ShriD5/claude-mods/tree/main/secret-guard
secret-guard
tool.call フックで認証情報らしい文字列をファイルへ書く操作を止め、プレースホルダーや開発用既定値、.env は許可する Claude Code プラグインです。
この mod について
secret-guard は tool.call フックで、ファイルツールが書き込む文字列と Bash のリダイレクト内容を検査し、本物らしい認証情報があれば呼び出しを拒否します。AWS、Anthropic/OpenAI、GitHub、Slack、Stripe、Google のキー、秘密鍵ブロック、パスワードを含む DB URL を検出します。xxxx、process.env.X、EXAMPLE キー、localhost、example.com、postgres:postgres、既存の秘密、.env 系ファイルは通しますが、.env.example/.sample/.template は保護します。CLAUDE.md と AGENTS.md はより厳しく検査します。ブロック時は種類と行を Claude に伝え、秘密を出力せず環境変数を使うよう促します。claude --plugin-dir ./secret-guard またはマーケットプレイスで導入し、/secret-guard で種類別の結果を確認します。
インストール
まず作者の README で marketplace とプラグイン名を確認してください。コマンドはリポジトリの構成によって変わる場合があります。
claude plugin marketplace add ShriD5/claude-mods claude plugin install secret-guard
原文 / README
secret-guard
Stops Claude from writing secrets into files. When a Write, Edit, MultiEdit or NotebookEdit would put a real-looking credential into a file, or a Bash command would echo, printf, tee or heredoc one into a file, the call is refused. Claude is told what it found and on which line, and to read the value from an environment variable instead, with the value kept in a gitignored .env. The secret itself is never repeated back.
🔒 secret-guard blocked a GitHub token in config.ts
It catches:
- AWS access keys (
AKIA…,ASIA…) - Anthropic keys (
sk-ant-…), OpenAI keys (sk-proj-…, legacysk-…), and other longsk-…keys - GitHub tokens (
ghp_,gho_,ghu_,ghs_,ghr_,github_pat_) - Slack tokens (
xoxb-,xoxp-, …) and Slack webhook URLs - Stripe live keys (
sk_live_,rk_live_) - Google API keys (
AIza…) - private key blocks (
-----BEGIN … PRIVATE KEY-----with a key body) - database URLs with an inline password (
postgres://,mysql://,mongodb+srv://,redis://,amqp://)
It lets these through:
- Placeholders:
xxxx,your-key-here,<api-key>,${VAR},process.env.X,AKIA…EXAMPLE, low-variety strings. - Dev defaults: database URLs to
localhostor a docker service name, documentation hosts likeexample.com, and default passwords likepostgres:postgres. - Secrets the file already holds: editing next to an existing key isn't blocked.
- Env files:
.env,.env.local,.env.productionand.dev.vars, which is where the deny message tells Claude to put secrets..env.example,.env.sampleand.env.templateare still guarded, because those get committed.
CLAUDE.md and AGENTS.md get extra-strict checks. In those files any credential-named assignment with a random-looking value (api_key: "q8Zr…") is blocked too. The deny reason also tells Claude why: these files are often committed and public, and in a public sample of 25,784 CLAUDE.md files, 275 contained real-looking secrets.
Run /secret-guard to see how many secrets it has blocked so far, broken down by type.
Install
claude --plugin-dir ./secret-guard
or add this repo as a marketplace and install it with /plugin.
Options
None. The rules live in hooks/detect.ts. Each one is a regex for a format a real service issues, followed by placeholder checks.
How it works
A tool.call hook reads the text a file tool is about to write, or the files a Bash command redirects into, and runs the detector on it. If anything new turns up, it answers { deny } so the tool never runs. The running count is kept in $.store.
同名の他の作品
- secret-guarddavidho27941 · ★ 0
- secret-guard0xGondarxyz · ★ 0
