secret-cloakOpenCode plugin: redact secrets/PII via gitleaks before LLM requests, restore locally after
0
18
近 7 天 1
23.5
生态多维模型
2 个月前
2026-05-27
快速安装与配置
opencode.json写入当前项目的 opencode.json,只对这个仓库生效。
opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["secret-cloak@0.1.4"]
}写入 ~/.config/opencode/opencode.json,对所有项目生效。
~/.config/opencode/opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["secret-cloak@0.1.4"]
}若你要在本地改造这个插件,先装到项目里再从本地路径引用。
shell
pnpm add -D secret-cloakopencode 启动时会通过内嵌运行时自动加载 npm 依赖并缓存至本地目录,无需手动在全局环境执行安装。
OpenCode plugin that redacts secrets/PII via gitleaks before LLM requests and restores them locally after.
Quick Start
- Install gitleaks
- Add plugin to your OpenCode config:
{
"plugins": ["secret-cloak"]
}
- (Optional) Create config in
~/.config/opencode/secret-cloak.config.json:
{
"enabled": true,
"debug": false,
"session": {
"ttlMs": 3600000,
"maxSessions": 1000,
"maxMappings": 100000
},
"gitleaks": {
"path": null,
"patterns": {
"exclude": []
}
}
}
Installation
From npm
Add secret-cloak to the plugins array in your OpenCode config:
{
"plugins": ["secret-cloak"]
}
Packages are installed automatically using Bun at startup and cached in ~/.cache/opencode/node_modules/.
From local files
Place the plugin in .opencode/plugins/ (project) or ~/.config/opencode/plugins/ (global). Create a package.json in your config directory if the plugin needs external dependencies.
Requires gitleaks to be installed and available in PATH. The plugin auto-detects gitleaks on startup.
Configuration
Config files are searched in this order:
OPENCODE_SECRET_CLOAK_CONFIGenv var (absolute path)secret-cloak.config.jsonin project root.opencode/secret-cloak.config.jsonin project root~/.config/opencode/secret-cloak.config.jsonglobally
Options
| Option | Default | Description |
|---|---|---|
enabled |
true |
Enable/disable the plugin |
debug |
false |
Enable debug logging |
session.ttlMs |
3600000 |
Session TTL in milliseconds |
session.maxSessions |
1000 |
Max concurrent sessions |
session.maxMappings |
100000 |
Max secret mappings per session |
gitleaks.path |
null |
Custom gitleaks binary path (null = auto-detect) |
gitleaks.patterns.exclude |
[] |
Gitleaks rule IDs to exclude |
How It Works
- Detect — gitleaks scans messages for secrets/PII
- Redact — Secrets are replaced with placeholders before LLM request
- LLM — Request sent to LLM with redacted content
- Restore — Placeholders replaced with original secrets in response
Session-based tracking ensures redactions are uniquely mapped per request and properly restored.