← Browse
credential-guard
yurukusa ★ 7
credential-guard is a Claude Code plugin that intercepts tool execution via a PreToolUse hook to detect and block credential leakage, including writes to .env files, API keys in shell commands, hardcoded tokens, and service account JSON files. It uses pattern matching to identify common secret patterns like AWS_SECRET, GITHUB_TOKEN, OPENAI_API_KEY, and credential filenames before they are executed.
Install
> /plugin marketplace add yurukusa/cc-safe-setup/tree/HEAD/plugins/credential-guard
> /plugin install credential-guard
Source: https://github.com/yurukusa/cc-safe-setup/tree/HEAD/plugins/credential-guard
What it's made of
5 hooks
- Commands
- 0
- Agents
- 0
- Skills
- 0
- MCP servers
- 0
- Hooks
- 5 · PreToolUse
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
!""))}catch(e){}})'%s.env.AWS_SECRETDATABASE_URL'GITHUB_TOKENOPENAI_API_KEYapicredentialscredentials\.json'dist)$'grepkeykey.jsonpassword)[-_]?[a-zA-Z0-9]{20,}'pkprint((d.get("tool_input")process.stdin.on(data,d=>s+=d).on(end,()=>{try{process.stdout.write(String((JSON.parse(s).tool_inputsamplesecretsecret'templatetoken{{}).command{}).file_path}})- Talks to
- nothing external detected
Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (yurukusa).