osm

by pratikbin · ★ 2 · updated 4 days ago

Status lineGuardsCommandsPrompt

0

Replaces a secret with a format-preserving fake before the model reads it, and restores the real credential on the way into a tool call. The map survives a resume or a reload; set persist off to keep it in memory only.

install osm

Install

/plugin marketplace add pratikbin/opensecretmask
/plugin install osm@opensecretmask

Then run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.

View source on GitHub

What it hooks into

From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.

Events
agent.spawnsession.sendcommand.runsession.compactprompt.submitskill.promptsession.receiveprompt.contextprompt.sectionsession.starttool.call
API calls
$.command.register$.fs.read$.store.get$.store.set$.ui.log$.ui.status

Origin

How it got here
Found through a post on X by @pratikbin, then checked on GitHub: the repo has a plugin manifest and function hooks. Listed .
Repository
github.com/pratikbin/opensecretmask
Path in repo
repository root
Source commit
f3d70db the exact code the scan read
Author
@pratikbin
License
MIT
First published
Last pushed
First listed here
On X
Mentioned in 1 post on X

Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.

Posts about this repo

pratikbin.node@pratikbin

@bcherny Mods are amazing, Since this was in alpha a month back, I created mod which will mask secrets with similar strings locally, so none of the credentials will make it to the API servers of Anthropic or any other https://github.com/pratikbin/opensecretmask