mashabek/claude-mods/tree/main/plugins/secret-mask
이 mod 소개
secret-mask
Claude가 읽기 전에 도구 출력, 파일 읽기 및 프롬프트의 비밀을 마스킹합니다. Claude에는 ‹secret:1›이 보이고 화면에는 실제 값이 계속 표시됩니다.
PreToolUse 훅은 해당 명령을 차단할 수만 있지만, 이 플러그인은 명령을 실행하고 출력을 마스킹합니다.
Claude Code 2.1.288에서 테스트되었습니다. Function hook은 얼리 액세스이므로 이후 릴리스에서 깨질 수 있습니다.
Install
claude plugin marketplace add mashabek/claude-mods
claude plugin install secret-mask@claude-mods
Commands
| | |
|---|---|
| /secret-mask | 상태, 읽은 파일 및 마스킹된 항목을 표시합니다. 값은 절대 출력하지 않습니다. |
| /secret-mask on, off | 마스킹을 켜거나 끕니다. 세션 간에 기억됩니다. |
| /secret-mask rescan | .env를 편집한 뒤 비밀 파일을 다시 읽습니다. |
무언가가 마스킹되면 상태 줄에 🔒 3 masked가 표시됩니다.
What it masks
- 프로젝트의
.env파일,~/.aws/credentials,~/.npmrc,~/.netrc,~/.pgpass와*_TOKEN,*_SECRET,*_PASSWORD같은 이름의 환경 변수 값. URL 인코딩 및 base64 복사본을 포함해 값이 나타나는 곳을 모두 처리합니다. - GitHub, GitLab, AWS, Anthropic, OpenAI, Stripe, Slack, Google, npm 및 SendGrid 토큰, JWT, 개인 키,
Authorization헤더,user:pass@hostURL의 비밀번호. apiKey = "..."또는SESSION_SECRET=...처럼 비밀 이름에 할당된 토큰 형태의 값.
커밋 해시, UUID, 경로, process.env.X 및 ${DB_PASS} 같은 플레이스홀더는 그대로 둡니다. 네트워크나 모델 호출을 하지 않으며 의존성도 없습니다. 값은 메모리에만 보관됩니다. 전체 코드는 hooks/에 약 320줄이며 테스트는 23개입니다.
Limits
- 알려진 형식이 아니고 비밀처럼 보이는 이름도 없으며 로컬 파일에 복사본도 없는 비밀은 통과합니다.
- Claude Code가 요청마다 만드는 일부 첨부 파일은 플러그인이 다시 쓸 수 없습니다.
- 플러그인이 로드되기 전에 Claude가 본 비밀은 컨텍스트에 남습니다.
설치
먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.
claude plugin marketplace add mashabek/claude-mods claude plugin install secret-mask
원문 / README
secret-mask
Masks secrets in tool output, file reads and prompts before Claude reads them. Claude sees
‹secret:1›, and your screen still shows the real value.
A PreToolUse hook could only block that command. This lets it run and masks the output.
Tested with Claude Code 2.1.288. Function hooks are early access, so a later release may break it.
Install
claude plugin marketplace add mashabek/claude-mods
claude plugin install secret-mask@claude-mods
Commands
| | |
|---|---|
| /secret-mask | Status, which files were read, and what was masked. Never prints a value. |
| /secret-mask on, off | Turns masking on or off. Remembered across sessions. |
| /secret-mask rescan | Rereads secret files after you edit a .env. |
The status line shows 🔒 3 masked once something has been masked.
What it masks
- Values from the project's
.envfiles,~/.aws/credentials,~/.npmrc,~/.netrc,~/.pgpass, and environment variables named like*_TOKEN,*_SECRETor*_PASSWORD, wherever they show up, including URL-encoded and base64 copies. - GitHub, GitLab, AWS, Anthropic, OpenAI, Stripe, Slack, Google, npm and SendGrid tokens, JWTs,
private keys,
Authorizationheaders, and passwords inuser:pass@hostURLs. - Token-like values assigned to secret names, like
apiKey = "..."orSESSION_SECRET=....
Commit hashes, UUIDs, paths, process.env.X and placeholders like ${DB_PASS} are left alone.
It makes no network or model calls and has no dependencies. Values are only held in memory.
The whole thing is about 320 lines in hooks/, with 23 tests.
Limits
- A secret with no known format, no secret-looking name and no copy in a local file gets through.
- Some attachments Claude Code builds per request can't be rewritten by plugins.
- Secrets Claude saw before the plugin loaded stay in its context.
동명의 다른 작품
- secret-maskFazzani · ★ 1
