ClaudeMods
☰
KO
● 0 명 접속 중 · 조회 0 회
후원프로젝트 제출
GitHub 저장소 · 작성자 homieyangg

secret-mask

모델이 보기 전에 도구 출력의 토큰처럼 보이는 문자열을 가리는 Claude Code hook 플러그인입니다.

homieyangg@homieyangg

homieyangg/claude-code-mods/tree/main/secret-mask

원본 게시물 이미지1
번역 완료

이 mod 소개

secret-mask는 claude-code-mods 시리즈의 Claude Code 플러그인으로 function hook 형태로 동작하며 Claude Code 2.1.287 이상이 필요합니다. Bash 명령 출력에서 자격 증명처럼 보이는 문자열을 찾으면 모델로 보내기 전에 앞의 4개 문자와 «…(masked)»로 바꿉니다. MCP 도구와 웹 가져오기 같은 다른 도구의 결과도 대화에 기록할 때 가립니다. 대상에는 sk-로 시작하는 API 키, GitHub 토큰(ghp_、gho_、ghu_、ghs_、ghr_、github_pat_), Slack 토큰(xoxa-、xoxb-、xoxp-、xoxr-、xoxs-), JWT, AWS 액세스 키 ID(AKIA…), Google API 키(AIza…), OAuth 토큰(ya29.…), Bearer 헤더, PEM 개인 키 블록이 포함됩니다. 이름에 TOKEN、SECRET、PASSWORD、API_KEY、PRIVATE_KEY、ACCESS_KEY가 들어간 NAME=value와 JSON 필드도 대상이며 값은 최소 16자이고 영숫자가 섞여야 합니다. Claude가 편집하려면 실제 파일 내용이 필요하므로 Read, Edit, Write, NotebookEdit 결과는 가리지 않습니다. /secret-mask는 현재 세션에서 가린 항목을 나열하고 /secret-mask off와 /secret-mask on은 가리기를 일시 중지하거나 다시 시작합니다. 작성자는 패턴 매칭이라 일부 자격 증명을 놓칠 수 있으므로, 기밀 파일 전체를 Claude에 넘기는 대신 사고 방지책으로 봐야 한다고 알립니다. 설치는 /plugin marketplace add homieyangg/claude-code-mods 뒤에 /plugin install을 실행하거나 --plugin-dir로 폴더를 로드하고 ~/.claude/settings.json에서 CLAUDE_CODE_PLUGIN_DIRS를 설정하는 방식입니다. 플러그인은 language 옵션(en、zh-TW、zh-CN)을 제공합니다. 라이선스는 MIT입니다. 이 항목은 도구 출력을 가로채 다시 쓰므로 민감한 자료 처리와 관련되며 공개 전에 사람이 검토하는 것이 좋습니다.

설치

먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.

claude plugin marketplace add homieyangg/claude-code-mods
claude plugin install secret-mask
원문 / README

claude-code-mods

English | 繁體中文 | 简体中文

Three mods for Claude Code, built as function hook plugins. Requires Claude Code 2.1.287 or later.

plan-bar, leftovers and secret-mask in one session

| Mod | What it does | Command | | --- | --- | --- | | plan-bar | Progress bars above the prompt while Claude works through a multi-step plan | /plans | | leftovers | Keeps a ledger of services, containers, backups and repos Claude left behind | /leftovers | | secret-mask | Masks token-like strings in tool output before the model sees them | /secret-mask |

Install

From this repo as a marketplace:

/plugin marketplace add homieyangg/claude-code-mods
/plugin install plan-bar@claude-code-mods
/plugin install leftovers@claude-code-mods
/plugin install secret-mask@claude-code-mods
/reload-plugins

Or clone it and load the folders directly. Edits reload while a session is running.

git clone https://github.com/homieyangg/claude-code-mods ~/claude-code-mods
claude --plugin-dir ~/claude-code-mods/plan-bar --plugin-dir ~/claude-code-mods/leftovers

To load them in every session, add the folders to ~/.claude/settings.json:

{
  "env": {
    "CLAUDE_CODE_PLUGIN_DIRS": "~/claude-code-mods/plan-bar:~/claude-code-mods/leftovers:~/claude-code-mods/secret-mask"
  }
}

plan-bar

plan-bar demo

Each plan gets one row above the prompt: the current stage, a bar split by stage, and a percentage. The row turns yellow while Claude is waiting on you and red when a task fails. A short sound plays when a stage finishes, when the plan waits, and when it ends.

Claude drives the bars itself. The mod registers two tools, plan_set and plan_update, and adds a short note to the system prompt asking Claude to use them for work with three or more steps.

| Command | | | --- | --- | | /plans | List the current plans | | /plans demo | Run a 20 second demo | | /plans clear | Remove all plans | | /plans sound off / on | Turn sounds off or on |

leftovers

leftovers demo

leftovers watches the Bash commands Claude runs, locally and over ssh, and writes down anything that keeps running or stays on disk after the session:

| Kind | Recorded from | | --- | --- | | launchd | launchctl bootstrap, launchctl load | | systemd | systemctl enable, systemctl start | | cron | crontab edits | | docker | docker run -d, docker compose up -d | | background | nohup, tmux new -d | | repo | gh repo create, git worktree add | | backup | copies or moves to .bak, .orig, .old |

It also tracks git repos Claude edited and shows the ones with uncommitted changes.

Above the prompt, a yellow dot shows how many are left next to the first item; click the count to expand the rest. /leftovers shows the full list grouped by machine. Clean up asks Claude to remove the item using the undo command it recorded, Done drops it from the ledger. Uncommitted repos get See changes and Ignore. When Claude runs the undo command itself (docker rm -f, systemctl disable, git worktree remove and so on) the item drops off on its own. The ledger is kept across sessions.

leftovers list

| Command | | | --- | --- | | /leftovers | Show the list | | /leftovers drop <n> | Remove item n from the ledger | | /leftovers clear | Empty the ledger |

secret-mask

secret-mask demo

When a Bash command prints something that looks like a credential, secret-mask replaces it with its first four characters and …(masked) before the output reaches the model. Results from other tools, such as MCP tools and web fetches, are masked when they are written to the conversation. A toast says how many were masked, and /secret-mask lists them.

It recognizes:

  • API keys starting with sk-
  • GitHub tokens: ghp_, gho_, ghu_, ghs_, ghr_, github_pat_
  • Slack tokens: xoxa-, xoxb-, xoxp-, xoxr-, xoxs-
  • JWTs, AWS access key IDs (AKIA…), Google API keys (AIza…) and OAuth tokens (ya29.…)
  • Bearer <token> headers and PEM private key blocks
  • NAME=value and JSON fields whose name contains TOKEN, SECRET, PASSWORD, API_KEY, PRIVATE_KEY or ACCESS_KEY, when the value is at least 16 characters and mixes letters and digits

This is pattern matching, so it will miss things. Results from Read, Edit, Write and NotebookEdit are left alone, because Claude needs the real file contents to edit them. Treat it as a guard against accidents, not as a way to hand Claude a file full of secrets.

| Command | | | --- | --- | | /secret-mask | List what was masked in this session | | /secret-mask off / on | Pause or resume masking for this session |

Clicking the buttons

The buttons above the prompt and in /leftovers take mouse clicks only in Claude Code's fullscreen mode. The default renderer does not turn on mouse reporting, so clicks never reach it. Turn fullscreen on in /config, or add "tui": "fullscreen" to ~/.claude/settings.json. In the default mode, press ctrl+x then tab to move into the row above the prompt, tab to pick a button and Enter to press it.

Language

Each mod has a language option: en (default), zh-TW or zh-CN. Change it in /config, or in ~/.claude/settings.json:

{
  "pluginConfigs": {
    "leftovers@claude-code-mods": { "options": { "language": "zh-TW" } }
  }
}

Use leftovers@inline as the key when the mod is loaded with --plugin-dir or CLAUDE_CODE_PLUGIN_DIRS.

/plugin install notes that the option is not set yet. You can ignore that; it falls back to en.

Development

claude plugin validate ./leftovers
claude plugin test ./leftovers

The demo recordings are made with VHS. media/tapes/setup-demo.sh builds a separate Claude Code config in ~/.claude-demo and a sample project in ~/acme-app; log in once with CLAUDE_CONFIG_DIR=~/.claude-demo claude auth login, then run media/tapes/record.sh plan-bar leftovers secret-mask hero.

License

MIT

동명의 다른 작품

비슷한 프로젝트