Scrub Transcripts — Development skill for Claude Code
Claude Code skill that finds passwords, API keys and tokens in Claude's local session logs and redacts them, without copying them into a new transcript.
How to install Scrub Transcripts
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open maccydee/scrub-transcripts and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Scrub Transcripts does
Claude Code skill that finds passwords, API keys and tokens in Claude's local session logs and redacts them, without copying them into a new transcript.
Alternatives in Development
- Sanitize — Detect and redact PII from text files — 15 categories (SSNs, credit cards, API keys, etc.), zero dependencies 3.1k ★
- Dexscreener Unofficial CLI + MCP + Skills — You are a token scanning specialist using the Dexscreener Unofficial CLI (not affiliated with or endorsed by D 213 ★
- Agentrules Architect — AGENTS.md/CLAUDE.md generator and ExecPlan harness for Codex, Claude Code, Cursor, Antigravity, OpenCode and o 114 ★
README
scrub-transcripts
[](https://docs.claude.com/en/docs/claude-code/skills) [](LICENSE) [](scripts/scrub.py) [](https://github.com/maccydee/scrub-transcripts/actions/workflows/tests.yml)
A Claude Code skill that finds passwords, API keys and tokens sitting in Claude's local session logs and replaces them with `[REDACTED:]`.
Claude Code writes every session to disk as plain JSONL. If you paste a token into a prompt, or Claude runs `cat .env`, that value stays in `~/.claude/projects` and in your prompt history until you delete it.
scrub-transcripts: Dry run, nothing changed
Scanned 3 files in 0.0s. Found 8 secrets in 3 files.
WHAT WAS FOUND
┌──────────────────────────┬───────┬───────┬────────────┬──────────────────────┐
│ Secret │ Found │ Files │ Confidence │ Where it came from │
├──────────────────────────┼───────┼───────┼────────────┼──────────────────────┤
│ github_token (ghp_…) │ 2 │ 2 │ certain │ you 2 │
│ telegram_bot_token │ 1 │ 1 │ certain │ tool output 1 │
│ anthropic_key (sk-ant-…) │ 1 │ 1 │ certain │ tool output 1 │
│ url_password │ 1 │ 1 │ certain │ Claude 1 │
│ password │ 3 │ 3 │ likely │ you 2, tool output 1 │
└──────────────────────────┴───────┴───────┴────────────┴──────────────────────┘
NEXT STEPS
1. Skim the table. "certain" rows are real credentials. "likely" rows are labelled values, so a few may be harmless (redacting those costs nothing).
2. Redact them: python3 ~/.claude/skills/scrub-transcripts/scripts/scrub.py --root demo-home --apply
3. Rotate these, because redacting the logs does
Related Skills
Spillage
Find the API keys your coding agents spilled into their logs. Claude Code, Codex, Gemini CLI, Cline and more.
Axguard Crypto
Crypto footguns — hard-coded keys/IVs, MD5 passwords, Math.random tokens, TLS verify off. Usage: /axguard-cryp
Bashrc Credential Guard
Always check ~/.bashrc for credentials, API keys, passwords, and configuration values before asking user
Transcript
Generate a JSON object with keys transcripts, screen_content, and speakers for the following three tasks.
Heeler Secrets Scan
Run Heeler secret scanning for a repository or staged changes. Use when comitting code or the user asks to det
Offline Telemetry Script
Offline analyzer for Claude Code session transcripts (~/.claude/projects/.jsonl). Pure-stdlib Python, no API c
Related Agents
Secret Purist
The paranoid sentinel of credential security. Use this agent to scan codebases and git history for leaked secr
Transcript Inspector
Specialist agent for diagnosing stop hook failures by reading Claude Code session transcripts. Use when the st
Transcript Summarizer
Expert at reading Claude Code session transcripts and extracting structured summaries with decisions, errors,