Free · Apache-2.0 · by mcpgate

Your secrets never reach Anthropic or OpenAI. Your tools still get them.

maisecrets is a free plugin for Claude Code and Codex. It catches passwords, keys and personal data on your machine before they go to the model: in what you type, and in every file and command output the agent reads. The model works with a placeholder. Your API calls, deploys and gateway requests still carry the real value.

  • Runs locally
  • No network access
  • Python standard library only
  • Free forever

What maisecrets does, all on your machine

YOUR MACHINE LEAVES YOUR MACHINE You type a token in the prompt The agent reads .env file or command output You hand a password over password: … or /maisecrets:put maisecrets Detect and swap value → ⟦SECRET_c1⟧ Vault your keychain At execution insert the real value one-time grant, this session only redact the output The model Anthropic · OpenAI sees placeholders only Your tools API · deploy · MCP server · gateway get the real value ⟦SECRET_c1⟧ the agent writes curl -u ⟦SECRET_c1⟧ … real value output
The real value (orange) stays on your machine and goes only into the call that needs it. The model gets placeholders, in both directions.

A blocked prompt sends zero requests to Anthropic or OpenAI. A value resolves only in the session where a human typed it, through a one-time grant, under a rate cap. Detection is deterministic: the gitleaks ruleset, Microsoft Presidio's PII patterns with their checksums, Yelp detect-secrets, and a few own rules. No model decides what is a secret.

What the model sees

You ask the agent to write a deploy script, and it reads your .env.

What the command printed
DB_PASSWORD=example-hunter2-9Qz
STRIPE_KEY=sk_live_example…
What the model received
DB_PASSWORD=⟦SECRET_c1⟧
STRIPE_KEY=⟦SECRET_c2⟧

The agent writes the command with the placeholder. You approve it. At execution the value is read once from your keychain, and the output is redacted again on the way back. The password was never in the prompt, the transcript, or the model's context.

Give the agent a password on purpose

Sometimes the agent needs the password to do the job. Label it, and keep working.

You type
log in to staging and run the migration,
password: correct-horse-battery-9
You send instead
log in to staging and run the migration,
password: ⟦SECRET_c4⟧

maisecrets stops the first prompt before it leaves the machine, stores the value, and puts the rewritten prompt into your clipboard. Paste it and send, or type /ms in Claude Code: it sends the rewritten prompt without the clipboard, also over SSH and in Remote Control. The agent does the task with the placeholder, and the value goes only into the real login.

With a label

password:, passwort:, DB_PASSWORD=, "secret": "…": any spelling in English, German and Spanish, even with the value on the next line. The value needs 8 characters or more and must not be a placeholder or a dictionary word, so password: yes stays text.

With /maisecrets:put

Copy the value and run /maisecrets:put in Claude Code. The placeholder replaces the value in your clipboard. Paste it where the agent needs the value.

A token, a key or an IBAN needs no label: its shape is enough. What it detects, and what not.

Install

Claude Code
claude plugin marketplace add Mcpgate-de/maisecrets
claude plugin install maisecrets@maisecrets
Codex
codex plugin marketplace add https://github.com/Mcpgate-de/maisecrets.git
codex plugin add maisecrets@maisecrets

Start a new session after the install. In Codex, open /hooks and trust the maisecrets entries once; until you do, no hook runs. Python 3.11 or newer is required. Without it the plugin blocks every prompt instead of letting one through.

What it detects

Detection does not depend on the file name. It scans every prompt and every tool result, wherever the text comes from: cat config.yaml, git diff, kubectl get secret, a psql dump. .env is only the example.

Token shapes

Anywhere in the text: the gitleaks rules, prefixes such as glpat- and whsec_, AWS keys, Bearer headers.

Labelled values

A label and a value in any spelling, also across a line break. From 8 characters, never a placeholder or a dictionary word.

Personal data

By shape: email, phone with a country code, IBAN, card, IP, and German identifiers.

Not detected: a password without a label in a sentence, such as "use Sommer2026 for the login". That is the limit of pattern matching, not a setting. Label it, or use /maisecrets:put.

Where it works

ClientPromptReal callTool outputStatus
Claude Code, Cowork ✅ ✅ ✅ Built and proven by the test harness.
Codex (CLI, IDE extension, ChatGPT desktop app) ✅ ✅ ✅ Built. Trust the hooks once in /hooks.
Cursor ☑️ ☑️ ⚠️ Waits for a shell-output hook.
Copilot CLI ⚠️ ☑️ ☑️ Waits for a prompt hook.
Chat apps, web, mobile ❌ ❌ ❌ No hooks. The plugin cannot help here.

✅ proven by the harness in the repository · ☑️ possible per the vendor's hook documentation, not measured · ⚠️ partly · ❌ no hook. A client without a prompt or an output guard cannot be made safe by a plugin. We do not ship an adapter that would look protected and leak.

What it does not protect

  • No hook, no protection. Chat apps, the web and the mobile apps run no plugin hooks.
  • Names are not detected. Detection is regex with validators, by design.
  • A transformed value passes. Base64, or a value split across lines, is not recognised.
  • Your own processes can read the vault. The guards stand in front of the agent, not in front of you.
  • Tool output above 50,000 characters is written to a file by Claude Code and is not rewritten.

The full list, the threat model and three security reviews are in the repository.

Why mcpgate builds this

mcpgate is a self-hosted MCP gateway for teams. It pseudonymizes PII before the model sees it. Then we counted our own Claude Code sessions: 185 real credentials across 3,254 sessions, May to September 2026. 80% of them never passed through the gateway. They came from files and commands on the laptop.

A gateway protects what goes through it. maisecrets protects what never reaches it. It is free, for one laptop or for a whole company.

Learn about the mcpgate gateway →

For your whole company

One person installing a plugin protects one laptop. An admin can make it the default for everyone who uses Claude or Codex at work, so the protection does not depend on each person remembering it.

Claude (organisation)

Add maisecrets from a private or internal marketplace repository in the organisation settings, and set it to required. Every member gets it at session start and needs no access to the repository. Updates arrive the same way.

Codex

Ship the hooks as managed hooks through requirements.toml and your MDM. Policy trusts them, and users cannot turn them off. In a ChatGPT workspace, import the same marketplace under Admin > Plugins.

How you know it runs

Every session starts with one line: maisecrets X.Y.Z active. If it is missing, the plugin did not load. Chat apps, the web and the mobile apps run no hooks and stay outside.

The organisation sync accepts no public repository. Create a private one whose marketplace lists maisecrets with its GitHub repository as the source, or mirror the repository and review each release before your members get it. The administrator guide has the steps.

Questions

Does maisecrets send anything anywhere?

No. No hook has network access. The plugin has no telemetry, no account and no licence check. Everything it runs is readable Python source in the repository, with no dependency outside the standard library.

Where does a value go when it is detected?

Into a local vault on your machine: the macOS login keychain, the Windows Credential Locker, or an encrypted file on Linux. Every entry has a time to live. When it expires, the value is deleted.

Is it really free?

Yes, and it stays free. maisecrets is Apache-2.0. There is no paid tier and no feature held back for one. mcpgate, the self-hosted gateway for teams, is a separate product.

Can we enforce it for the whole company?

Yes. In a claude.ai organisation an admin adds maisecrets from a private marketplace repository and sets it to required, so every member gets it at session start. In Codex an admin ships the hooks as managed hooks through requirements.toml and MDM; policy trusts them, and users cannot turn them off.

Does it replace a secrets manager?

No. It keeps values out of the model. A process that runs as you can still read the vault, like any keychain. The threat model in the repository says exactly where the line is.

Support · Privacy · Changelog