This mod runs inside Claude Code with your own access. It makes no network call, starts no process, writes no file, and calls no model. The validator prints that reach before any code runs:
claude plugin validate plugins/redact --strict
Email karan@karanbansal.in. Include the Claude Code version (claude --version), the mod version from plugins/redact/.claude-plugin/plugin.json, and the shape of the text involved with fake values. Never send a real secret.
A bypass (text the rules should catch and do not) is a bug, not a vulnerability; open a public issue for it unless it also leaks something already hidden. A way to make a hidden value leave the machine, or to make the mod store a raw value it reported as hidden, is a vulnerability; email it.
- A placeholder restored outside
Edit,WriteandNotebookEditarguments. - A row stored raw after the mod reported it hidden.
- A crafted row that makes the mod call anything beyond
$.command.register,$.state, and$.ui.log. - A regex that can be made to run past the ten-second hook budget.
- Secrets in formats the rules do not know. See
plugins/redact/README.mdunder Limitations and open an issue. - Engine bookkeeping records the hooks cannot rewrite (the
queue-operationrecord and a command'sargsstamp). Those are documented and not sent to the model.