secret-cloakOpenCode plugin: redact secrets/PII via gitleaks before LLM requests, restore locally after
0
18
1 in 7 days
23.5
Multi-signal model
2 months ago
2026-05-27
Install and configure
opencode.jsonWrites to this project's opencode.json — applies to this repository only.
opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["secret-cloak@0.1.4"]
}Writes to ~/.config/opencode/opencode.json — applies to every project.
~/.config/opencode/opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["secret-cloak@0.1.4"]
}If you want to modify the plugin locally, install it into the project and reference the local path.
shell
pnpm add -D secret-cloakopencode loads npm dependencies through its embedded runtime on startup and caches them locally — no manual global install needed.
OpenCode plugin that redacts secrets/PII via gitleaks before LLM requests and restores them locally after.
Quick Start
- Install gitleaks
- Add plugin to your OpenCode config:
{
"plugins": ["secret-cloak"]
}
- (Optional) Create config in
~/.config/opencode/secret-cloak.config.json:
{
"enabled": true,
"debug": false,
"session": {
"ttlMs": 3600000,
"maxSessions": 1000,
"maxMappings": 100000
},
"gitleaks": {
"path": null,
"patterns": {
"exclude": []
}
}
}
Installation
From npm
Add secret-cloak to the plugins array in your OpenCode config:
{
"plugins": ["secret-cloak"]
}
Packages are installed automatically using Bun at startup and cached in ~/.cache/opencode/node_modules/.
From local files
Place the plugin in .opencode/plugins/ (project) or ~/.config/opencode/plugins/ (global). Create a package.json in your config directory if the plugin needs external dependencies.
Requires gitleaks to be installed and available in PATH. The plugin auto-detects gitleaks on startup.
Configuration
Config files are searched in this order:
OPENCODE_SECRET_CLOAK_CONFIGenv var (absolute path)secret-cloak.config.jsonin project root.opencode/secret-cloak.config.jsonin project root~/.config/opencode/secret-cloak.config.jsonglobally
Options
| Option | Default | Description |
|---|---|---|
enabled |
true |
Enable/disable the plugin |
debug |
false |
Enable debug logging |
session.ttlMs |
3600000 |
Session TTL in milliseconds |
session.maxSessions |
1000 |
Max concurrent sessions |
session.maxMappings |
100000 |
Max secret mappings per session |
gitleaks.path |
null |
Custom gitleaks binary path (null = auto-detect) |
gitleaks.patterns.exclude |
[] |
Gitleaks rule IDs to exclude |
How It Works
- Detect — gitleaks scans messages for secrets/PII
- Redact — Secrets are replaced with placeholders before LLM request
- LLM — Request sent to LLM with redacted content
- Restore — Placeholders replaced with original secrets in response
Session-based tracking ensures redactions are uniquely mapped per request and properly restored.