osm
by pratikbin · ★ 2 · updated 4 days ago
Replaces a secret with a format-preserving fake before the model reads it, and restores the real credential on the way into a tool call. The map survives a resume or a reload; set persist off to keep it in memory only.
Install
/plugin marketplace add pratikbin/opensecretmask/plugin install osm@opensecretmaskThen run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
agent.spawnsession.sendcommand.runsession.compactprompt.submitskill.promptsession.receiveprompt.contextprompt.sectionsession.starttool.call- API calls
$.command.register$.fs.read$.store.get$.store.set$.ui.log$.ui.status
Origin
- How it got here
- Found through a post on X by @pratikbin, then checked on GitHub: the repo has a plugin manifest and function hooks. Listed .
- Repository
- github.com/pratikbin/opensecretmask
- Path in repo
- repository root
- Source commit
f3d70dbthe exact code the scan read- Author
- @pratikbin
- License
- MIT
- First published
- Last pushed
- First listed here
- On X
- Mentioned in 1 post on X
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.
Posts about this repo
@bcherny Mods are amazing, Since this was in alpha a month back, I created mod which will mask secrets with similar strings locally, so none of the credentials will make it to the API servers of Anthropic or any other https://github.com/pratikbin/opensecretmask