nHush provides an **OpenCode plugin** that blocks reads of sensitive files (`.env`, `*.pem`, `credentials.*`, `id_rsa`, etc.) before the tool executes — the AI model never sees the contents.\n\n### Drop-in setup\n\nCopy the plugin file and update your `opencode.json`:\n\n```\nyour-project/\n├── .opencode/plugins/hush.ts    # plugin file\n└── opencode.json                # add \"plugin\" array\n```\n\n```json\n{\n  \"provider\": {\n    \"zai-coding-plan\": {\n      \"options\": {\n        \"baseURL\": \"http://127.0.0.1:4000/api/coding/paas/v4\"\n      }\n    }\n  },\n  \"plugin\": [\".opencode/plugins/hush.ts\"]\n}\n```\n\nFind the drop-in plugin at [`examples/team-config/.opencode/plugins/hush.ts`](examples/team-config/.opencode/plugins/hush.ts).\n\n### npm import\n\n```typescript\nimport { HushPlugin } from '@aictrl/hush/opencode-plugin'\n```\n\n### What it blocks\n\n| Tool | Blocked when |\n|------|-------------|\n| `read` | File path matches `.env*`, `*credentials*`, `*secret*`, `*.pem`, `*.key`, `*.p12`, `*.pfx`, `*.jks`, `*.keystore`, `*.asc`, `id_rsa*`, `.netrc`, `.pgpass` |\n| `bash` | Commands like `cat`, `head`, `tail`, `less`, `more`, `bat` target a sensitive file |\n\n### Plugin + Proxy = Defense-in-depth\n\nThe plugin blocks reads of known-sensitive filenames. The proxy catches PII in files with normal names (e.g., `config.txt` containing an email). Together they provide two layers of protection:\n\n```\nTool reads .env       → [Plugin: BLOCKED]           → model never sees it\nTool reads config.txt → [Plugin: allowed]            → proxy redacts PII → model sees tokens\n                         (not a sensitive filename)\n```\n\n## How it Works\n\n1. **Intercept** — Hush sits on your machine between your AI tool and the LLM provider.\n2. **Redact** — Before forwarding, it scans for PII and swaps it for deterministic tokens (`bulat@aictrl.dev` → `[USER_EMAIL_f22c5a]`).\n3. **Vault** — Original values are saved in a local, in-memory TokenVault (auto-expires after 1 hour).\n4. **Forward** — The redacted request goes to the provider. They never see your real data.\n5. **Rehydrate** — Responses come back with tokens replaced by originals before reaching your tool.\n\n## Supported Tools\n\n| Tool | Config | Route |\n|------|--------|-------|\n| Claude Code | `~/.claude/settings.json` | `/v1/messages` → Anthropic |\n| Codex | `~/.codex/config.toml` | `/v1/chat/completions` → OpenAI |\n| OpenCode | `opencode.json` | `/api/paas/v4/**` → ZhipuAI |\n| Gemini CLI | `.gemini/.env` | `/v1beta/models/**` → Google |\n| Any tool | Point base URL at hush | `/*` catch-all with auto-detect |\n\nHush forwards your existing auth headers transparently — no API keys need to be reconfigured.\n\n## Features\n\n- **Semantic Redaction** — Identifies emails, IPs, secrets, credit cards, phone numbers. Deterministic hash-based tokens (same input → same token).\n- **Local Rehydration** — Restores original values in responses locally. You see real data; the provider sees tokens.\n- **Streaming Support** — SSE-aware rehydration handles tokens split across network chunks.\n- **Live Dashboard** — `hush --dashboard` for a real-time TUI showing PII being blocked.\n- **Zero-Trust** — PII never leaves your machine. Binds to `127.0.0.1` by default.\n- **Universal Proxy** — One instance handles all providers simultaneously. Auto-detects from request path.\n\n## Configuration\n\n| Variable | Description | Default |\n|----------|-------------|---------|\n| `PORT` | Gateway listen port | `4000` |\n| `HUSH_HOST` | Bind address | `127.0.0.1` |\n| `HUSH_AUTH_TOKEN` | Require auth on all requests to the gateway itself | — |\n| `HUSH_DASHBOARD` | Enable TUI dashboard | `false` |\n| `DEBUG` | Show vault size in `/health` | `false` |\n\n## Development\n\n```bash\ngit clone https://github.com/aictrl-dev/hush.git\ncd hush && npm install\nnpm run dev        # dev mode with tsx\nnpm test           # run tests\nnpm run build      # production build\n```\n\n## License\n\nApache License 2.0 — see [LICENSE](LICENSE).\n","readmeFilename":"README.md"}