<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Avazbek Olimov</title>
    <description>The latest articles on DEV Community by Avazbek Olimov (@avazbek22).</description>
    <link>https://dev.to/avazbek22</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4097680%2F2c0d38ee-d0d4-4e01-a92a-777d941f312e.jpg</url>
      <title>DEV Community: Avazbek Olimov</title>
      <link>https://dev.to/avazbek22</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/avazbek22"/>
    <language>en</language>
    <item>
      <title>I built DevProjex, an MCP server that hides your secrets from the AI — and you can't turn it off</title>
      <dc:creator>Avazbek Olimov</dc:creator>
      <pubDate>Wed, 02 Sep 2026 14:45:36 +0000</pubDate>
      <link>https://dev.to/avazbek22/i-made-devprojex-pack-your-codebase-for-ai-gui-tui-cli-and-mcp-server-in-one-app-3h60</link>
      <guid>https://dev.to/avazbek22/i-made-devprojex-pack-your-codebase-for-ai-gui-tui-cli-and-mcp-server-in-one-app-3h60</guid>
      <description>&lt;p&gt;An AI coding agent is great right up until it reads your &lt;code&gt;.env&lt;/code&gt; and helpfully quotes an API key back into a chat log you don't control.&lt;/p&gt;

&lt;p&gt;That thought bothered me enough that I built the masking into DevProjex at the deepest level I could. The built-in MCP server redacts detected secrets in every tool response, and there is no flag to turn it off. Not a config option, not an env var, nothing. A tool whose whole job is handing your code to an AI shouldn't be able to leak credentials, even if you ask it nicely.&lt;/p&gt;

&lt;p&gt;DevProjex is bigger than that one feature though — it's a local, read-only desktop app for Windows, Linux and macOS that turns any folder or Git repo into clean, token-efficient context. GUI, terminal TUI, CLI and the MCP server all share one engine. The security part is just the piece I'm most proud of, so I'm starting there.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;I built DevProjex, a desktop app that packs any folder or Git repo into one AI-ready document — with a visual file tree, live preview, token estimate, and secret masking before anything leaves your machine — plus a read-only MCP server for AI agents where masking is always on. Free, open source, runs locally on Windows/Linux/macOS.&lt;/p&gt;


&lt;div class="ltag-github-readme-tag"&gt;
  &lt;div class="readme-overview"&gt;
    &lt;h2&gt;
      &lt;img src="https://assets.dev.to/assets/github-logo-5a155e1f9a670af7944dd5e12375bc76ed542ea80224905ecaf878b9157cdefc.svg" alt="GitHub logo"&gt;
      &lt;a href="https://github.com/Avazbek22" rel="noopener noreferrer"&gt;
        Avazbek22
      &lt;/a&gt; / &lt;a href="https://github.com/Avazbek22/DevProjex" rel="noopener noreferrer"&gt;
        DevProjex
      &lt;/a&gt;
    &lt;/h2&gt;
    &lt;h3&gt;
      Build safe, token-efficient codebase context for LLMs, AI chats, and coding agents — local-first GUI, TUI, CLI, and a read-only MCP server with Smart Ignore, secret/PII redaction, Git scopes, and code compression.
    &lt;/h3&gt;
  &lt;/div&gt;
  &lt;div class="ltag-github-body"&gt;
    
&lt;div id="readme" class="md"&gt;&lt;div class="markdown-heading"&gt;
&lt;h1 class="heading-element"&gt;DevProjex 📁🌳&lt;/h1&gt;
&lt;/div&gt;
&lt;div class="markdown-heading"&gt;
&lt;h2 class="heading-element"&gt;🏆 Officially Selected by the Avalonia UI Team for the &lt;a href="https://avaloniaui.net/showcase" rel="nofollow noopener noreferrer"&gt;App Showcase&lt;/a&gt;
&lt;/h2&gt;
&lt;/div&gt;
&lt;p&gt;
  &lt;a href="https://github.com/Avazbek22/DevProjex/releases" rel="noopener noreferrer"&gt;&lt;img alt="Downloads" src="https://camo.githubusercontent.com/ba48980f0a4ef2fb5b35c92937eb3517115f22cb6035f0a8e3a80cffa7cc62e9/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f646f776e6c6f6164732f4176617a62656b32322f44657650726f6a65782f746f74616c"&gt;&lt;/a&gt;
  &lt;a href="https://github.com/Avazbek22/DevProjex/actions" rel="noopener noreferrer"&gt;&lt;img alt="Build" src="https://camo.githubusercontent.com/5329861160eed80a5551fb336ab93110f028430b14ddec19328404f420630cd3/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f616374696f6e732f776f726b666c6f772f7374617475732f4176617a62656b32322f44657650726f6a65782f646f746e65742e796d6c"&gt;&lt;/a&gt;
  &lt;a href="https://github.com/Avazbek22/DevProjex/LICENSE" rel="noopener noreferrer"&gt;&lt;img alt="License" src="https://camo.githubusercontent.com/35b94db23d3ed026343335f74d52ce31e74b77ad7dab4e4b89f49f2026e0937f/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6c6963656e73652d4170616368652d2d322e302d626c7565"&gt;&lt;/a&gt;
  &lt;a rel="noopener noreferrer nofollow" href="https://camo.githubusercontent.com/30f404a93aefdad0f058fbeab7b14075ea7fa9504ab35afef88063a97a328930/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f6c6173742d636f6d6d69742f4176617a62656b32322f44657650726f6a6578"&gt;&lt;img alt="Last commit" src="https://camo.githubusercontent.com/30f404a93aefdad0f058fbeab7b14075ea7fa9504ab35afef88063a97a328930/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f6c6173742d636f6d6d69742f4176617a62656b32322f44657650726f6a6578"&gt;&lt;/a&gt;
  &lt;a rel="noopener noreferrer nofollow" href="https://camo.githubusercontent.com/3b47a8d412962fe7d78bfc85abcb61d70f0292e0d6e8a6b8a8d55b8d59a699ef/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f706c6174666f726d2d57696e646f77732532302537432532304c696e75782532302537432532306d61634f532d677265656e"&gt;&lt;img alt="Platforms" src="https://camo.githubusercontent.com/3b47a8d412962fe7d78bfc85abcb61d70f0292e0d6e8a6b8a8d55b8d59a699ef/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f706c6174666f726d2d57696e646f77732532302537432532304c696e75782532302537432532306d61634f532d677265656e"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;
  &lt;strong&gt;Turn a real codebase into clean, AI-ready context — and see exactly what you're sending.&lt;/strong&gt;
&lt;/p&gt;

&lt;p&gt;DevProjex turns any folder or codebase into clean, ready-to-use context for AI chats, code reviews, and documentation. Use it as a &lt;strong&gt;GUI&lt;/strong&gt;, a &lt;strong&gt;TUI&lt;/strong&gt;, a &lt;strong&gt;CLI&lt;/strong&gt;, or an &lt;strong&gt;MCP server&lt;/strong&gt; for AI agents — whatever fits your workflow.&lt;/p&gt;

&lt;p&gt;Choose what you need in an interactive file tree, check the result in a live preview, then export it as &lt;strong&gt;ASCII, Markdown, JSON, or XML&lt;/strong&gt;. Need more than text? Export a real copy of your project — a clean &lt;strong&gt;folder or ZIP file&lt;/strong&gt; — with the same filters applied.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;🔒 &lt;strong&gt;Read-only and telemetry-free by design.&lt;/strong&gt; DevProjex does not upload your project contents or collect telemetry.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;div class="markdown-heading"&gt;
&lt;h2 class="heading-element"&gt;App Demo 🖼️&lt;/h2&gt;
&lt;/div&gt;

&lt;p&gt;&lt;a rel="noopener noreferrer" href="https://github.com/Avazbek22/DevProjex/Docs/Media/readme-demo/devprojex-demo-04-readme.gif"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fraw.githubusercontent.com%2FAvazbek22%2FDevProjex%2FHEAD%2FDocs%2FMedia%2Freadme-demo%2Fdevprojex-demo-04-readme.gif" alt="DevProjex desktop app demo" width="100%"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;div class="markdown-heading"&gt;
&lt;h2 class="heading-element"&gt;Download 🚀&lt;/h2&gt;

&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Download from Microsoft Store:&lt;/strong&gt;
👉 &lt;a href="https://apps.microsoft.com/detail/9ndq3nq5m354" rel="nofollow noopener noreferrer"&gt;DevProjex&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Latest GitHub release:&lt;/strong&gt;…&lt;/p&gt;&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class="gh-btn-container"&gt;&lt;a class="gh-btn" href="https://github.com/Avazbek22/DevProjex" rel="noopener noreferrer"&gt;View on GitHub&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;


&lt;h2&gt;
  
  
  The secrets part
&lt;/h2&gt;

&lt;p&gt;This is the part I care most about. One switch masks detected API keys, tokens, passwords and connection strings right in the output. The file stays in the pack, only the value gets masked, and every finding is marked in the preview — there are even little markers on the scrollbar so nothing hides below the fold. False positive? Override that one match, right there.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnm1v4dpjpe2b226h3qek.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnm1v4dpjpe2b226h3qek.png" alt="Secret masking markers in the preview" width="800" height="498"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In CI you can go further: the CLI has a findings check that fails the pipeline if secrets are detected, without ever printing the values.&lt;/p&gt;

&lt;h2&gt;
  
  
  Background
&lt;/h2&gt;

&lt;p&gt;Every time I wanted real help from an AI on my actual project, the ritual was the same. Open a file, copy, paste. Open another one, copy, paste. Write "here's some more context". Hit the token limit. Delete half. Realize the half I deleted was the part that mattered.&lt;/p&gt;

&lt;p&gt;And the whole time there's this low-level anxiety: did I just paste a connection string in there? A key from some config I forgot about?&lt;/p&gt;

&lt;p&gt;There are good CLI tools in this space already (Repomix, gitingest, code2prompt — they all do the pack-your-repo thing well). But I kept wanting to &lt;em&gt;see&lt;/em&gt; what I was about to send. Not a glob pattern in a terminal — an actual tree with checkboxes and a preview that updates while I click things. So I built one. It started years ago as a tiny tool that just showed a project tree so I could copy it into a chat. It, uh, grew.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fl8xezqwdgosqibqi4wso.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fl8xezqwdgosqibqi4wso.png" alt="DevProjex main window: file tree with checkboxes and live preview" width="800" height="497"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Features
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;File tree with checkboxes and a live preview — you see exactly what you're sending, before you send it&lt;/li&gt;
&lt;li&gt;Token estimate up front, plus metrics for files, lines and characters&lt;/li&gt;
&lt;li&gt;Smart Ignore: filters out dependencies, caches and build artifacts based on actual evidence, not folder names — a &lt;code&gt;build&lt;/code&gt; folder with real source in it doesnt silently disappear&lt;/li&gt;
&lt;li&gt;Git filtering beyond .gitignore: only tracked files, only staged files, current changes, or a diff between two refs&lt;/li&gt;
&lt;li&gt;Secret masking (Gitleaks-based rules) and optional private-data masking: emails, IPs, MACs, phone numbers, user paths&lt;/li&gt;
&lt;li&gt;Code compression: keeps declarations and signatures, empties method bodies — pure source shrinks about 3x&lt;/li&gt;
&lt;li&gt;Export as Markdown, ASCII, JSON or XML, or copy straight to the clipboard&lt;/li&gt;
&lt;li&gt;Same engine in four forms: GUI, terminal UI, CLI, and an MCP server&lt;/li&gt;
&lt;li&gt;Local, read-only, no telemetry, no account&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Token optimization
&lt;/h2&gt;

&lt;p&gt;Models have context windows, wallets have limits. Three things help:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Code compression, as above — great when the question is about architecture, not one specific function&lt;/li&gt;
&lt;li&gt;Comment and blank-line stripping, 20 syntax-aware language packs&lt;/li&gt;
&lt;li&gt;A token budget: set a maximum, and it packs the largest files that fit and reports what was included and what was skipped&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The diff scopes deserve a mention here too. Narrowing the pack to "what I'm working on right now" saves more tokens than any compression.&lt;/p&gt;

&lt;h2&gt;
  
  
  The terminal side
&lt;/h2&gt;

&lt;p&gt;The same workflow runs as a keyboard-first TUI (works over SSH), and as a CLI for scripts:&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;devprojex           # terminal workspace
devprojex help      # CLI reference
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Faeeqfrldk9yaaxhj1m1o.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Faeeqfrldk9yaaxhj1m1o.png" alt="Terminal workspace TUI" width="800" height="469"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  MCP server
&lt;/h2&gt;

&lt;p&gt;New in v5.1: a built-in read-only MCP server. For Claude Code it's one line:&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;claude mcp add devprojex -- devprojex mcp --root .
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;The agent gets read-only tools, sees only the folders you allowed, and can narrow the selection but never widen it. Secret masking in MCP mode is always on — there is no flag to turn it off, on purpose. I did not want "the agent decided to disable redaction" to be a sentence anyone ever says.&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;This started as a tool I built because I needed it, and it slowly turned into one binary with a GUI, a TUI, a CLI and an MCP server, in 20 languages, with 17,000+ automated tests (solo project — tests are how I sleep at night). Apache-2.0, on GitHub:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/Avazbek22/DevProjex" rel="noopener noreferrer"&gt;https://github.com/Avazbek22/DevProjex&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Honest question for the comments: what do you actually paste into AI chats — whole repo, or hand-picked files? And does the secrets thing worry you, or am I paranoid?&lt;/p&gt;

</description>
      <category>ai</category>
      <category>cli</category>
      <category>opensource</category>
      <category>tools</category>
    </item>
  </channel>
</rss>
