secret-guard
by Mehmet Aras · ★ 4 · updated 2 days ago
Keeps secrets out of the conversation: hides API keys and private keys before the model or the transcript sees them, and blocks reads of credential files and commands that print secrets
Install
/plugin marketplace add arasovic/claude-code-mods/plugin install secret-guard@claude-code-modsThen run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
session.starttool.callsession.append- API calls
$.env.get$.fs.stat$.ui.status- Can see
every tool call- Reach
- level 1 of 3 reads filesreads env varsdraws
Origin
- How it got here
- Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
- Repository
- github.com/arasovic/claude-code-mods
- Path in repo
secret-guard- Author
- Mehmet Aras @arasovic
- License
- MIT
- First published
- Last pushed
- First listed here
- On X
- Mentioned in 2 posts on X
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.
Posts about this repo
Built a few mods for Claude Code. They draw inside the terminal: a live pane with context and 5h/7d limits, the files a session changed, a timeline of each turn, and a handoff file saved on every /compact. Open source, one marketplace add away: https://github.com/arasovic/claude-code-mods
One more: image-peek. Claude Code shows a pasted image as [Image #1]. This shows the image, above the prompt and in the chat. https://github.com/arasovic/claude-code-mods/tree/main/image-peek
More from arasovic/claude-code-mods
cache-timer
arasovic/claude-code-mods
Counts down to when the prompt cache expires, so you can send the next message before the whole conversation has to be cached again
change-ledger
arasovic/claude-code-mods
Lists the files this session edited in a pane (/changes), with line counts and who edited them, beside the git working tree
ci-watch
arasovic/claude-code-mods
Watches GitHub Actions in a band above the prompt after Claude pushes, opens a PR or pushes a tag: a progress bar per run, then pass or fail; optionally flags failed scheduled workflows at start
compact-keeper
arasovic/claude-code-mods
Saves each compaction's summary, with the files edited before it, to ~/.claude/handoffs so the context before /compact can be recovered
guardrails
arasovic/claude-code-mods
Blocks Cloudflare write commands, attribution lines in commits and PRs, and claude/ branch names
image-peek
arasovic/claude-code-mods
Shows the images you paste: thumbnails above the prompt, and larger pictures under each sent message in the chat; needs a kitty-graphics terminal such as Ghostty
loop-guard
arasovic/claude-code-mods
Tells the model, out of the user's sight, to stop when the same call fails twice with the same error
pin-board
arasovic/claude-code-mods
Pins standing notes with /pin that Claude keeps following after /compact and /clear; shows them in one row above the prompt or as a counter, and keeps them per folder with --keep
search-meter
arasovic/claude-code-mods
Counts the model's searches and colors each one: green found first try, yellow found after misses, red found nothing
session-meter
arasovic/claude-code-mods
Shows a live session pane (/ctx): context breakdown, usage limits with pace, tool calls and model requests; sends the model a one-time note when limits or context cross a threshold
show-me
arasovic/claude-code-mods
Draws the mermaid diagrams of each answer as images in a pane (/show-me); needs mmdc and a kitty-graphics terminal such as Ghostty
turn-footer
arasovic/claude-code-mods
Turns the line under each answer into a turn summary (tools, requests, tokens, cache hit) and shows the running tool in the spinner