secret-scrub
by Pradeep Kumar Balakrishnan · ★ 0 · updated yesterday
Catches API keys, tokens and private keys in the prompt you are about to send, and masks or blocks them before they reach the model.
Install
/plugin marketplace add pradyb/claude-mods/plugin install secret-scrub@claude-modsThen run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
prompt.submit- API calls
$.ui.toast- Can see
every prompt- Reach
- level 0 of 3 draws
Origin
- How it got here
- Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
- Repository
- github.com/pradyb/claude-mods
- Path in repo
secret-scrub- Source commit
8add0fbthe exact code the scan read- Author
- Pradeep Kumar Balakrishnan @pradyb
- License
- MIT
- First published
- Last pushed
- First listed here
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.
More from pradyb/claude-mods
notify-router
pradyb/claude-mods
Rules for Claude Code alerts: when one is worth sending (done, blocked, error, usage limits) and where it goes (chime, macOS notification, ntfy, Slack, Discord or a JSON webhook).
safety-guard
pradyb/claude-mods
Blocks destructive shell commands and access to secret files (.env, SSH keys, cloud credentials).