Llmscrub — AI skill for Claude Code
Sweep LLM agent logs (Claude Code, Codex) for leaked secrets and redact them in place.
How to install Llmscrub
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open harqian/llmscrub and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Llmscrub does
Sweep LLM agent logs (Claude Code, Codex) for leaked secrets and redact them in place.
Alternatives in AI
- Cl4r1t4s — LEAKED SYSTEM PROMPTS FOR CHATGPT, CLAUDE, GEMINI, GROK, PERPLEXITY, CURSOR, LOVABLE, REPLIT, AND MORE 47.2k ★
- Skills Manage — Desktop app to manage AI coding agent skills across Claude Code, Cursor, Gemini CLI, Codex, and 20+ platforms 2.2k ★
- Internal Safety Collapse — We built an adversarial codespace setup 1.2k ★
README
llmscrub

Sweep LLM agent logs (Claude Code, Codex) for leaked secrets and redact them in place.
LLM agents accumulate surprising amounts of secret material in their logs: API keys pasted into prompts, `.env` files read into tool results, `curl -H "Authorization: Bearer ..."` commands, Supabase access tokens baked into MCP config, GCP service-account private keys from `cat credentials.json`, 1Password outputs that got piped to stdout. `llmscrub` stacks several detectors to find them and redacts in place with backups.
What it detects
Four layers:
- trufflehog — ~700 known-format detectors, many verified against live APIs
- gitleaks — regex-heavy ruleset, complementary to trufflehog (catches things like
curl -u user:passauth) - Built-in extras that trufflehog/gitleaks miss:
- PEM private-key blocks (including embedded in JSONL as
\n-escaped strings) - Environment-variable assignments with sensitive key names (
API_KEY=...,DATABASE_URL=...) Authorization: BearerandBasicheaders- URL-embedded passwords (
scheme://user:pass@host) - Aggressive
KEY=VALredaction when the file context suggests a.envwrite
- PEM private-key blocks (including embedded in JSONL as
- 1Password sweep (opt-in via
--op) — pulls every concealed field from your signed-in 1Password vault and does exact-string matching against the logs. Catches values that are real secrets but don't look like one structurally (homegrown tokens, service passwords, anything the pattern detectors can't recognize). Filtered by entropy so short dictionary-word entries don't cause false positives.
Install
brew install harqian/tap/llmscrub
Usage
llmscrub scan # report what's there (read-only)
llmscrub scan -v # also list affected files
llmscrub redact --dry-run # preview redactions
llmscrub redact # re
Related Skills
Agent Sweep
Find and redact secrets in AI coding agent histories (Claude Code, and more).
Neuralyzer
Your AI agent saw your API keys, and saved them in plaintext forever. Scan, redact and rotate secrets in Claud
Claude Code Redact
Claude Code mod that redacts secrets and PII before the model reads them, stores placeholders in the conversat
Foci
openclaw-like ai agent platform. Written in go for speed and memory-efficiency. Supports claude code as backen
Residoo
Find secrets your AI coding agent leaked to disk. Free, MIT, zero deps, zero network calls. Beat TruffleHog an
Agentleak
Find secrets you already leaked into AI chat sessions — offline, local-first.
Related Agents
Secret Purist
The paranoid sentinel of credential security. Use this agent to scan codebases and git history for leaked secr
Opensource Sanitizer
Pre-public-push safety net. Scans a diff or working tree for leaked secrets, PII, internal references, interna
Svelte Recurrence Sweep
Given a defect just found or fixed in a SvelteKit app (apps/moderator, apps/auth, apps/creator-studio), finds