---
title: "trustless"
description: "Credential broker CLI for AI agents. Injects credentials into subprocess memory: agent never sees plaintext values."
canonical: https://agentpluginsdirectory.com/plugins/trustless
last-updated: 2026-09-28
---

# trustless
Credential broker CLI for AI agents. Injects credentials into subprocess memory: agent never sees plaintext values.
- Slug: trustless
- Publisher: ikkun1222
- Repository: https://github.com/ikkun1222/trustless
- Manifest: plugin.json
- Version: 0.1.0
- License: MIT
- Category (editorial): security
- Skills: 1 (trustless-usage)
- MCP servers: 0
- Stars: 4
- Repository created: 2026-07-28
- Repository last pushed: 2026-09-13
- Publisher type: User
- Listing: https://agentpluginsdirectory.com/plugins/trustless
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What trustless does, in the publisher's words

trustless is a credential broker CLI that decouples AI agents from the secrets they use. Instead of agents holding plaintext credentials in their context window (where prompt injection or leakage can expose them), trustless acts as an intermediary: agents reference credentials by name, and the broker resolves them at the transport or process layer, the agent never holds plaintext values.

The name reflects the architecture: you don't need to trust the agent with secrets because the agent structurally cannot access them.

Traditional AI agent setups give the agent direct access to credentials, either as environment variables, config files, or inline in prompts. This means a single prompt injection or overly-verbose debug output can leak secrets to an attacker or an untrusted third-party API.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/ikkun1222/trustless/HEAD/README.md

## Skills

- trustless-usage: Use trustless CLI for credential management. All credentials are stored in the pass password store (GPG-encrypted). The agent injects secrets into subprocess memory only, never sees plaintext values. Run commands with `trustless run -s <key>, <command>`. Register new credentials with `trustless…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
