ClaudeMods
☰
KO
● 0 명 접속 중 · 조회 0 회
후원프로젝트 제출
GitHub 저장소 · 작성자 mashabek

secret-mask

Claude가 읽기 전에 도구 출력과 프롬프트의 비밀(API 키, 토큰, 비밀번호, .env 값)을 마스킹합니다.

mashabek@mashabek

mashabek/claude-mods/tree/main/plugins/secret-mask

원본 게시물 이미지1
번역 완료

이 mod 소개

secret-mask

Claude가 읽기 전에 도구 출력, 파일 읽기 및 프롬프트의 비밀을 마스킹합니다. Claude에는 ‹secret:1›이 보이고 화면에는 실제 값이 계속 표시됩니다.

터미널에는 비밀이 보이고 Claude는 ‹secret:1›을 읽습니다

PreToolUse 훅은 해당 명령을 차단할 수만 있지만, 이 플러그인은 명령을 실행하고 출력을 마스킹합니다.

Claude Code 2.1.288에서 테스트되었습니다. Function hook은 얼리 액세스이므로 이후 릴리스에서 깨질 수 있습니다.

Install

claude plugin marketplace add mashabek/claude-mods
claude plugin install secret-mask@claude-mods

Commands

| | | |---|---| | /secret-mask | 상태, 읽은 파일 및 마스킹된 항목을 표시합니다. 값은 절대 출력하지 않습니다. | | /secret-mask on, off | 마스킹을 켜거나 끕니다. 세션 간에 기억됩니다. | | /secret-mask rescan | .env를 편집한 뒤 비밀 파일을 다시 읽습니다. |

무언가가 마스킹되면 상태 줄에 🔒 3 masked가 표시됩니다.

What it masks

  • 프로젝트의 .env 파일, ~/.aws/credentials, ~/.npmrc, ~/.netrc, ~/.pgpass와 *_TOKEN, *_SECRET, *_PASSWORD 같은 이름의 환경 변수 값. URL 인코딩 및 base64 복사본을 포함해 값이 나타나는 곳을 모두 처리합니다.
  • GitHub, GitLab, AWS, Anthropic, OpenAI, Stripe, Slack, Google, npm 및 SendGrid 토큰, JWT, 개인 키, Authorization 헤더, user:pass@host URL의 비밀번호.
  • apiKey = "..." 또는 SESSION_SECRET=...처럼 비밀 이름에 할당된 토큰 형태의 값.

커밋 해시, UUID, 경로, process.env.X 및 ${DB_PASS} 같은 플레이스홀더는 그대로 둡니다. 네트워크나 모델 호출을 하지 않으며 의존성도 없습니다. 값은 메모리에만 보관됩니다. 전체 코드는 hooks/에 약 320줄이며 테스트는 23개입니다.

Limits

  • 알려진 형식이 아니고 비밀처럼 보이는 이름도 없으며 로컬 파일에 복사본도 없는 비밀은 통과합니다.
  • Claude Code가 요청마다 만드는 일부 첨부 파일은 플러그인이 다시 쓸 수 없습니다.
  • 플러그인이 로드되기 전에 Claude가 본 비밀은 컨텍스트에 남습니다.

설치

먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.

claude plugin marketplace add mashabek/claude-mods
claude plugin install secret-mask
원문 / README

secret-mask

Masks secrets in tool output, file reads and prompts before Claude reads them. Claude sees ‹secret:1›, and your screen still shows the real value.

Your terminal shows the secret, Claude reads ‹secret:1›

A PreToolUse hook could only block that command. This lets it run and masks the output.

Tested with Claude Code 2.1.288. Function hooks are early access, so a later release may break it.

Install

claude plugin marketplace add mashabek/claude-mods
claude plugin install secret-mask@claude-mods

Commands

| | | |---|---| | /secret-mask | Status, which files were read, and what was masked. Never prints a value. | | /secret-mask on, off | Turns masking on or off. Remembered across sessions. | | /secret-mask rescan | Rereads secret files after you edit a .env. |

The status line shows 🔒 3 masked once something has been masked.

What it masks

  • Values from the project's .env files, ~/.aws/credentials, ~/.npmrc, ~/.netrc, ~/.pgpass, and environment variables named like *_TOKEN, *_SECRET or *_PASSWORD, wherever they show up, including URL-encoded and base64 copies.
  • GitHub, GitLab, AWS, Anthropic, OpenAI, Stripe, Slack, Google, npm and SendGrid tokens, JWTs, private keys, Authorization headers, and passwords in user:pass@host URLs.
  • Token-like values assigned to secret names, like apiKey = "..." or SESSION_SECRET=....

Commit hashes, UUIDs, paths, process.env.X and placeholders like ${DB_PASS} are left alone. It makes no network or model calls and has no dependencies. Values are only held in memory. The whole thing is about 320 lines in hooks/, with 23 tests.

Limits

  • A secret with no known format, no secret-looking name and no copy in a local file gets through.
  • Some attachments Claude Code builds per request can't be rewritten by plugins.
  • Secrets Claude saw before the plugin loaded stay in its context.

동명의 다른 작품

비슷한 프로젝트