honmoon-redact
by Honmoon · ★ 5 · updated 7 days ago
Client-side secret/PII redaction hooks: keep API keys and sensitive identifiers out of Claude Code's model context by redacting Read/Bash/Grep tool output, blocking prompts that carry secrets, and denying reads of known credential files. Session-transcript scrubbing verified on Claude Code 2.1.263 (updatedToolOutput is what gets persisted); re-verify on other versions.
Install
git clone https://github.com/pleaseai/honmoonclaude --plugin-dir ./honmoon/packages/claude-pluginThen run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
tool.callprompt.submit- API calls
$.clock.sleep$.http.fetch$.process.run$.session.cwd$.session.id$.ui.log- Can see
Read|Bash|Grep|WebFetch callsevery prompt- Reach
- level 3 of 3 networkruns processesdraws
Origin
- How it got here
- Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
- Repository
- github.com/pleaseai/honmoon
- Path in repo
packages/claude-plugin- Author
- Honmoon @pleaseai
- License
- Apache-2.0
- First published
- Last pushed
- First listed here
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.