secret-shield
by mako-code · ★ 0 · updated 2 days ago
Keeps credentials out of your code, your shell commands and Claude's context: blocks hard-coded secrets in edits, asks before commands with literal keys, redacts secrets from tool results and flags them in prompts.
Install
/plugin marketplace add mako-code/gobworks/plugin install secret-shield@gobworksThen run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
session.startsession.endtool.callsession.appendprompt.submitcommand.run- API calls
$.clock.after$.clock.now$.command.register$.fs.read$.process.run$.prompt.fill$.state.get$.state.set$.ui.ask$.ui.log$.ui.status$.ui.toast- Can see
Write|Edit|NotebookEdit callsBash|PowerShell callsRead|Grep callsevery prompt- Reach
- level 2 of 3 other: $.state.getother: $.state.setruns processeswrites the prompt boxreads filesdraws
Origin
- How it got here
- Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
- Repository
- github.com/mako-code/gobworks
- Path in repo
mods/safety/secret-shield- Author
- @mako-code
- License
- MIT
- First published
- Last pushed
- First listed here
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.
More from mako-code/gobworks
achievements
mako-code/gobworks
A little game layer: 32 achievements for how you use Claude Code, with lifetime progress and a /achievements pane.
agent-router
mako-code/gobworks
Picks the model for each subagent by its type (Explore on Haiku by default) and can cap how many run at once.
arcade
mako-code/gobworks
Something to do during long turns: /snake and /2048 in a pane, with high scores and a nudge when Claude is done.
attribution
mako-code/gobworks
Your commit and pull request credit line, your way: Claude Code's default, none, or your own template with {model}.
auto-context
mako-code/gobworks
Say "this error", "the tests", "this file", "what you just did" or "the plan" and what it points at goes along with your prompt: the failing output, the test failures, the file, the diff, the plan. No model calls, size-capped, never twice, and Remove takes it back.
auto-continue
mako-code/gobworks
Keeps work flowing: when Claude stops mid-task ("Next I'll…") or asks an obvious yes ("Shall I continue?"), a 5-second countdown you can stop sends a short continue. Never for choices, missing info or risky steps.
auto-polish
mako-code/gobworks
Every prompt you type gets a quiet second read: without changing your words, a hidden note gives Claude the goal in one line, the likely scope, the project's checks to keep green, and what done means. Haiku only for vague prompts; See, Undo and Off in the band.
auto-retry
mako-code/gobworks
Keeps long sessions going through API errors and rate limits: resubmits after a backoff when idle, waits out rate limits with a countdown, never loops, and stops the moment you type.
auto-review
mako-code/gobworks
A quick second pair of eyes after edits: reviews the turn's diff in the background and offers to fix what it finds.
autotune
mako-code/gobworks
Per-prompt effort autopilot: classifies each prompt (Jev, Claude Haiku, or heuristics) and sets that turn's effort, and optionally its model, only when the switch beats the prompt-cache rewrite it causes.
bash-guard
mako-code/gobworks
Blocks catastrophic shell commands (rm -rf ~, curl | sh, force-push to main, DROP DATABASE, format C:) and asks before risky ones (git reset --hard, rm -rf, terraform apply), in Bash and PowerShell.
best-of-n
mako-code/gobworks
Runs 2-4 attempts at a task in parallel git worktrees, each with a different approach; compare their diffs and adopt the best.