Keep secrets out of Claude Code's context
secret-guard scans every tool output, prompt and attachment with gitleaks before the model reads it. When an API key, token or private key shows up, the agent pauses and you decide what the model sees.
- Cut the secrets
- Hide the whole output
- Let the model see it
- Not a secret, allow
GITHUB_TOKEN=[SECRET:github-pat#1] and never learns the value.Why
A coding agent reads whatever is in front of it: .env files, configs, verbose curl output, logs. Everything it reads is sent to the model and kept in the session transcript. Removing a secret afterwards does not take it back, so secret-guard checks text on its way in.
Before, not after
It hooks the points where text enters the context: tool results, prompts, @-files, CLAUDE.md, attachments.
You decide
Cut the secret, hide the output, or let it through. A secret you cut once is cut again without asking.
Hides when unsure
A dismissed dialog, a missing scanner or a crashed hook withholds the text. Nothing passes silently.
Values stay local
Dialogs and the journal show masks and hashes; the /secrets pane shows a value only when you ask, for 30 seconds. Cut secrets are absent from the transcript file too.
What it checks
| Where text enters | On a finding |
|---|---|
| Any tool's output: Bash, Read, Grep, WebFetch, MCP, subagents | Dialog: cut / hide / pass / not a secret |
| Your prompt | Dialog: cut / send as is / don't send |
@path mentions | Dialog: cut / don't attach / attach as is |
| CLAUDE.md, reminders, attachments | Cut automatically, logged in the pane |
| Every other stored row | Safety net: cut automatically |
gitleaks also decodes base64, hex and percent-encoding, so cat .env | base64 is caught. It honours your project's .gitleaks.toml, .gitleaksignore and gitleaks:allow comments.
Install
Requires Claude Code with mods (tested on 2.1.292) and gitleaks 8.19 or newer.
brew install gitleaks
Then, at the Claude Code prompt:
/plugin install secret-guard --marketplace legostin/claude-code-secret-guard
Answer y to add the marketplace and pick a scope. Open the pane with /secrets. To switch the dialogs to Russian, run /plugin configure secret-guard@secret-guard and set language to ru.
Limits
- Pattern-based: it finds what gitleaks' ~200 rules and entropy checks find. A password with no recognizable shape can get through.
- Images and screenshots are not scanned.
- A value you let through is the model's.
- No protection while the mod is not loaded. The status line and
/secretsshow its state. - Mods are an early-access Claude Code API.