mashabek/claude-mods/tree/main/plugins/secret-mask
關於這個 mod
secret-mask
在 Claude 讀取前遮蓋工具輸出、檔案讀取結果和提示中的機密。Claude 看到的是 ‹secret:1›,而畫面仍顯示實際值。
PreToolUse hook 只能阻擋指令,而此外掛會讓指令繼續執行並遮蓋輸出。
已使用 Claude Code 2.1.288 測試。Function hook 處於搶先體驗階段,後續版本可能使其失效。
Install
claude plugin marketplace add mashabek/claude-mods
claude plugin install secret-mask@claude-mods
Commands
| | |
|---|---|
| /secret-mask | 顯示狀態、讀取過的檔案以及被遮蓋的內容。絕不輸出值。 |
| /secret-mask on, off | 開啟或關閉遮蓋。設定會跨工作階段記住。 |
| /secret-mask rescan | 編輯 .env 後重新讀取機密檔案。 |
一旦有內容被遮蓋,狀態列會顯示 🔒 3 masked。
What it masks
- 專案的
.env檔案、~/.aws/credentials、~/.npmrc、~/.netrc、~/.pgpass,以及名稱類似*_TOKEN、*_SECRET或*_PASSWORD的環境變數值;無論出現在哪裡,包括 URL 編碼和 base64 副本都會處理。 - GitHub、GitLab、AWS、Anthropic、OpenAI、Stripe、Slack、Google、npm 和 SendGrid 權杖、JWT、私密金鑰、
Authorization標頭,以及user:pass@hostURL 中的密碼。 - 指派給機密名稱的權杖樣式值,例如
apiKey = "..."或SESSION_SECRET=...。
提交雜湊、UUID、路徑、process.env.X 和 ${DB_PASS} 之類的預留位置會保持不變。它不進行網路或模型呼叫,也沒有相依性。值只保存在記憶體中。整個外掛在 hooks/ 中約 320 行,包含 23 個測試。
Limits
- 沒有已知格式、名稱也不像機密且本機檔案中沒有副本的機密會直接通過。
- Claude Code 為每個請求建立的某些附件無法由外掛重寫。
- 外掛載入前 Claude 已經看過的機密會留在上下文中。
安裝
請先查看作者 README,確認 marketplace 與外掛名稱;指令可能隨儲存庫結構而變動。
claude plugin marketplace add mashabek/claude-mods claude plugin install secret-mask
原文 / README
secret-mask
Masks secrets in tool output, file reads and prompts before Claude reads them. Claude sees
‹secret:1›, and your screen still shows the real value.
A PreToolUse hook could only block that command. This lets it run and masks the output.
Tested with Claude Code 2.1.288. Function hooks are early access, so a later release may break it.
Install
claude plugin marketplace add mashabek/claude-mods
claude plugin install secret-mask@claude-mods
Commands
| | |
|---|---|
| /secret-mask | Status, which files were read, and what was masked. Never prints a value. |
| /secret-mask on, off | Turns masking on or off. Remembered across sessions. |
| /secret-mask rescan | Rereads secret files after you edit a .env. |
The status line shows 🔒 3 masked once something has been masked.
What it masks
- Values from the project's
.envfiles,~/.aws/credentials,~/.npmrc,~/.netrc,~/.pgpass, and environment variables named like*_TOKEN,*_SECRETor*_PASSWORD, wherever they show up, including URL-encoded and base64 copies. - GitHub, GitLab, AWS, Anthropic, OpenAI, Stripe, Slack, Google, npm and SendGrid tokens, JWTs,
private keys,
Authorizationheaders, and passwords inuser:pass@hostURLs. - Token-like values assigned to secret names, like
apiKey = "..."orSESSION_SECRET=....
Commit hashes, UUIDs, paths, process.env.X and placeholders like ${DB_PASS} are left alone.
It makes no network or model calls and has no dependencies. Values are only held in memory.
The whole thing is about 320 lines in hooks/, with 23 tests.
Limits
- A secret with no known format, no secret-looking name and no copy in a local file gets through.
- Some attachments Claude Code builds per request can't be rewritten by plugins.
- Secrets Claude saw before the plugin loaded stay in its context.
其他同名作品
- secret-maskhomieyangg · ★ 2
- secret-maskFazzani · ★ 1
