0xGondarxyz/claude-code-mods/tree/main/secret-guard
이 mod 소개
secret-guard는 Claude가 읽기 전에 모든 도구 결과의 API key, token, password를 마스킹하고, 비밀이나 home 경로를 공개 repository에 노출할 수 있는 git push를 차단합니다. 접두사가 있는 token(Anthropic, OpenAI, GitHub, AWS, Google, Slack, Stripe, GitLab, npm, Telegram, JWT 등), PEM 개인 키 블록, Bearer token, URL 비밀번호와 비밀처럼 보이는 할당을 감지하고 각각 종류와 마지막 4개 문자를 표시하는 표식으로 바꿉니다. 쓰기 보호는 표식이 포함된 Write/Edit/MultiEdit/NotebookEdit 및 Bash 명령을 거부합니다. push 검사는 repository와 remote를 확인하고 gh에 공개 범위를 묻고, push하지 않은 commit의 추가 줄을 스캔합니다(명령이 add나 commit도 수행하면 작업 트리 diff와 추적되지 않은 파일도 스캔). 비밀이나 절대 home 경로를 찾으면 최대 10개의 file:line 결과와 함께 push를 거부합니다. /plugin marketplace add 0xGondarxyz/claude-code-mods 및 /plugin install secret-guard@claude-code-mods로 설치하거나 --plugin-dir로 실행하세요. MIT 라이선스이며 mod에는 샌드박스가 없습니다.
설치
먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.
claude plugin marketplace add 0xGondarxyz/claude-code-mods claude plugin install secret-guard
원문 / README
secret-guard
A Claude Code mod that keeps secrets out of the conversation and out of public repos.
- It masks API keys, tokens and passwords in every tool result before Claude reads them.
- It blocks a
git pushthat would leak a secret or a home path to a public repo.
Install
/plugin marketplace add 0xGondarxyz/claude-code-mods
/plugin install secret-guard@claude-code-mods
Or try it without installing:
git clone https://github.com/0xGondarxyz/claude-code-mods
claude --plugin-dir claude-code-mods/secret-guard
Mods are not sandboxed. They run with the same access as Claude Code. Read the source before you install any mod, including this one.
Masking
Every tool result is checked before it is stored: built-in tools, MCP tools, the main thread and subagents. Each secret becomes a marker. The rest of the text is kept byte for byte.
ANTHROPIC_API_KEY=[masked anthropic_key ...a1b2]
The marker shows the kind and the last 4 characters.
What it finds:
- Prefixed tokens: Anthropic, OpenAI, GitHub (
ghp_,gho_,ghu_,ghs_,ghr_,github_pat_), AWSAKIA, GoogleAIza, Slack, Stripe, GitLab, Apify, Notion, Hugging Face, Replicate, npm, Telegram bot tokens, JWTs. - PEM private key blocks (the whole block).
- Bearer tokens (
Bearerfollowed by 20 or more token characters). - The password in a URL such as
postgres://user:PASSWORD@host. - Assignments: a name that contains
api_key,secret,token,password,credential,private_key,access_keyorauth, then=or:, then a value of 16 or more characters with a letter and a digit. Only the value is masked.
What it leaves alone: placeholders (your_..., xxx..., <...>, ${...}, process.env..., os.environ..., changeme, example), git SHAs, UUIDs, numbers, file paths, npm sha512- integrity hashes.
Claude now sees markers, so it could write one back over the real secret. The write guard stops that. Write, Edit, MultiEdit and NotebookEdit are denied when the new text holds a marker, and so is a Bash command that holds one. Claude is told to edit around the line or ask you to change that value.
Push check
When a Bash command runs git push, secret-guard checks before it runs:
- It finds the repo (
git -C <dir>, a leadingcd <dir> &&, or the session folder) and the remote (defaultorigin). - It asks
gh repo viewfor the visibility.PRIVATEorINTERNAL: the push goes through, no scan.PUBLICor unknown (nogh, not GitHub, an error): it scans. - It scans the added lines of every local commit the remote does not have. If the same command also runs
git addorgit commit, it scans the working tree diff and the untracked files too (not ignored, under 1 MB, not binary). - It looks for the same secrets as masking, plus absolute home paths: your real home folder and any
/home/<name>/or/Users/<name>/path, and Windows paths (C:\Users\<name>\, the forward-slash form and the JSON-escaped form, any drive letter).HOMEand, when set,USERPROFILEcount as your home folder./home/user/,/home/runner/and the Windows namesPublic,Default,Default UserandAll Usersare ignored.
With findings, the push is denied. The text lists up to 10 as file:line kind. It never prints the secret. A toast says secret-guard: push blocked, N findings. When the visibility was unknown, the text says so.
If the scan itself fails (git error, timeout of about 5 seconds), the push is allowed and a toast says secret-guard: scan failed, push allowed.
Commands
| Command | What it does |
| --- | --- |
| /secret-guard | Shows how many values were masked this session and whether a pass is active. |
| /secret-guard allow | Lets the next push skip the scan. The pass lasts 10 minutes and works once. |
For a false positive: run /secret-guard allow, then push again.
Limits
- Detection is by pattern. A secret with no known prefix and no telling name (for example a bare random string) is not masked.
- What the model reads is masked. The engine stores a tool result's structured record (what the screen draws) as made, so the transcript file on disk can still hold the raw output.
- Rows that are not tool results (your prompts, attachments) are not masked.
git logoutput is cut at 4 MB. A very large unpushed history is only scanned in part.- Pushes started outside Claude Code's Bash tool (hooks, scripts it launches) are not seen.
- A file that must contain the literal marker text cannot be written by Claude. Ask Claude to leave it to you.
No options.
License
MIT
동명의 다른 작품
- secret-guarddavidho27941 · ★ 0
- secret-guardShriD5 · ★ 0
