ModsCode / Claude Code Mods / Ranking / secret-broker
secret-broker
Pops up when Claude needs an API key or token for a terminal command and injects it without Claude ever seeing it
What it does
- Draws a band above the prompt, a pane, the status line, toasts
- Adds /secrets
- Watches Bash, PowerShell calls and can refuse them
- Hooks prompt.compose, prompt.submit, session.start, turn.complete and 1 more
- Keeps its own state between turns
Good points
- No network calls
- Written in TypeScript
- Handles errors
Code to start from
A starter ModsCode writes from the drawing it read, and the mod's own lines that draw, where there are any.
Starter (register.tsx)
import type { Register } from 'claude-code'
// Drawn like secret-broker by cesarroger (pane, band, status, toast), as ModsCode read it from the mod's code:
// https://modscode.com/claude-mods/mods/cesarroger-secret-broker/
// Written by ModsCode from that reading, not copied from the mod: use it as you like.
// Each value below stands for one the mod works out at run time; put in your own.
export const register: Register = on => {
// the band above the prompt; what else goes there is drawn under it
on('ui.render', { component: 'AbovePrompt' }, async ($, e, next) => {
const { Box, Text, Button } = $.ui.resolve(e)
const line = '…'
const line2 = '…'
const line3 = '…'
return (
<Box flexDirection="column">
<Box flexDirection="row" borderStyle="round" borderColor="#ff5e1a" backgroundColor="#120804" paddingX={1} alignItems="center">
<Box flexDirection="column">
<Text color="#d9822b" bold>
{line}
</Text>
<Text color="#d9822b" bold>
{line2}
</Text>
<Text color="#d9822b" bold>
{line3}
</Text>
</Box>
<Box flexDirection="column" paddingX={1} flexGrow={1}>
<Text color="#d9822b" bold>
THE LOG HAS NOTICED.
</Text>
<Text color="#ffe9c7">
Claude just asked you to handle a key step yourself. The log can take it from here.
</Text>
</Box>
<Button variant="primary" hotkey="l" label="Feed the log" />
<Text>
{" "}
</Text>
<Button dimColor label="Dismiss" />
</Box>
{await next(e)}
</Box>
)
})
// the pane: open it with $.ui.open({ id: 'my-pane', title: "Secret needed" })
on('ui.render', { component: 'Pane', requestId: 'my-pane' }, async ($, e) => {
const { Box, Text, Input, Button } = $.ui.resolve(e)
const line = '…'
const line2 = '…'
const line3 = '…'
const logLine = '…'
const command = '…'
const name = '…'
const name2 = '…'
const name3 = '…'
const note = '…'
const missing = '…'
return (
<Box flexDirection="column" backgroundColor="#120804" paddingX={1}>
<Box flexDirection="row" alignItems="center">
<Box flexDirection="column">
<Text color="#d9822b" bold>
{line}
</Text>
<Text color="#d9822b" bold>
{line2}
</Text>
<Text color="#d9822b" bold>
{line3}
</Text>
</Box>
<Box flexDirection="column" paddingX={1}>
<Text color="#ff5e1a" bold>
{"▌ THE LOG REQUIRES "}
A SECRET
</Text>
<Text color="#d9822b" italic>
{logLine}
</Text>
<Text color="#ffe9c7" dimColor>
Claude never sees the value. It goes to this one command, then it is gone.
</Text>
</Box>
</Box>
<Box flexDirection="column" borderStyle="round" borderColor="#3b1f0e" paddingX={1}>
<Text color="#d9822b" bold>
the command, exactly as it will run
</Text>
<Text color="#ffe9c7" wrap="wrap">
{command}
</Text>
</Box>
<Box flexDirection="column" borderStyle="round" borderColor="#d9822b" paddingX={1}>
<Box flexDirection="column">
<Text color="#ff5e1a" bold>
{"◯ "}
{name}
</Text>
<Input label=" ▶ " placeholder="paste it here, press Enter. the log is watching." autoFocus submitLabel="feed" />
<Box flexDirection="row">
<Button>
From clipboard
</Button>
<Text>
{" "}
</Text>
<Button>
Use saved
</Button>
</Box>
</Box>
</Box>
<Box flexDirection="column" borderStyle="round" borderColor="#d9822b" paddingX={1}>
<Box flexDirection="column">
<Text color="#ff5e1a" bold>
{"◯ "}
{name2}
</Text>
<Input label=" ▶ " placeholder="paste it here, press Enter. the log is watching." autoFocus submitLabel="feed" />
<Box flexDirection="row">
<Button>
From clipboard
</Button>
<Text>
{" "}
</Text>
<Button>
Use saved
</Button>
</Box>
</Box>
</Box>
<Box flexDirection="column" borderStyle="round" borderColor="#d9822b" paddingX={1}>
<Box flexDirection="column">
<Text color="#ff5e1a" bold>
{"◯ "}
{name3}
</Text>
<Input label=" ▶ " placeholder="paste it here, press Enter. the log is watching." autoFocus submitLabel="feed" />
<Box flexDirection="row">
<Button>
From clipboard
</Button>
<Text>
{" "}
</Text>
<Button>
Use saved
</Button>
</Box>
</Box>
</Box>
<Text color="#ff5e1a" bold>
{"! "}
{note}
</Text>
<Button plain dimColor label="◉ the log remembers these for this session" />
<Box flexDirection="row" paddingY={1} alignItems="center">
<Text color="#d9822b" dimColor>
{"the log waits for: "}
{missing}
</Text>
<Text>
{" "}
</Text>
<Button role="dismiss" hotkey="n">
Decline
</Button>
</Box>
</Box>
)
})
on('session.start', async ($, e, next) => {
const names = '…'
await $.ui.status(`secret-broker: waiting for ${names}`)
await $.ui.toast(`secret-broker: a command needs a secret; widen the window to see the pane`)
await $.ui.toast(`secret-broker reloaded and dropped the pending secret request; ask Claude to run the command again`)
return next(e)
})
}
The mod's own code
Its licence text was not found at the commit read, so only the places in the source are linked.
How to build this: Pane (panel), Deny a tool call
What its code calls
runs programswrites filesenv varsdrives Claudetool callsremembers
What its code shows
Read from the source at commit 15114133b3cd. The first group decides whether a mod is listed; the rest is for you to weigh. A later commit is not read until the next crawl.
| Decides the listing: code you can check | |
|---|---|
| Entry read | Every module hooks/hooks.json names was read.hooks/register.tsx |
| Parses | Every file parses as TypeScript or JavaScript.1 files parsed |
| All its code is in the mod | Every import is a file of the mod or the engine's own module; no packages, no require.all its code is in the mod |
| Readable | No minified lines, no eval or new Function, no import of a computed path, no encoded blobs.no minified code, no eval, no encoded blobs |
| Calls in the open | Network and programs are reached as $.http.fetch and $.process.run in place, never passed around.every call outside goes through $ in the open |
| For you to weigh before installing | |
| Where it draws | The terminal, the desktop app, both, or nothing (hooks only: a guard or a prompt rewriter), as its code says. Shown, never a reason to leave a mod out.draws in the terminal and the desktop app, the same in both |
| Install line | Whether its repository's own .claude-plugin/marketplace.json lists it, so it installs from that marketplace with the lines on its page.its repository's .claude-plugin/marketplace.json does not list it: no marketplace line to give; the page shows how to try the commit read |
| Programs on Windows | Whether every program it starts through $.process exists on Windows (tail, date, open, osascript, /usr/… do not).hooks/register.tsx:239 /bin/sh (not on Windows); hooks/register.tsx:261 /bin/rm (not on Windows) |
| Network | Whether every fetch names its https host in the code.no network |
| Programs | Whether every program it starts is named in the code and is not a shell, an interpreter or a network tool.hooks/register.tsx:155 a program named at run time; hooks/register.tsx:239 /bin/sh (a shell or interpreter); hooks/register.tsx:272 cmd.exe (a shell or interpreter) |
| Reads and sends | Whether it both reads something of yours (files, environment variables, the transcript, settings) and reaches outside (the network, an MCP server, another session, telemetry).reads environment variables, files, but reaches nothing outside |
| Keys in the source | Whether the source holds what looks like an API key or a private key.no keys in the source |
| Licence | An open licence (MIT, Apache-2.0, BSD, ISC, Unlicense, 0BSD, CC0) with its text lets ModsCode show its code; otherwise the code is linked.no licence |
| Settings hooks | Hooks declared in hooks/hooks.json or plugin.json beside the module: a command (a shell when it has no args), an HTTP request, an MCP tool or a model prompt at an event. They run outside $.no settings hooks: its function hooks alone |
| Servers it ships | MCP servers (a program, or a URL; a headersHelper is a shell command; a .mcpb bundle is unpacked at run time), LSP servers, monitors (a shell command for the whole session) and bin/ (on the PATH of the Bash tool).ships no MCP or LSP server, no monitor, no bin/ |
| Skills, commands, agents | What its Markdown declares beyond text: allowed-tools granted for the turn, hooks added when a skill is invoked, a command run before Claude reads the skill.no skills, commands, agents or workflows |
| Tools and MCP | Whether every tool it calls through $.tool.call and $.mcp.call is named in the code, and none is a shell (Bash through the tool runs a shell without $.process).calls no tool, MCP server or command |
| Asks of the model | Completions it runs ($.model.complete, fork, classify), subagents it spawns, prompts it submits as you, and the tools, commands and agents it adds.prompt.submit (as the person), adds command secrets |
| Events it hooks | By what a hook there can do: gates (refuse a tool call, a prompt, a setting, another plugin), shapes (what the model reads: the system prompt, tool descriptions, each request), reads (your input, the events of the settings hooks, every event with *), and the rest.gates: command.run (secrets), prompt.submit, tool.call · shapes: prompt.compose, tool.describe (Bash, PowerShell) · also: session.start, turn.complete, ui.render (AbovePrompt, Pane), ui.close |
| Reads, by name | The environment variables and files it names, and whether it reads the transcript, settings.json, the prompt box or the mouse selection.env: OS, USERPROFILE, HOME; files: …/…, a path computed at run time, its own folder/assets/log.png |
| Writes, by name | The files and environment variables it names, and whether it changes settings, the prompt box, the clipboard, the conversation (a row the model reads) or another session.files: …/… |
This is a reading of the code text, not a security review: it does not run the mod, and it cannot see what a program the mod starts does. The check before installing is yours. How mods are chosen
Install it
Check it yourself before you install it. Mods run unsandboxed, with your permissions, and ModsCode does not vouch for what this code does. Read its code (or run claude plugin validate . in its folder), weigh what it reaches, and install the commit you read.
Its repository's .claude-plugin/marketplace.json does not list it, so there is no marketplace line to give.
Try the commit ModsCode read
No marketplace needed. In a terminal, clone the repository, check out the commit read, validate the mod, and load it for one session:
git clone https://github.com/cesarroger/secret-brokergit -C secret-broker checkout 15114133b3cd4b74f1d7628fd6611e4206147b40claude plugin validate secret-brokerclaude --plugin-dir secret-brokerThe validate line lists the events the mod hooks and what it asks Claude Code to do, without running it. The last line loads the mod for this session only and writes nothing to your settings. If the author has rewritten history, the commit may no longer exist.
Ask Claude about it
With the ModsCode connector added, Claude can read this mod's code and what it reaches, and build on them. Ask it like this:
Read the ModsCode mod "cesarroger-secret-broker" with its code and make me one like itSearch them from Claude: the MCP connector
Similar mods
- code-modernizationAnthropic★ 37,653
- explain-asSumit Paul★ 20
- agent-discoverkeshrath★ 7
- spending-effort-with-jevYaxin Luo★ 6
- superpowers-trackernalyk★ 2
- a2a-modAliasgar Khimani★ 1
Badge for your README
If this is your mod, paste this into your README. It links to this page.
[](https://modscode.com/claude-mods/mods/cesarroger-secret-broker/)