Your secrets never reach Anthropic or OpenAI. Your tools still get them.
maisecrets is a free plugin for Claude Code and Codex. It catches passwords, keys and personal data on your machine before they go to the model: in what you type, and in every file and command output the agent reads. The model works with a placeholder. Your API calls, deploys and gateway requests still carry the real value.
- Runs locally
- No network access
- Python standard library only
- Free forever
What maisecrets does, all on your machine
A blocked prompt sends zero requests to Anthropic or OpenAI. A value resolves only in the session where a human typed it, through a one-time grant, under a rate cap. Detection is deterministic: the gitleaks ruleset, Microsoft Presidio's PII patterns with their checksums, Yelp detect-secrets, and a few own rules. No model decides what is a secret.
What the model sees
You ask the agent to write a deploy script, and it reads your .env.
DB_PASSWORD=example-hunter2-9Qz
STRIPE_KEY=sk_live_example…
DB_PASSWORD=⟦SECRET_c1⟧
STRIPE_KEY=⟦SECRET_c2⟧
The agent writes the command with the placeholder. You approve it. At execution the value is read once from your keychain, and the output is redacted again on the way back. The password was never in the prompt, the transcript, or the model's context.
Give the agent a password on purpose
Sometimes the agent needs the password to do the job. Label it, and keep working.
log in to staging and run the migration,
password: correct-horse-battery-9
log in to staging and run the migration,
password: ⟦SECRET_c4⟧
maisecrets stops the first prompt before it leaves the machine, stores the value, and puts the rewritten prompt into your clipboard. Paste it and send, or type /ms in Claude Code: it sends the rewritten prompt without the clipboard, also over SSH and in Remote Control. The agent does the task with the placeholder, and the value goes only into the real login.
With a label
password:, passwort:, DB_PASSWORD=, "secret": "…": any spelling in English, German and Spanish, even with the value on the next line. The value needs 8 characters or more and must not be a placeholder or a dictionary word, so password: yes stays text.
With /maisecrets:put
Copy the value and run /maisecrets:put in Claude Code. The placeholder replaces the value in your clipboard. Paste it where the agent needs the value.
A token, a key or an IBAN needs no label: its shape is enough. What it detects, and what not.
Install
claude plugin marketplace add Mcpgate-de/maisecrets
claude plugin install maisecrets@maisecrets
codex plugin marketplace add https://github.com/Mcpgate-de/maisecrets.git
codex plugin add maisecrets@maisecrets
Start a new session after the install. In Codex, open /hooks and trust the maisecrets entries once; until you do, no hook runs. Python 3.11 or newer is required. Without it the plugin blocks every prompt instead of letting one through.
What it detects
Detection does not depend on the file name. It scans every prompt and every tool result, wherever the text comes from: cat config.yaml, git diff, kubectl get secret, a psql dump. .env is only the example.
Token shapes
Anywhere in the text: the gitleaks rules, prefixes such as glpat- and whsec_, AWS keys, Bearer headers.
Labelled values
A label and a value in any spelling, also across a line break. From 8 characters, never a placeholder or a dictionary word.
Personal data
By shape: email, phone with a country code, IBAN, card, IP, and German identifiers.
Not detected: a password without a label in a sentence, such as "use Sommer2026 for the login". That is the limit of pattern matching, not a setting. Label it, or use /maisecrets:put.
Where it works
| Client | Prompt | Real call | Tool output | Status |
|---|---|---|---|---|
| Claude Code, Cowork | ✅ | ✅ | ✅ | Built and proven by the test harness. |
| Codex (CLI, IDE extension, ChatGPT desktop app) | ✅ | ✅ | ✅ | Built. Trust the hooks once in /hooks. |
| Cursor | ☑️ | ☑️ | ⚠️ | Waits for a shell-output hook. |
| Copilot CLI | ⚠️ | ☑️ | ☑️ | Waits for a prompt hook. |
| Chat apps, web, mobile | ❌ | ❌ | ❌ | No hooks. The plugin cannot help here. |
✅ proven by the harness in the repository · ☑️ possible per the vendor's hook documentation, not measured · ⚠️ partly · ❌ no hook. A client without a prompt or an output guard cannot be made safe by a plugin. We do not ship an adapter that would look protected and leak.
What it does not protect
- No hook, no protection. Chat apps, the web and the mobile apps run no plugin hooks.
- Names are not detected. Detection is regex with validators, by design.
- A transformed value passes. Base64, or a value split across lines, is not recognised.
- Your own processes can read the vault. The guards stand in front of the agent, not in front of you.
- Tool output above 50,000 characters is written to a file by Claude Code and is not rewritten.
The full list, the threat model and three security reviews are in the repository.
Why mcpgate builds this
mcpgate is a self-hosted MCP gateway for teams. It pseudonymizes PII before the model sees it. Then we counted our own Claude Code sessions: 185 real credentials across 3,254 sessions, May to September 2026. 80% of them never passed through the gateway. They came from files and commands on the laptop.
A gateway protects what goes through it. maisecrets protects what never reaches it. It is free, for one laptop or for a whole company.
Learn about the mcpgate gateway →For your whole company
One person installing a plugin protects one laptop. An admin can make it the default for everyone who uses Claude or Codex at work, so the protection does not depend on each person remembering it.
Claude (organisation)
Add maisecrets from a private or internal marketplace repository in the organisation settings, and set it to required. Every member gets it at session start and needs no access to the repository. Updates arrive the same way.
Codex
Ship the hooks as managed hooks through requirements.toml and your MDM. Policy trusts them, and users cannot turn them off. In a ChatGPT workspace, import the same marketplace under Admin > Plugins.
How you know it runs
Every session starts with one line: maisecrets X.Y.Z active. If it is missing, the plugin did not load. Chat apps, the web and the mobile apps run no hooks and stay outside.
The organisation sync accepts no public repository. Create a private one whose marketplace lists maisecrets with its GitHub repository as the source, or mirror the repository and review each release before your members get it. The administrator guide has the steps.
Questions
Does maisecrets send anything anywhere?
No. No hook has network access. The plugin has no telemetry, no account and no licence check. Everything it runs is readable Python source in the repository, with no dependency outside the standard library.
Where does a value go when it is detected?
Into a local vault on your machine: the macOS login keychain, the Windows Credential Locker, or an encrypted file on Linux. Every entry has a time to live. When it expires, the value is deleted.
Is it really free?
Yes, and it stays free. maisecrets is Apache-2.0. There is no paid tier and no feature held back for one. mcpgate, the self-hosted gateway for teams, is a separate product.
Can we enforce it for the whole company?
Yes. In a claude.ai organisation an admin adds maisecrets from a private marketplace repository and sets it to required, so every member gets it at session start. In Codex an admin ships the hooks as managed hooks through requirements.toml and MDM; policy trusts them, and users cannot turn them off.
Does it replace a secrets manager?
No. It keeps values out of the model. A process that runs as you can still read the vault, like any keychain. The threat model in the repository says exactly where the line is.