Jamf-native control pack for secretless-ai. Keep plaintext secrets out of AI coding tools on managed Macs — no extra agent, no second console.

Deterministic posture for AI-exposed secrets

Antacid orchestrates secretless-ai on every managed Mac and surfaces results where Jamf admins already work. Values never leave the device.

  1. Ensure Secretless Install and pin secretless-ai via Jamf policy (Homebrew or npm).
  2. Check compliance Gate on verify, status, and complete scans — incomplete is never clean.
  3. Inventory names only Report secret names from MCP configs and scans into Extension Attributes.

One search for secrets exposed to AI tools

Smart Groups and Advanced Search show which Macs still have sensitive env names in AI surfaces — names and sources only, never credential values.

Antacid AI Secret Count   2
Antacid AI Secret Names   STRIPE_SECRET_KEY,GITHUB_PERSONAL_ACCESS_TOKEN
Antacid AI Secret Sources STRIPE_SECRET_KEY:mcp/cursor,GITHUB_PERSONAL_ACCESS_TOKEN:mcp/claude

Audit secrets on the API path

The Antacid Kong plugin logs secret key, semi-masked value, and user id for requests through Kong — without blocking traffic. Open the Admin UI at /antacid to review recent events.

Deploy through Jamf Pro only

Import scripts and Extension Attributes. Developers install nothing by hand.

  1. Sync Antacid to /Library/Application Support/antacid/ on target Macs.
  2. Paste the eight Extension Attribute scripts into Jamf Pro.
  3. Schedule install + inventory policies against your developer group.
  4. Open the Antacid AI Secrets Advanced Search — or export via API.