PlugMyPlugin
← Browse

credential-guard

yurukusa ★ 7

credential-guard is a Claude Code plugin that intercepts tool execution via a PreToolUse hook to detect and block credential leakage, including writes to .env files, API keys in shell commands, hardcoded tokens, and service account JSON files. It uses pattern matching to identify common secret patterns like AWS_SECRET, GITHUB_TOKEN, OPENAI_API_KEY, and credential filenames before they are executed.

Security No API key detected runs shell

Install

> /plugin marketplace add yurukusa/cc-safe-setup/tree/HEAD/plugins/credential-guard
> /plugin install credential-guard

Source: https://github.com/yurukusa/cc-safe-setup/tree/HEAD/plugins/credential-guard

What it's made of

5 hooks

Commands
0
Agents
0
Skills
0
MCP servers
0
Hooks
5 · PreToolUse

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
! ""))}catch(e){}})' %s .env. AWS_SECRET DATABASE_URL' GITHUB_TOKEN OPENAI_API_KEY api credentials credentials\.json' dist)$' grep key key.json password)[-_]?[a-zA-Z0-9]{20,}' pk print((d.get("tool_input") process.stdin.on(data,d=>s+=d).on(end,()=>{try{process.stdout.write(String((JSON.parse(s).tool_input sample secret secret' template token { {}).command {}).file_path } })
Talks to
nothing external detected

Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (yurukusa).