</>MCP Agents Market
Plugin

ggshield

by GitGuardian2kPythonUpdated 2026-09-04

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.

Claude CodeCursorCopilot ChatCodex

The ggshield Claude Code plugin protects your code by detecting over 500 types of hardcoded secrets before they're exposed to AI coding assistants. Developed by GitGuardian, it integrates with Claude Code, Cursor, Copilot Chat, and other AI tools to scan interactions in real-time and block actions containing sensitive credentials. The tool operates locally using GitGuardian's public API to identify vulnerabilities without storing your files or secrets on remote servers. It can be deployed as a pre-commit hook, GitHub Action, or standalone CLI for proactive security scanning.

Key Features

Real-time secret detection scanning interactions between developers and AI coding assistants
Identifies 500+ types of hardcoded secrets including AWS keys, API tokens, and database credentials
Blocks dangerous actions containing secrets before execution in supported AI tools
Privacy-focused architecture that sends only metadata, never storing files or detected secrets
Cross-platform support via install scripts, package managers (Homebrew, Chocolatey, apt, yum), and PyPI
Multiple scan modes: files, repositories, Docker images, and PyPI packages
Git hook integration for pre-commit, pre-push, and pre-receive workflows
CI/CD integration for automated security checks in deployment pipelines

Use Cases

  • 01Prevent developers from accidentally sharing API keys or credentials with Claude Code during code generation
  • 02Scan repositories before commits to catch hardcoded secrets in staging areas
  • 03Audit Docker images for exposed credentials before pushing to registries
  • 04Block sensitive data leaks during pair programming sessions with Cursor or Copilot Chat
  • 05Integrate into CI/CD pipelines to automatically reject builds containing secrets
  • 06Review Python packages from PyPI for embedded credentials before installation

Related Plugins

View more

ggshield — FAQ

What is the ggshield Claude Code plugin?+

It's a security tool that scans code interactions with AI assistants like Claude Code in real-time to detect and block over 500 types of hardcoded secrets before they're exposed or executed.

How do I install the ggshield plugin for Claude Code?+

Run the install script for your platform (curl command on Linux/macOS or PowerShell script on Windows), then authenticate using 'ggshield auth login'. For AI assistant integration, use 'ggshield install' to set up hooks for Claude Code and other supported tools.

Which AI coding assistants work with ggshield?+

ggshield supports Claude Code, Cursor, Copilot Chat, Codex, and Mistral Vibe 2.21+. It can scan interactions with these tools in real-time to prevent secret leaks.

Do I need a GitGuardian API key to use ggshield?+

Yes, you need to authenticate with GitGuardian servers. Use 'ggshield auth login' for automatic token provisioning, or manually create a personal access token and set it in the GITGUARDIAN_API_KEY environment variable.

Is ggshield free to use?+

The tool is open source and MIT licensed. It uses GitGuardian's public API for scanning, which may have usage limits depending on your GitGuardian account tier.

Does ggshield store my code or secrets?+

No, ggshield only sends metadata like call time, request size, and scan mode to GitGuardian's API. Your files and any detected secrets are never stored or displayed on dashboards.

How do I install ggshield?+

Open the source repository on GitHub and follow its README. ggshield is a plugin — MCP Agents Market links you directly to the official repo.

Is ggshield free?+

ggshield is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches