Add ctxguard: hook-enforced context sanitization

Keeps credentials, company names, personal names and PII out of the model's
context. Enforcement lives in Claude Code hooks rather than in instructions to
the agent: a skill alone cannot protect anything, because by the time the agent
reads a rule the surrounding context has already been sent.

Credentials are removed irreversibly and marked. Entities from a user-supplied
dictionary become stable aliases, rewritten back to real values on their way to
disk and to the shell, so code and commands referring to them still work.

Published from a clean tree; development history is not included.
This commit is contained in:
dev
2026-09-16 11:33:09 +03:00
commit 278ecca018
34 changed files with 5315 additions and 0 deletions
+17
View File
@@ -0,0 +1,17 @@
{
"$schema": "https://anthropic.com/claude-code/marketplace.schema.json",
"name": "ctx-tools",
"description": "Claude Code plugins for keeping sensitive data out of the model's context",
"owner": {
"name": "A.Shakhmatov",
"email": "dev@shakhmatov.com"
},
"plugins": [
{
"name": "ctxguard",
"source": "./plugins/ctxguard",
"description": "Sanitizes the agent's context: blocks credentials and replaces company names, people and PII with stable reversible aliases before anything reaches the model",
"version": "1.0.4"
}
]
}