Loading…
Stops an agent reading, printing, or committing credential files, and escalates any command that would rotate a secret.
For: Platform and security engineers letting agents work in credentialed repos
Blocks reads of .env, key material, and cloud credential files.
Blocks shell commands that would print an environment secret to stdout or a log.
Escalates any command that would rotate or revoke a secret so two approvers sign off.
# Claude Code Secrets & Credentials Guard
# Fork: extend the protected path list with your own credential locations.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: claude-code-secrets-guard
surface: claude_code
standards: [SOC2-CC6.1, ISO27001-A.8.24]
defaults:
mode: shadow
emit_dossier: true
fail_closed: true
protected_paths:
- ".env"
- ".env.*"
- "**/*.pem"
- "**/*.key"
- "~/.aws/credentials"
- "~/.ssh/**"
rules:
- name: credential_file_read_block
when: "tool in ['Read', 'Bash']"
decision: |
BLOCK IF path matches any protected_paths
ALLOW OTHERWISE
reason_code: credential_file_access_blocked
- name: secret_echo_guard
when: "tool == 'Bash'"
decision: |
BLOCK IF command matches '(echo|printenv|env)\b.*(SECRET|TOKEN|PASSWORD|API_KEY)'
ALLOW OTHERWISE
reason_code: secret_would_be_printed
- name: rotation_escalation
when: "tool == 'Bash'"
decision: |
ESCALATE IF command matches '(rotate|revoke).*(key|secret|token)'
ALLOW OTHERWISE
reason_code: secret_rotation_requires_two_approvers
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.