ClaudeMods
☰
ZH-CN
● 0 人在线 · 浏览 0 次
赞助提交作品
GitHub 仓库 · 发布者 0xGondarxyz

secret-guard

一个让秘密信息远离对话和公共仓库的 Claude Code mod。

0xGondarxyz@0xGondarxyz

0xGondarxyz/claude-code-mods/tree/main/secret-guard

已翻译

关于这个 mod

secret-guard 会在 Claude 读取每个工具结果之前遮盖其中的 API key、token 和密码,并阻止可能把秘密或 home 路径泄露到公共仓库的 git push。它会检测带前缀的 token(Anthropic、OpenAI、GitHub、AWS、Google、Slack、Stripe、GitLab、npm、Telegram、JWT 等)、PEM 私钥区块、Bearer token、URL 密码和类似秘密的赋值,并将每项替换为显示类型和末 4 个字符的标记。写入保护会拒绝包含标记的 Write/Edit/MultiEdit/NotebookEdit 与 Bash 命令。push 检查会解析仓库和远端,向 gh 查询可见性,扫描未推送 commit 新增的行(如果命令还执行 add 或 commit,也会扫描工作树 diff 和未追踪文件);如果发现秘密或绝对 home 路径,就以最多 10 个 file:line 结果拒绝 push。通过 /plugin marketplace add 0xGondarxyz/claude-code-mods 和 /plugin install secret-guard@claude-code-mods 安装,也可以使用 --plugin-dir 运行。MIT 授权;mod 没有沙箱。

安装

请先查看作者 README 确认 marketplace 和插件名称;命令可能随仓库结构改变。

claude plugin marketplace add 0xGondarxyz/claude-code-mods
claude plugin install secret-guard
原文 / README

secret-guard

A Claude Code mod that keeps secrets out of the conversation and out of public repos.

  1. It masks API keys, tokens and passwords in every tool result before Claude reads them.
  2. It blocks a git push that would leak a secret or a home path to a public repo.

Install

/plugin marketplace add 0xGondarxyz/claude-code-mods
/plugin install secret-guard@claude-code-mods

Or try it without installing:

git clone https://github.com/0xGondarxyz/claude-code-mods
claude --plugin-dir claude-code-mods/secret-guard

Mods are not sandboxed. They run with the same access as Claude Code. Read the source before you install any mod, including this one.

Masking

Every tool result is checked before it is stored: built-in tools, MCP tools, the main thread and subagents. Each secret becomes a marker. The rest of the text is kept byte for byte.

ANTHROPIC_API_KEY=[masked anthropic_key ...a1b2]

The marker shows the kind and the last 4 characters.

What it finds:

  • Prefixed tokens: Anthropic, OpenAI, GitHub (ghp_, gho_, ghu_, ghs_, ghr_, github_pat_), AWS AKIA, Google AIza, Slack, Stripe, GitLab, Apify, Notion, Hugging Face, Replicate, npm, Telegram bot tokens, JWTs.
  • PEM private key blocks (the whole block).
  • Bearer tokens (Bearer followed by 20 or more token characters).
  • The password in a URL such as postgres://user:PASSWORD@host.
  • Assignments: a name that contains api_key, secret, token, password, credential, private_key, access_key or auth, then = or :, then a value of 16 or more characters with a letter and a digit. Only the value is masked.

What it leaves alone: placeholders (your_..., xxx..., <...>, ${...}, process.env..., os.environ..., changeme, example), git SHAs, UUIDs, numbers, file paths, npm sha512- integrity hashes.

Claude now sees markers, so it could write one back over the real secret. The write guard stops that. Write, Edit, MultiEdit and NotebookEdit are denied when the new text holds a marker, and so is a Bash command that holds one. Claude is told to edit around the line or ask you to change that value.

Push check

When a Bash command runs git push, secret-guard checks before it runs:

  1. It finds the repo (git -C <dir>, a leading cd <dir> &&, or the session folder) and the remote (default origin).
  2. It asks gh repo view for the visibility. PRIVATE or INTERNAL: the push goes through, no scan. PUBLIC or unknown (no gh, not GitHub, an error): it scans.
  3. It scans the added lines of every local commit the remote does not have. If the same command also runs git add or git commit, it scans the working tree diff and the untracked files too (not ignored, under 1 MB, not binary).
  4. It looks for the same secrets as masking, plus absolute home paths: your real home folder and any /home/<name>/ or /Users/<name>/ path, and Windows paths (C:\Users\<name>\, the forward-slash form and the JSON-escaped form, any drive letter). HOME and, when set, USERPROFILE count as your home folder. /home/user/, /home/runner/ and the Windows names Public, Default, Default User and All Users are ignored.

With findings, the push is denied. The text lists up to 10 as file:line kind. It never prints the secret. A toast says secret-guard: push blocked, N findings. When the visibility was unknown, the text says so.

If the scan itself fails (git error, timeout of about 5 seconds), the push is allowed and a toast says secret-guard: scan failed, push allowed.

Commands

| Command | What it does | | --- | --- | | /secret-guard | Shows how many values were masked this session and whether a pass is active. | | /secret-guard allow | Lets the next push skip the scan. The pass lasts 10 minutes and works once. |

For a false positive: run /secret-guard allow, then push again.

Limits

  • Detection is by pattern. A secret with no known prefix and no telling name (for example a bare random string) is not masked.
  • What the model reads is masked. The engine stores a tool result's structured record (what the screen draws) as made, so the transcript file on disk can still hold the raw output.
  • Rows that are not tool results (your prompts, attachments) are not masked.
  • git log output is cut at 4 MB. A very large unpushed history is only scanned in part.
  • Pushes started outside Claude Code's Bash tool (hooks, scripts it launches) are not seen.
  • A file that must contain the literal marker text cannot be written by Claude. Ask Claude to leave it to you.

No options.

License

MIT

其他同名作品

更多类似作品