Skip to main content
Glama
yulinlina

ctxbleach

by yulinlina

ctxbleach

Local CLI and MCP server that bleaches secrets from logs, files, and diffs before AI agents see them.

License Language Status Python License MCP


🎯 Why?

Trending agent-context projects focus on giving agents more code and memory, while guardrail tools mostly block commands. Developers still need a tiny local middleware that transforms raw logs, env files, and command output into safe, token-budgeted context before it reaches an LLM. Existing secret scanners are CI-oriented and do not provide interactive redaction placeholders, MCP tools, or context budgeting.

Target audience: Developers and platform engineers using Claude Code, Cursor, Codex, or MCP-enabled agents who need to share logs, .env files, stack traces, and CI output without leaking credentials.

Related MCP server: sieve-map

✨ Features

  • Regex-based redaction for AWS keys, GitHub/Slack tokens, JWTs, bearer headers, URL passwords, private keys, and generic secret assignments

  • Stable placeholders and masked scan output so no secret values are echoed back

  • Token-budgeted truncation with head or tail preservation for large logs

  • CLI commands for scan, redact, and MCP stdio serving

  • Zero-dependency Python implementation that can be dropped into agent workflows

🚀 Quick Start

# Install
pip install ctxbleach

# Run
ctxbleach --help

📦 Installation

From Source

git clone https://github.com/YOUR_USERNAME/ctxbleach.git
cd ctxbleach
# Create virtual environment
python -m venv .venv
source .venv/bin/activate  # Windows: .venv\Scripts\activate

# Install in development mode
pip install -e ".[dev]"

# Run tests
pytest -v

🎬 Demo

The GIF above was recorded using Charm VHS:

vhs < demo.tape

📖 Usage

# Show help
ctxbleach --help

# Common usage examples
ctxbleach --example

🏗️ Architecture

graph LR
    A[Input] --> B[Core Engine]
    B --> C[Output]
    B --> D[Plugins]
    D --> E[Extensions]

🤝 Contributing

Contributions are welcome! Please:

  1. Fork the repo

  2. Create a feature branch (git checkout -b feature/amazing-feature)

  3. Commit your changes (git commit -m 'Add amazing feature')

  4. Push to the branch (git push origin feature/amazing-feature)

  5. Open a Pull Request

📄 License

MIT © 2026 — See LICENSE for details.


If this project helped you, please ⭐ star it!

Made with ❤️ and AI

A
license - permissive license
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    C
    maintenance
    Local MCP server for macOS that scans AI coding tool history (Claude Code, Cursor, Copilot, Cline, Codex, Gemini CLI) for leaked secrets. Finds API keys in chat transcripts, redacts with sieve:// placeholders, and runs commands with Keychain-injected secrets - no plaintext values ever returned.
    9
    1
    MIT
  • A
    license
    -
    quality
    D
    maintenance
    Secret management MCP server for AI coding agents that prevents secrets from entering the LLM context window by returning metadata only and using side-channel injection. Integrates with Bitwarden and offers hooks for auto-capture and leak prevention.
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    A local-first redacting MCP gateway that strips secrets from file reads and shell output before they reach an AI coding agent's context, the command still runs with the real credential, but the model never sees it.
    2
    18
    MIT

View all related MCP servers

Related MCP Connectors

  • User-owned memory for AI agents, Copilot, Claude, IDEs, CLIs, and chat apps over remote MCP.

  • Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.

  • Artifact store for AI agents. Hosted OAuth at mcp.artifacta.io/mcp; local stdio via npm/PyPI.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/yulinlina/ctxbleach'

If you have feedback or need assistance with the MCP directory API, please join our Discord server