Synthetic helper-dispatch counter

Keep recognized credentials out of supported Claude Code model inputs. Redacton scans prompt text/context, Read text, and Bash stdout/stderr, replacing detected credentials with placeholders. Recognized private keys block the entire event.
Redacton targets macOS, Linux and Windows CLI installations with one shared Mod/helper implementation. The published verified release remains macOS ARM64, Claude Code 2.1.294, Node 22.16.0. Portable packages, Unix/PowerShell candidate installers and CI are development paths until each platform's actual host is qualified. See the target and verified matrix.
Powered by Redact Secret, a deterministic Rust detection engine with native and WebAssembly runtimes. Scanning runs locally, without sending content to a detection service. Explore Redact Secret for local redaction in your own apps, and star the project to support it.
This command installs the existing verified macOS Apple Silicon release, not a universal cross-platform package.
Have Claude Code and Node.js 22 installed on macOS Apple Silicon. The verified combination is Claude Code 2.1.294 and Node 22.16.0; other platforms, host versions and Desktop have not been qualified. Required follow-on support targets macOS x64, Linux x64/ARM64 and Windows x64/WSL; those targets are not supported by this installer.
curl -fsSL https://raw.githubusercontent.com/milocosmopolitan/redacton/main/scripts/install.sh | bash
claude --plugin-dir "$HOME/.local/share/redacton/current"
The installer downloads the published package, verifies its pinned checksum, and installs it without npm or a build step. You can inspect the installer or download packages from Releases.
The --plugin-dir option loads Redacton for that Claude Code launch. Use the same launch command for future sessions.
Linux, Intel Mac, native Windows and WSL users should follow the candidate installation and qualification guidance. Native Windows and WSL are separate environments; Desktop is a separate host surface. A helper/installer success does not establish protection of model inputs.
After launch, run /redacton and confirm Protect ready before your first task.
New, resumed and branched CLI sessions start with protection requested ON. Readiness is shown separately as loading, ready or unavailable.
| Command | Effect |
|---|---|
/redacton | Request protection for subsequent supported operations. |
/redactoff | Bypass scans for subsequent operations in this session. |
/redact:status | Show cached readiness, coverage, rules and recent outcomes. |
/redact:config, /redact:add-rule, /redact:remove-rule | Manage custom formats through local forms. |
Commands take no arguments. Never paste secrets, patterns or test text into slash-command arguments; the host can store them before local rejection. Running operations keep the policy they started with. OFF displays a prompt-area warning: ⚠ Redacton OFF — credential protection disabled.
Custom rules use guided token formats or assignment names. Validate, inspect synthetic sample outcomes, then explicitly Apply session; personal/project saving and portable import/export are separate actions. Confirm the form has keyboard focus before typing, and close it before ordinary chat. Never enter actual credential values as rule definitions. See configuration and scope.
Protection depends on the functioning host and outer guard. Unsupported selected results and scanner failures withhold content under those guard conditions; a host that bypasses all guards can expose it.
Original prompts and tool arguments can remain in host storage. Encoded credentials can be missed, and zero findings does not mean safe content. MCP, other tools, tool arguments, binary/image/audio content, PII and existing history are outside coverage. Withholding output does not undo a tool's effects.
See compatibility and evidence and the threat model for exact limits. For vulnerabilities, use private security reporting; public issues are not confidential.
Contributing · Security policy · Code of conduct · Dependency notices · MIT license
hooks/register.js 11 lines1let calls = 0
2let configured = false
3export function register(on) {
4 on('process.run', ($, e, next) => { calls += 1;try{const request=JSON.parse(e.init?.stdin??'{}');if(request.operation==='sanitize')configured=request.config?.rules?.some(rule=>rule.kind==='token' && rule.id==='synthetic.rule' && rule.prefix==='syntheticcred_' && rule.run?.length===16)??false;}catch{} return next(e) })
5 on('session.start', async ($, e, next) => {
6 await $.command.register({ name: 'helpercount', description: 'Return fixed helper dispatch count' })
7 return next(e)
8 })
9 on('command.run', { command: 'helpercount' }, () => ({ text: 'HELPER_CALLS_' + calls + ' CONFIG_EXPECTED_' + configured }))
10}
11