hn.today

Show HN: Let agent read files with secrets while redacting values for LLM contex

github.com4 points1 comments

ContextVeil is a small, local tool that lets coding agents read environment variables, .env files, config files and command output while redacting chosen secret values before those texts reach a language model. During a guided one-time setup it suggests likely secret sources (env names, .env entries, JSON fields, Java properties, .npmrc keys, and maintained agent credential stores like Claude Code, Codex, GitHub Copilot, OpenCode) and records where values live - not the values themselves. At runtime ContextVeil reads current values and performs exact, deterministic text replacements (e.g., GITHUB_TOKEN=ghp_secret_example -> GITHUB_TOKEN=) so commands and file reads still run and most output remains useful. No daemon, no network, no hosted service; installs and runs locally.

Key specifics: matching is literal and case-sensitive, guided discovery uses a Known Source vocabulary (tokens, password, key suffix rules, credential-bearing URLs) and skips common literal values to reduce false positives. Setup shows masked previews, users pick what to protect, and ContextVeil supports on-demand re-run and a doctor check; it stores source locations so key rotation works automatically. It intentionally avoids heuristic secret detection or scanning arbitrary keys, focusing on predictable, reproducible redaction on supported agent integration paths.

Read on github.com1 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.