cd /news/ai-tools/is-anyone-else-tired-of-claude-code-… · home topics ai-tools article
[ARTICLE · art-90170] src=dev.to ↗ pub= topic=ai-tools verified=true sentiment=· neutral

Is Anyone Else Tired of Claude Code Leaking Their Secrets?

A developer has released claude-code-guardrails, an open-source set of user-level hooks for Claude Code that intercepts Bash tool calls before execution to deny commands that might expose secrets like .env files or private keys. The tool also includes a session-heartbeat hook that acts as a canary for context degradation, injecting a timestamp and turn counter into prompts to signal when a session may be drifting. The project is available on GitHub under an MIT license.

read2 min views1 publishedAug 10, 2026

If you use Claude Code a lot, you've probably seen this:

“Let me inspect the configuration.”

And then:

cat .env

Great.

Your database password or API key is now sitting in the conversation.

Claude apologizes.

You rotate the key.

A few sessions later:

grep SOMETHING ~/.pgpass

Same story.

After doing this enough times, I got tired of relying on:

“Claude, please remember not to print secrets.”

So I built claude-code-guardrails.

It's a small open-source set of user-level hooks for Claude Code.

The main hook, deny-secrets

, intercepts Bash tool calls before execution.

If Claude tries something like:

cat .env

or attempts to expose .pgpass

, private keys, credential files, environment variables, or other secret-looking data, the hook can deny the command before Bash runs it.

Conceptually:

Claude Code
    ↓
Bash command
    ↓
PreToolUse hook
    ↓
secret?
    ↓
NOPE.

It's not a security sandbox and it's definitely not 100% protection.

But it stops a surprisingly large class of accidental:

“Oops, I shouldn't have printed that.”

The second hook is session-heartbeat

.

Long Claude Code sessions can gradually lose earlier instructions after context compaction.

The dangerous part is that Claude doesn't suddenly stop working.

It keeps answering.

It keeps sounding confident.

It keeps writing code.

Only the decisions start getting... weird.

So the heartbeat acts as a canary for context degradation.

It injects a timestamp and turn counter into every prompt. If Claude suddenly stops returning the expected marker, that's an early signal that the session may be starting to drift.

Maybe it's time to kill the session and start a fresh one — before Claude starts confidently producing nonsense.

Is it proof that the context is healthy?

No.

It's a canary.

That's the point.

This is not intended to replace proper secret managers, filesystem permissions, gitleaks, trufflehog, or real sandboxing.

It's just a pragmatic extra layer for problems I kept encountering myself.

MIT licensed. Download it, modify it, add your own rules, break it, fix it, send a PR.

Full documentation and installation instructions are on GitHub:

https://github.com/ineron/claude-code-guardrails

Sometimes AI coding agents don't need another prompt.

They need a fence.

And maybe a canary.

── more in #ai-tools 4 stories · sorted by recency
── more on @claude code 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/is-anyone-else-tired…] indexed:0 read:2min 2026-08-10 ·