harqian

Llmscrub — AI skill for Claude Code

AI community

Sweep LLM agent logs (Claude Code, Codex) for leaked secrets and redact them in place.

How to install Llmscrub

This entry records only its repository, not the path inside it, so there is no exact command to give. Open harqian/llmscrub and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Llmscrub does

Sweep LLM agent logs (Claude Code, Codex) for leaked secrets and redact them in place.

Alternatives in AI

  • Cl4r1t4s — LEAKED SYSTEM PROMPTS FOR CHATGPT, CLAUDE, GEMINI, GROK, PERPLEXITY, CURSOR, LOVABLE, REPLIT, AND MORE 47.2k ★
  • Skills Manage — Desktop app to manage AI coding agent skills across Claude Code, Cursor, Gemini CLI, Codex, and 20+ platforms 2.2k ★
  • Internal Safety Collapse — We built an adversarial codespace setup 1.2k ★

README

llmscrub

![demo](demo/demo.gif?v=2)

Sweep LLM agent logs (Claude Code, Codex) for leaked secrets and redact them in place.

LLM agents accumulate surprising amounts of secret material in their logs: API keys pasted into prompts, `.env` files read into tool results, `curl -H "Authorization: Bearer ..."` commands, Supabase access tokens baked into MCP config, GCP service-account private keys from `cat credentials.json`, 1Password outputs that got piped to stdout. `llmscrub` stacks several detectors to find them and redacts in place with backups.

What it detects

Four layers:

  1. trufflehog — ~700 known-format detectors, many verified against live APIs
  2. gitleaks — regex-heavy ruleset, complementary to trufflehog (catches things like curl -u user:pass auth)
  3. Built-in extras that trufflehog/gitleaks miss:
    • PEM private-key blocks (including embedded in JSONL as \n-escaped strings)
    • Environment-variable assignments with sensitive key names (API_KEY=..., DATABASE_URL=...)
    • Authorization: Bearer and Basic headers
    • URL-embedded passwords (scheme://user:pass@host)
    • Aggressive KEY=VAL redaction when the file context suggests a .env write
  4. 1Password sweep (opt-in via --op) — pulls every concealed field from your signed-in 1Password vault and does exact-string matching against the logs. Catches values that are real secrets but don't look like one structurally (homegrown tokens, service passwords, anything the pattern detectors can't recognize). Filtered by entropy so short dictionary-word entries don't cause false positives.

Install

brew install harqian/tap/llmscrub

Usage

llmscrub scan                  # report what's there (read-only)
llmscrub scan -v               # also list affected files

llmscrub redact --dry-run      # preview redactions
llmscrub redact                # re