Hush MCP Server
a secret store for AI agents, the one with no get . get a secret once into the OS keychain, then inject it into commands forever, the value never hits stdout, the transcript, or the cloud. It is available as a remote MCP endpoint.
Teams that work with agent skills, credentials and developer tools and want a hosted endpoint instead of running a local process. The project is written in JavaScript.
VERIFIED ACTIVE
LAST COMMIT 2026-09-14 · ★ 20 · #130 OF 204 MAINTAINED SECURITY · VERIFIED 2026-09-18
MIT · JavaScript servers · how we verify → /methodology
01 · Install Hush
before you install - you'll need
The README does not document required environment variables for a basic install.
Claude Code
claude mcp add royashbrook-hush --transport http https://royashbrook.com/hush Claude Desktop / Cursor / VS Code - add to config
{
"mcpServers": {
"royashbrook-hush": {
"url": "https://royashbrook.com/hush"
}
}
} Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.
Using another client? Same JSON, different key
Claude Desktop · mcpServers
Cursor · mcpServers
VS Code · servers
Windsurf · mcpServers
Zed · context_servers
Cline · mcpServers
Roo Code · mcpServers
Continue · mcpServers
LibreChat · mcpServers
Gemini CLI · mcpServers
Codex CLI · mcp_servers
Full setup guides: every client.
02 · Evidence
https://royashbrook.com/hush
transport: streamable-http
endpoint alive - responded to MCP initialize · probed 2026-09-17
Security posture
What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.
runs as remote - your agent's requests go to royashbrook.com
endpoint auth accepted our unauthenticated MCP initialize - no credentials needed to connect
license MIT - declared in the repository
registry vendor namespace com.royashbrook - domain-verified with the official MCP registry
03 · Who maintains Hush
hush is maintained by royashbrook. We track 2 MCP servers from royashbrook - 2 actively maintained, 21 combined GitHub stars, oldest repo from Jun 2026.
04 · Facts
- repository
- github.com/royashbrook/hush
- category
- security - ranked #130 of 204 actively-maintained security servers as of 2026-09-18.
- registry
- com.royashbrook/hush (active, first published 2026-06-29)
05 · Hush FAQ
What is Hush?
a secret store for AI agents, the one with no get . get a secret once into the OS keychain, then inject it into commands forever, the value never hits stdout, the transcript, or the cloud. It is available as a remote MCP endpoint.
Is Hush still maintained?
Yes - as of 2026-09-18, its last commit was 2026-09-14. We re-verify nightly.
How do I install Hush?
Run `claude mcp add royashbrook-hush --transport http https://royashbrook.com/hush`. The README does not document required environment variables for a basic install. You can also paste the ready-made client config above.
Does Hush require authentication?
No - the endpoint accepted our unauthenticated MCP initialize when probed on 2026-09-17; you can connect without credentials.
06 · Alternatives to Hush
Alternatives to Hush
Maintained security servers if Hush isn't the fit.
- Treg To OpenRouter for tools and data. Compare catalog providers and call them from one hosted MCP endpoint. ★ 1,627 · 2026-09-18
- SafeDep Vet MCP Protect your AI agents and IDEs from malicious open-source packages. ★ 1,105 · 2026-09-16
- SonarQube MCP Server Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants. ★ 652 · 2026-09-17
- HOL Guard Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server. ★ 625 · 2026-09-18
- Decionis CommerceGate MCP Commerce preflights, D365 authorization, signed evidence, and reports; no marketplace or ERP writes. ★ 533 · 2026-09-18
- Emisar Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step. ★ 353 · 2026-09-15
Pairs well with
Servers that cover what Hush doesn't - only shown when the pairing reason fits the companion.
More security MCP servers · Janee · Agent Wormhole · Audit · Code Sentinel
More JavaScript MCP servers · Figbridge · Dev Globe · Norn · Muapi · Sanity · see all