Mask secrets and PII before Claude Code or Codex sends them
Summary
A developer built Hamza, a tool that inspects outbound requests from AI coding agents like Claude Code and Codex to mask secrets and PII before they leave your machine.
Similar Articles
I tricked Claude into leaking your deepest, darkest secrets
A security researcher demonstrates a method to trick Claude AI into exfiltrating user personal data from its memory system by encoding data in web fetch URLs, exploiting the combination of memory retrieval and web browsing capabilities.
How I tricked Claude into leaking your deepest, darkest secrets
A security researcher discovered a vulnerability in Claude's web_fetch tool that allowed data exfiltration by chaining through nested links, compromising user privacy. Anthropic has since fixed the issue.
Breaking Claude Code Opus 5 Auto Mode
A researcher discovered an attack that bypasses Claude Code's auto mode with 80% success, exposing risks in AI safety mechanisms and advocating for sandboxing.
If you're new to coding agents: they keep a diary, and your API keys are in it
Coding agents like Claude Code, Cursor, and Codex save session logs locally, potentially exposing sensitive data like API keys and environment variables. A developer named Ishan created an offline tool to scan and redact secrets from these logs, addressing a common security blind spot.
Secret Claude tracker shocks users after Anthropic’s anti-surveillance stance
Anthropic secretly embedded a hidden tracker in Claude Code to monitor Chinese users, using prompt steganography, contradicting its anti-surveillance stance and sparking user trust concerns.