mashabek/claude-mods/tree/main/plugins/secret-mask
secret-mask
Claudeが読む前に、ツール出力とプロンプトに含まれる秘密情報(APIキー、トークン、パスワード、.envの値)をマスクします。
この mod について
secret-mask
Claudeが読む前に、ツール出力、ファイル読み取り、プロンプトに含まれる秘密情報をマスクします。Claudeには‹secret:1›が見え、画面には実際の値が表示されます。
PreToolUseフックならコマンドをブロックするだけですが、これはコマンドを実行させたまま出力をマスクします。
Claude Code 2.1.288でテスト済みです。Function hookは早期アクセスのため、後のリリースで壊れる可能性があります。
Install
claude plugin marketplace add mashabek/claude-mods
claude plugin install secret-mask@claude-mods
Commands
| | |
|---|---|
| /secret-mask | 状態、読み取ったファイル、マスクした内容を表示します。値は決して表示しません。 |
| /secret-mask on, off | マスクをオンまたはオフにします。セッションをまたいで記憶されます。 |
| /secret-mask rescan | .envを編集した後に秘密ファイルを再読み込みします。 |
何かをマスクすると、ステータスラインに🔒 3 maskedが表示されます。
What it masks
- プロジェクトの
.envファイル、~/.aws/credentials、~/.npmrc、~/.netrc、~/.pgpass、および*_TOKEN、*_SECRET、*_PASSWORDのような名前の環境変数の値。URLエンコードやbase64のコピーを含め、現れる場所でマスクします。 - GitHub、GitLab、AWS、Anthropic、OpenAI、Stripe、Slack、Google、npm、SendGridのトークン、JWT、秘密鍵、
Authorizationヘッダー、user:pass@hostURLのパスワード。 apiKey = "..."やSESSION_SECRET=...のように秘密らしい名前に割り当てられたトークン形式の値。
コミットハッシュ、UUID、パス、process.env.X、${DB_PASS}のようなプレースホルダーはそのままです。ネットワーク通信やモデル呼び出しは行わず、依存関係もありません。値はメモリ内だけに保持されます。全体はhooks/内の約320行で、23個のテストがあります。
Limits
- 既知の形式でなく、秘密らしい名前もなく、ローカルファイルにもコピーがない秘密情報は通過します。
- Claude Codeがリクエストごとに作成する一部の添付ファイルは、プラグインで書き換えられません。
- プラグイン読み込み前にClaudeが見た秘密情報はコンテキストに残ります。
インストール
まず作者の README で marketplace とプラグイン名を確認してください。コマンドはリポジトリの構成によって変わる場合があります。
claude plugin marketplace add mashabek/claude-mods claude plugin install secret-mask
原文 / README
secret-mask
Masks secrets in tool output, file reads and prompts before Claude reads them. Claude sees
‹secret:1›, and your screen still shows the real value.
A PreToolUse hook could only block that command. This lets it run and masks the output.
Tested with Claude Code 2.1.288. Function hooks are early access, so a later release may break it.
Install
claude plugin marketplace add mashabek/claude-mods
claude plugin install secret-mask@claude-mods
Commands
| | |
|---|---|
| /secret-mask | Status, which files were read, and what was masked. Never prints a value. |
| /secret-mask on, off | Turns masking on or off. Remembered across sessions. |
| /secret-mask rescan | Rereads secret files after you edit a .env. |
The status line shows 🔒 3 masked once something has been masked.
What it masks
- Values from the project's
.envfiles,~/.aws/credentials,~/.npmrc,~/.netrc,~/.pgpass, and environment variables named like*_TOKEN,*_SECRETor*_PASSWORD, wherever they show up, including URL-encoded and base64 copies. - GitHub, GitLab, AWS, Anthropic, OpenAI, Stripe, Slack, Google, npm and SendGrid tokens, JWTs,
private keys,
Authorizationheaders, and passwords inuser:pass@hostURLs. - Token-like values assigned to secret names, like
apiKey = "..."orSESSION_SECRET=....
Commit hashes, UUIDs, paths, process.env.X and placeholders like ${DB_PASS} are left alone.
It makes no network or model calls and has no dependencies. Values are only held in memory.
The whole thing is about 320 lines in hooks/, with 23 tests.
Limits
- A secret with no known format, no secret-looking name and no copy in a local file gets through.
- Some attachments Claude Code builds per request can't be rewritten by plugins.
- Secrets Claude saw before the plugin loaded stay in its context.
同名の他の作品
- secret-maskFazzani · ★ 1
