跳到主要内容
    ↑↓ 选择↵ 打开esc 关闭
    中文English
    amauryconstant

    Secret Cloak

    v0.1.4模型接入
    secret-cloak

    OpenCode plugin: redact secrets/PII via gitleaks before LLM requests, restore locally after

    GitHub 星标

    0

    月装机量

    18

    近 7 天 1

    综合评分SCORE

    23.5

    生态多维模型

    最近提交

    2 个月前

    2026-05-27

    快速安装与配置

    opencode.json

    写入当前项目的 opencode.json,只对这个仓库生效。

    opencode.json

    {
      "$schema": "https://opencode.ai/config.json",
      "plugin": ["secret-cloak@0.1.4"]
    }

    opencode 启动时会通过内嵌运行时自动加载 npm 依赖并缓存至本地目录,无需手动在全局环境执行安装。

    OpenCode plugin that redacts secrets/PII via gitleaks before LLM requests and restores them locally after.

    Quick Start

    1. Install gitleaks
    2. Add plugin to your OpenCode config:
    {
        "plugins": ["secret-cloak"]
    }
    
    1. (Optional) Create config in ~/.config/opencode/secret-cloak.config.json:
    {
        "enabled": true,
        "debug": false,
        "session": {
            "ttlMs": 3600000,
            "maxSessions": 1000,
            "maxMappings": 100000
        },
        "gitleaks": {
            "path": null,
            "patterns": {
                "exclude": []
            }
        }
    }
    

    Installation

    From npm

    Add secret-cloak to the plugins array in your OpenCode config:

    {
        "plugins": ["secret-cloak"]
    }
    

    Packages are installed automatically using Bun at startup and cached in ~/.cache/opencode/node_modules/.

    From local files

    Place the plugin in .opencode/plugins/ (project) or ~/.config/opencode/plugins/ (global). Create a package.json in your config directory if the plugin needs external dependencies.

    Requires gitleaks to be installed and available in PATH. The plugin auto-detects gitleaks on startup.

    Configuration

    Config files are searched in this order:

    1. OPENCODE_SECRET_CLOAK_CONFIG env var (absolute path)
    2. secret-cloak.config.json in project root
    3. .opencode/secret-cloak.config.json in project root
    4. ~/.config/opencode/secret-cloak.config.json globally

    Options

    Option Default Description
    enabled true Enable/disable the plugin
    debug false Enable debug logging
    session.ttlMs 3600000 Session TTL in milliseconds
    session.maxSessions 1000 Max concurrent sessions
    session.maxMappings 100000 Max secret mappings per session
    gitleaks.path null Custom gitleaks binary path (null = auto-detect)
    gitleaks.patterns.exclude [] Gitleaks rule IDs to exclude

    How It Works

    1. Detect — gitleaks scans messages for secrets/PII
    2. Redact — Secrets are replaced with placeholders before LLM request
    3. LLM — Request sent to LLM with redacted content
    4. Restore — Placeholders replaced with original secrets in response

    Session-based tracking ensures redactions are uniquely mapped per request and properly restored.