Phantom Secrets — AI skill for Claude Code
Stop AI coding agents from leaking your API keys.
How to install Phantom Secrets
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open ashlrai/phantom-secrets and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Phantom Secrets does
Stop AI coding agents from leaking your API keys. Local proxy + MCP that swaps real secrets for phm_ tokens — works with Claude Code, Cursor, Windsurf, and Codex.
Alternatives in AI
- WindsurfAPI — Turn Windsurf / Devin Desktop's 100+ AI models (Claude, GPT, Gemini, DeepSeek, Kimi, GLM, SWE) into OpenAI-, A 3k ★
- Jcodemunch MCP — Cut AI token costs 95%+ on code exploration 2.6k ★
- Qiaomu Markdown Proxy — Fetch any URL as clean Markdown via proxy services (r.jina.ai / defuddle.md) or built-in scripts 426 ★
README
Phantom
**Delegate everything to AI. Without sharing a single key.**
Phantom hands every AI tool a worthless `phm_` token. The local proxy injects the real key at the network layer. Full access. Zero exposure.
[](https://github.com/ashlrai/phantom-secrets/stargazers) [](https://github.com/ashlrai/phantom-secrets/actions/workflows/ci.yml) [](https://www.npmjs.com/package/phantom-secrets) [](LICENSE)
[**Quick start**](#quick-start) · [**Why Phantom?**](#why-phantom) · [**MCP setup**](#mcp-integration-claude-code-cursor-windsurf-codex) · [**Docs**](https://phm.dev/docs) · [**phm.dev**](https://phm.dev)
**▶ [Watch the 45-second demo](https://github.com/ashlrai/phantom-secrets/releases/download/v0.4.0/phantom-demo.mp4)** · **🛡 [Security model](SECURITY.md)** · **📋 [Threat model](THREAT_MODEL.md)** · **💬 [Discussions](https://github.com/ashlrai/phantom-secrets/discussions)**
Why Phantom?
AI coding agents read your `.env` files. Once a real API key enters an LLM's context window, it leaks — via prompt injection, session logs, malicious MCP servers, or training data. GitGuardian reports AI-assisted commits leak secrets at **2× the baseline rate**.
Every other secrets manager protects keys *at rest* and *in transit*. Phantom protects them **in context**:
- 🔒 **Real ke
Related Skills
Keyfence
Local proxy that keeps your API keys and secrets out of LLM requests. Works with Claude Code, Cursor, Codex an
1password Skill
A Claude Code skill for securing API keys with 1Password CLI. Stop hardcoding secrets where your AI tools can
AI Keyword Research Agent
AI Keyword Research Automation — give your AI coding assistant one job: find N real keyword opportunities for
Secure Agent
🔐 Egress inspection & secret-leak firewall for local AI agents — see what your agents send, catch secrets bef
Secretless AI
One command to keep secrets out of AI (LLMs). Works with Claude Code, Cursor, Copilot, Windsurf, and any AI co
Agent Secrets
Let an AI agent use your API keys and passwords without the plaintext ever entering its transcript. A plugin f
Related Agents
10x Tool Calls
Cursor and Windsurf meter usage by requests and tool calls rather than tokens, which means a finished or stall
Secret Purist
The paranoid sentinel of credential security. Use this agent to scan codebases and git history for leaked secr
Secret Guard
MUST be used whenever the user asks to scan for secrets, API keys, credentials, or tokens before a commit or i