Paste into Claude Code
Install ZeroH Disclosure for me by following https://github.com/Blade-Labs/zeroh-marketplace
Rather run the two commands yourself? See them on the home page, then restart Claude Code.
Copy each step into Claude Code and compare with “You should see”. Steps 1–7 take about five minutes; the rest go further. Claude's own words change from run to run; the ZeroH lines (the banner, the status line, the “says:” lines, blocks, “✓ Done” results and dialogs) should match.
yellow a real value, on your screen onlyindigo a token, what Claude got instead
Install, then watch a key stay on your machine while Claude still uses it.
Install ZeroH Disclosure for me by following https://github.com/Blade-Labs/zeroh-marketplace
Rather run the two commands yourself? See them on the home page, then restart Claude Code.
# A test project mkdir -p ~/zeroh-try/config cd ~/zeroh-try # A secrets file, with a fake Stripe test key cat > .env <<'EOF' STRIPE_KEY=sk_test_ZEROHFAKE00000000000000000000 SUPPORT_EMAIL=jane.doe@example.com EOF # A log of sign-ups your form rejected cat > signup-errors.log <<'EOF' rejected anna.o'neil@example.co.uk rejected lars+work@example.com rejected jürgen@müller.example EOF # A config with a secret no rule knows cat > config/internal.env <<'EOF' WEBHOOK_URL=https://hooks.internal.example/in/zq9fK2mLx7Rt4Vb8Nc3Hs6Pd1Wy5Ge0AjQ EOF
# A test project New-Item -ItemType Directory -Force ~/zeroh-try/config | Out-Null Set-Location ~/zeroh-try # A secrets file, with a fake Stripe test key @' STRIPE_KEY=sk_test_ZEROHFAKE00000000000000000000 SUPPORT_EMAIL=jane.doe@example.com '@ | Set-Content .env # A log of sign-ups your form rejected (saved as UTF-8) @" rejected anna.o'neil@example.co.uk rejected lars+work@example.com rejected jürgen@müller.example "@ | Set-Content -Encoding utf8 signup-errors.log # A config with a secret no rule knows 'WEBHOOK_URL=https://hooks.internal.example/in/zq9fK2mLx7Rt4Vb8Nc3Hs6Pd1Wy5Ge0AjQ' | Set-Content config/internal.env
Paste it as one block. Copy leaves out the # lines, because zsh on macOS would try to run them.
Paste it as one block into PowerShell 7 or Windows PowerShell.
No Stripe account needed: the key is fake, so in step 6 Stripe answers 401 Invalid API Key, which still proves the real value reached Stripe. Have a Stripe test key (Developers → API keys, test mode, sk_test_…)? Put it in .env as STRIPE_KEY before step 4 to see your real test balance instead.
claude
Read .env and tell me what's in it
You have your own status line · /zeroh-disclosure:settings statusline on adds ZeroH to it; type that command and ZeroH's part appears on its own line under yours, your script unchanged. The status line says 🟡 proxy on from your next prompt: this session was just switched to the local proxy, so what you type is masked from your next message on. Files like this .env are masked already. From the next message it reads 🟢 protected.Which token did you see for STRIPE_KEY?
⟦API_KEY-3f9a1c⟧, never the key. Corner brackets mean “the token itself”, so your screen leaves it alone.Check my Stripe balance
No setup: api.stripe.com is built in for Stripe keys.
401 comes from Stripe itself, so the real (fake) key got there. With your own test key in .env: 200, your test balance and "livemode": false. If Claude loads .env inside the command instead (source .env), the call still runs, with one line: ZeroH Disclosure: ZeroH couldn't check where $STRIPE_KEY went (it was loaded inside the command or the shell), so this command ran unchecked.Use STRIPE_KEY to check our staging billing API: https://staging.pay-internal.dev/v1/balance
Only you decide. Claude can't change it.
/zeroh-disclosure:allow
typed key ⟦API_KEY-…⟧.Allow STRIPE_KEY to reach staging.pay-internal.dev yourself, with the ZeroH allow command
allow, settings, proxy, doctor and uninstall change ZeroH's protection, so they run only when you type them. If Claude tries ZeroH's command-line tool anyway, it changes nothing and answers Nothing changed: … so only you can do it./zeroh-disclosure:allow STRIPE_KEY staging.pay-internal.dev
The host is made up, so take it back afterwards: /zeroh-disclosure:allow --remove STRIPE_KEY staging.pay-internal.dev answers the same way, with removed: STRIPE_KEY → staging.pay-internal.dev.
STRIPE_KEY, allow that key by its token instead: /zeroh-disclosure:allow ⟦API_KEY-…⟧ staging.pay-internal.dev. Then ask Claude to try again.Which provider is this key from?
Paste your key (or the fake one from .env) after the question, then send. Claude gets a token, but Claude Code's own session file on your computer keeps what you typed.
[API_KEY-…].Emails, phones, cards, IBANs and national IDs are masked too. You decide when Claude may see one kind.
Read signup-errors.log and find out why validateEmail would reject these addresses
/zeroh-disclosure:unmask EMAIL to list the rejected sign-ups exactly
Read signup-errors.log again and list the addresses exactly
Done, stop showing emails
/zeroh-disclosure:unmask revoke does the same.No rule knows every secret. This one hides in a URL path.
Read config/internal.env. Does anything in it look like a secret?
Report it as a missed secret
/zeroh-disclosure:report-miss: a private form says Type the value ZeroH missed into this private form. Submit masks it from now on and keeps a local note of its shape (never the value); Cancel changes nothing. Reports stay on this computer./zeroh-disclosure:mask-receipt
/zeroh-disclosure:status
What does ZeroH Disclosure protect, and what doesn't it?
/zeroh-disclosure:proxy off
ZeroH Disclosure: this prompt was not protected (proxy not running); STRIPE_KEY was used without masking. /zeroh-disclosure:proxy on turns it back on, the same way: The local masking proxy is on again: your next Claude Code session sets it up.Tell us:
Open an issue at github.com/Blade-Labs/zeroh-marketplace or write to hello@bladelabs.io. Never paste a real key.