homieyangg/claude-code-mods/tree/main/secret-mask

homieyangg/claude-code-mods/tree/main/secret-mask

secret-mask 是 claude-code-mods 系列中的 Claude Code 外掛,以 function hook 形式運作,需求是 Claude Code 2.1.287 以上版本。當 Bash 指令輸出看似憑證的字串時,會在輸出送到模型前替換成前四個字元加上 «…(masked)»;其他工具(例如 MCP 工具與網頁抓取)的結果寫入對話時也會遮罩。辨識範圍包含 sk- 開頭的 API 金鑰、GitHub 權杖(ghp_、gho_、ghu_、ghs_、ghr_、github_pat_)、Slack 權杖(xoxa-、xoxb-、xoxp-、xoxr-、xoxs-)、JWT、AWS 存取金鑰 ID(AKIA…)、Google API 金鑰(AIza…)、OAuth 權杖(ya29.…)、Bearer 標頭與 PEM 私鑰區塊,以及名稱含 TOKEN、SECRET、PASSWORD、API_KEY、PRIVATE_KEY、ACCESS_KEY 的 NAME=value 和 JSON 欄位(值至少 16 個字元,且需混合英數字)。Read、Edit、Write 與 NotebookEdit 的結果不遮罩,因為 Claude 需要真實檔案內容才能編輯。指令包括 /secret-mask,列出本次工作階段遮罩的項目;/secret-mask off 與 /secret-mask on 則可暫停或恢復遮罩。作者提醒這是樣式比對,可能漏掉部分憑證,應把它視為防止意外的措施,不是把整份機密檔案交給 Claude 的方法。安裝方式可以先執行 /plugin marketplace add homieyangg/claude-code-mods,再用 /plugin install;也可以用 --plugin-dir 載入資料夾,或在 ~/.claude/settings.json 設定 CLAUDE_CODE_PLUGIN_DIRS。外掛提供 language 選項(en、zh-TW、zh-CN)。授權為 MIT。這個項目會攔截並改寫工具輸出,涉及敏感資料處理,建議人工複核後再發佈。
請先查看作者 README,確認 marketplace 與外掛名稱;指令可能隨儲存庫結構而變動。
claude plugin marketplace add homieyangg/claude-code-mods claude plugin install secret-mask
Three mods for Claude Code, built as function hook plugins. Requires Claude Code 2.1.287 or later.

| Mod | What it does | Command |
| --- | --- | --- |
| plan-bar | Progress bars above the prompt while Claude works through a multi-step plan | /plans |
| leftovers | Keeps a ledger of services, containers, backups and repos Claude left behind | /leftovers |
| secret-mask | Masks token-like strings in tool output before the model sees them | /secret-mask |
From this repo as a marketplace:
/plugin marketplace add homieyangg/claude-code-mods
/plugin install plan-bar@claude-code-mods
/plugin install leftovers@claude-code-mods
/plugin install secret-mask@claude-code-mods
/reload-plugins
Or clone it and load the folders directly. Edits reload while a session is running.
git clone https://github.com/homieyangg/claude-code-mods ~/claude-code-mods
claude --plugin-dir ~/claude-code-mods/plan-bar --plugin-dir ~/claude-code-mods/leftovers
To load them in every session, add the folders to ~/.claude/settings.json:
{
"env": {
"CLAUDE_CODE_PLUGIN_DIRS": "~/claude-code-mods/plan-bar:~/claude-code-mods/leftovers:~/claude-code-mods/secret-mask"
}
}

Each plan gets one row above the prompt: the current stage, a bar split by stage, and a percentage. The row turns yellow while Claude is waiting on you and red when a task fails. A short sound plays when a stage finishes, when the plan waits, and when it ends.
Claude drives the bars itself. The mod registers two tools, plan_set and plan_update, and adds a short note to the system prompt asking Claude to use them for work with three or more steps.
| Command | |
| --- | --- |
| /plans | List the current plans |
| /plans demo | Run a 20 second demo |
| /plans clear | Remove all plans |
| /plans sound off / on | Turn sounds off or on |

leftovers watches the Bash commands Claude runs, locally and over ssh, and writes down anything that keeps running or stays on disk after the session:
| Kind | Recorded from |
| --- | --- |
| launchd | launchctl bootstrap, launchctl load |
| systemd | systemctl enable, systemctl start |
| cron | crontab edits |
| docker | docker run -d, docker compose up -d |
| background | nohup, tmux new -d |
| repo | gh repo create, git worktree add |
| backup | copies or moves to .bak, .orig, .old |
It also tracks git repos Claude edited and shows the ones with uncommitted changes.
Above the prompt, a yellow dot shows how many are left next to the first item; click the count to expand the rest. /leftovers shows the full list grouped by machine. Clean up asks Claude to remove the item using the undo command it recorded, Done drops it from the ledger. Uncommitted repos get See changes and Ignore. When Claude runs the undo command itself (docker rm -f, systemctl disable, git worktree remove and so on) the item drops off on its own. The ledger is kept across sessions.

| Command | |
| --- | --- |
| /leftovers | Show the list |
| /leftovers drop <n> | Remove item n from the ledger |
| /leftovers clear | Empty the ledger |

When a Bash command prints something that looks like a credential, secret-mask replaces it with its first four characters and …(masked) before the output reaches the model. Results from other tools, such as MCP tools and web fetches, are masked when they are written to the conversation. A toast says how many were masked, and /secret-mask lists them.
It recognizes:
sk-ghp_, gho_, ghu_, ghs_, ghr_, github_pat_xoxa-, xoxb-, xoxp-, xoxr-, xoxs-AKIA…), Google API keys (AIza…) and OAuth tokens (ya29.…)Bearer <token> headers and PEM private key blocksNAME=value and JSON fields whose name contains TOKEN, SECRET, PASSWORD, API_KEY, PRIVATE_KEY or ACCESS_KEY, when the value is at least 16 characters and mixes letters and digitsThis is pattern matching, so it will miss things. Results from Read, Edit, Write and NotebookEdit are left alone, because Claude needs the real file contents to edit them. Treat it as a guard against accidents, not as a way to hand Claude a file full of secrets.
| Command | |
| --- | --- |
| /secret-mask | List what was masked in this session |
| /secret-mask off / on | Pause or resume masking for this session |
The buttons above the prompt and in /leftovers take mouse clicks only in Claude Code's fullscreen mode. The default renderer does not turn on mouse reporting, so clicks never reach it. Turn fullscreen on in /config, or add "tui": "fullscreen" to ~/.claude/settings.json. In the default mode, press ctrl+x then tab to move into the row above the prompt, tab to pick a button and Enter to press it.
Each mod has a language option: en (default), zh-TW or zh-CN. Change it in /config, or in ~/.claude/settings.json:
{
"pluginConfigs": {
"leftovers@claude-code-mods": { "options": { "language": "zh-TW" } }
}
}
Use leftovers@inline as the key when the mod is loaded with --plugin-dir or CLAUDE_CODE_PLUGIN_DIRS.
/plugin install notes that the option is not set yet. You can ignore that; it falls back to en.
claude plugin validate ./leftovers
claude plugin test ./leftovers
The demo recordings are made with VHS. media/tapes/setup-demo.sh builds a separate Claude Code config in ~/.claude-demo and a sample project in ~/acme-app; log in once with CLAUDE_CONFIG_DIR=~/.claude-demo claude auth login, then run media/tapes/record.sh plan-bar leftovers secret-mask hero.
MIT