(pronounced "ree-doh")
Keep sensitive files out of coding sandboxes without changing your workflow.
rido moves files outside your repository and leaves symlinks behind. Your local environment keeps
working normally, but isolated agents that cannot access the private store simply see missing files.
Telling an agent "don't read secrets" is not a security boundary.
Configuration files, prompt rules, and allow-lists are only suggestions. A compromised dependency, a prompt injection, or a curious agent can still access anything available in its filesystem.
Before rido
repo/
├── .env
├── config/
│ └── credentials.json
└── src/
After rido
repo/
├── .env -> ~/.rido/store/01J8XQ4M7K/.env
├── config/
│ └── credentials.json -> ~/.rido/store/01J8XQ52PB/credentials.json
└── src/
~/.rido/store/
├── 01J8XQ4M7K/
│ ├── .env
│ └── meta.json
└── 01J8XQ52PB/
├── credentials.json
└── meta.json
One directory per entry, named with a ULID. meta.json records where the file came from.
This is what your agent sees inside an isolated sandbox:
.env -> ENOENT
This is what you see on your local machine:
.env -> real file
Linux and macOS. Windows is not supported: creating symlinks there needs elevated privileges.
go install github.com/marftn/rido@latestrido add .env config/credentials.jsonrido add secrets/The tree moves into one entry, unchanged, and the directory itself becomes the symlink:
repo/
└── secrets -> ~/.rido/store/01J8XQA1/secrets
~/.rido/store/01J8XQA1/
├── meta.json
└── secrets/
├── db.json
└── prod/
└── api.key
Subdirectories do not get entries of their own. Because the whole path is hidden, files created
inside secrets/ later are covered too, with no re-add.
Add the files individually when you only want some of them hidden, or when a build script needs to write into that directory:
rido add secrets/db.json secrets/prod/api.keyrido refuses to add a file that git already tracks, and offers to add it to .gitignore if it is
untracked.
Sometimes your agent will overwrite some symlinks because it needs valid files to execute your code. Simply restore them afterward.
rido restore .env # one file
rido restore --all # everything under the current directoryIf a real file sits where the symlink should be, rido asks before deleting it.
rido listID STATUS ADDED ORIGIN
01J8XQ4M7K linked 2026-08-07 /home/you/code/myrepo/.env
01J8XQ6F3D MISSING 2026-08-07 /home/you/code/myrepo/.env.staging
Puts the file back in the repository and drops the store entry.
rido revert .envNote this is the opposite of git restore / git revert: here restore recreates the symlink,
revert hands the file back.
Optional. ~/.config/rido/config.json, or $XDG_CONFIG_HOME/rido/config.json.
{ "storeRoot": "/media/luks/rido-store" }Defaults to ~/.rido/store.
rido protects against processes running in restricted environments that cannot access the private
store.
It does not protect against:
- a process that already has access to your home directory
- malware running as your user
- someone with filesystem access to the private store
The store needs to be owned and trusted. A meta.json file records where a payload belongs, so
anyone able to write into the store decides where the next restore puts a file. Keep it 0700,
and on your own volume.
This project is licensed under the MIT License. See the LICENSE.md file for details.