Add ctxguard: hook-enforced context sanitization
Keeps credentials, company names, personal names and PII out of the model's context. Enforcement lives in Claude Code hooks rather than in instructions to the agent: a skill alone cannot protect anything, because by the time the agent reads a rule the surrounding context has already been sent. Credentials are removed irreversibly and marked. Entities from a user-supplied dictionary become stable aliases, rewritten back to real values on their way to disk and to the shell, so code and commands referring to them still work. Published from a clean tree; development history is not included.
This commit is contained in:
+11
@@ -0,0 +1,11 @@
|
||||
# ctxguard runtime state lives in ~/.claude/ctx-guard/ and must NEVER be committed.
|
||||
# These entries are a second line of defence in case anything is copied in by hand.
|
||||
**/entities.json
|
||||
**/policy.json
|
||||
**/index.json
|
||||
**/audit.jsonl
|
||||
**/.ctxguard-cache/
|
||||
*.local.md
|
||||
__pycache__/
|
||||
*.pyc
|
||||
.venv/
|
||||
Reference in New Issue
Block a user