---
name: secret-redactor
description: "Detects and warns about secrets in outbound messages, monitors SECURITY_FLAG markers"
metadata: { "openclaw": { "emoji": "🔐", "events": ["message:sent"] } }
---
# Secret Redactor

Scans outbound AI messages for leaked secrets and `[SECURITY_FLAG]` markers injected by the security-bootstrap hook.

## How It Works

### Secret Detection
Uses the same pattern library as `secrets-scanner` to detect credentials in AI responses. When found, pushes a redaction warning to the user. Unlike `secrets-scanner`, this hook focuses specifically on outbound messages and provides actionable redaction guidance.

### Security Flag Detection
When `security-bootstrap` injects SECURITY.md into the agent context, the LLM may add `[SECURITY_FLAG: description]` markers when it detects suspicious requests. This hook watches for those markers and logs them as security events.

## Events

| Event | Action |
|-------|--------|
| `message:sent` | Scans AI response for secrets and security flags |

## Limitations

- **Post-send detection**: the message has already been sent when the hook fires. This hook provides awareness and audit, not prevention.
- For true pre-send blocking, a `message_sending` plugin hook would be needed (not available in hook packs).
- `tool_result_persist` (plugin API) would be needed for transcript-level redaction.
