ClaudeMods
☰
EN
● 0 online · Views 0 times
SponsorsSubmit a project
GitHub repositories · by Fazzani

secret-mask

Masks secrets (API keys, tokens, passwords, private keys) in the Claude Code transcript; hover a masked value to reveal it.

Fazzani@Fazzani

Fazzani/claude-mods/tree/main/plugins/secret-mask

Translated

About this mod

Masks secrets in the Claude Code transcript. Hover a masked value with the mouse to reveal it.

● Your key is sk-a•••••••• ← hover → sk-ant-api03-AbCd…

What is detected: private key blocks, Anthropic / OpenAI / GitHub / GitLab / Slack / Google / Stripe / npm tokens, AWS access keys and secret keys, JWTs, Azure AccountKey= / SharedAccessKey= / sig=, passwords in URLs (postgres://user:pass@host), Bearer tokens, and generic assignments (password=…, api_key: …, client_secret=…). References and placeholders (${TOKEN}, <key>, process.env.X, xxxx) are left alone. Rules live in hooks/patterns.ts.

Where masked: assistant replies and prompts (masked with hover reveal), bash output and text results (masked, first 12 lines; ctrl+o shows the rest), tool call arguments / structured results / messages from other agents (masked, no reveal). Masking only changes what the screen shows; the model and transcript file still see the real values. Hover needs a surface that reports the pointer: the desktop app or the terminal's fullscreen layout.

Installation

Check the author's README for the marketplace and plugin name first. Commands may change as the repository evolves.

claude plugin marketplace add Fazzani/claude-mods
claude plugin install secret-mask
Original text / README

secret-mask

Masks secrets in the Claude Code transcript. Hover a masked value with the mouse to reveal it.

● Your key is sk-a••••••••      ← hover → sk-ant-api03-AbCd…

What is detected

Private key blocks, Anthropic / OpenAI / GitHub / GitLab / Slack / Google / Stripe / npm tokens, AWS access keys and secret keys, JWTs, Azure AccountKey= / SharedAccessKey= / sig=, passwords in URLs (postgres://user:pass@host), Bearer tokens, and generic assignments (password=…, api_key: …, client_secret=…). References and placeholders (${TOKEN}, <key>, process.env.X, xxxx) are left alone. The rules live in hooks/patterns.ts.

Where

| Row | Behaviour | | --- | --- | | Assistant replies, your prompts | Masked, with hover reveal (a reply that contains a secret is drawn as plain text, not markdown) | | Bash output and other text results | Masked, with hover reveal (first 12 lines; ctrl+o shows the rest) | | Tool call arguments, structured results, messages from other agents | Masked, no reveal |

Masking only changes what the screen shows. The model and the transcript file still see the real values.

Hover needs a surface that reports the pointer: the desktop app, or the terminal's fullscreen layout.

Other works with the same name

Similar projects