mashabek/claude-mods/tree/main/plugins/secret-mask
关于这个 mod
secret-mask
在 Claude 读取前遮盖工具输出、文件读取结果和提示中的机密。Claude 看到的是 ‹secret:1›,而屏幕仍显示真实值。
PreToolUse hook 只能阻止命令,而此插件会让命令继续运行并遮盖输出。
已使用 Claude Code 2.1.288 测试。Function hook 处于早期访问阶段,后续版本可能使其失效。
Install
claude plugin marketplace add mashabek/claude-mods
claude plugin install secret-mask@claude-mods
Commands
| | |
|---|---|
| /secret-mask | 显示状态、读取过的文件以及被遮盖的内容。绝不打印值。 |
| /secret-mask on, off | 开启或关闭遮盖。设置会跨会话记住。 |
| /secret-mask rescan | 编辑 .env 后重新读取机密文件。 |
一旦有内容被遮盖,状态栏会显示 🔒 3 masked。
What it masks
- 项目的
.env文件、~/.aws/credentials、~/.npmrc、~/.netrc、~/.pgpass,以及名称类似*_TOKEN、*_SECRET或*_PASSWORD的环境变量值;无论出现在何处,包括 URL 编码和 base64 副本都会处理。 - GitHub、GitLab、AWS、Anthropic、OpenAI、Stripe、Slack、Google、npm 和 SendGrid 令牌、JWT、私钥、
Authorization标头,以及user:pass@hostURL 中的密码。 - 分配给机密名称的令牌样式值,例如
apiKey = "..."或SESSION_SECRET=...。
提交哈希、UUID、路径、process.env.X 和 ${DB_PASS} 之类的占位符会保留不变。它不进行网络或模型调用,也没有依赖项。值只保存在内存中。整个插件在 hooks/ 中约 320 行,包含 23 个测试。
Limits
- 没有已知格式、名称也不像机密且本地文件中没有副本的机密会直接通过。
- Claude Code 为每个请求创建的某些附件无法由插件重写。
- 插件加载前 Claude 已经看到的机密会留在上下文中。
安装
请先查看作者 README 确认 marketplace 和插件名称;命令可能随仓库结构改变。
claude plugin marketplace add mashabek/claude-mods claude plugin install secret-mask
原文 / README
secret-mask
Masks secrets in tool output, file reads and prompts before Claude reads them. Claude sees
‹secret:1›, and your screen still shows the real value.
A PreToolUse hook could only block that command. This lets it run and masks the output.
Tested with Claude Code 2.1.288. Function hooks are early access, so a later release may break it.
Install
claude plugin marketplace add mashabek/claude-mods
claude plugin install secret-mask@claude-mods
Commands
| | |
|---|---|
| /secret-mask | Status, which files were read, and what was masked. Never prints a value. |
| /secret-mask on, off | Turns masking on or off. Remembered across sessions. |
| /secret-mask rescan | Rereads secret files after you edit a .env. |
The status line shows 🔒 3 masked once something has been masked.
What it masks
- Values from the project's
.envfiles,~/.aws/credentials,~/.npmrc,~/.netrc,~/.pgpass, and environment variables named like*_TOKEN,*_SECRETor*_PASSWORD, wherever they show up, including URL-encoded and base64 copies. - GitHub, GitLab, AWS, Anthropic, OpenAI, Stripe, Slack, Google, npm and SendGrid tokens, JWTs,
private keys,
Authorizationheaders, and passwords inuser:pass@hostURLs. - Token-like values assigned to secret names, like
apiKey = "..."orSESSION_SECRET=....
Commit hashes, UUIDs, paths, process.env.X and placeholders like ${DB_PASS} are left alone.
It makes no network or model calls and has no dependencies. Values are only held in memory.
The whole thing is about 320 lines in hooks/, with 23 tests.
Limits
- A secret with no known format, no secret-looking name and no copy in a local file gets through.
- Some attachments Claude Code builds per request can't be rewritten by plugins.
- Secrets Claude saw before the plugin loaded stay in its context.
其他同名作品
- secret-maskhomieyangg · ★ 2
- secret-maskFazzani · ★ 1
