with one click
saferead
Runtime redaction tools — safe-read strips secrets and
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Menu
Runtime redaction tools — safe-read strips secrets and
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Based on SOC occupation classification
| name | SafeRead |
| description | Runtime redaction tools — safe-read strips secrets and |
Runtime redaction tools for reading protected files and managing their metadata.
Read a file with inline #tlp/red sections stripped and secrets redacted:
Modules/forge-tlp/bin/safe-read "/path/to/file.md"
RED files are refused entirely — safe-read only handles AMBER and below.
safe-read automatically scans for known API key and credential patterns (sourced from gitleaks) and replaces them with [SECRET REDACTED]. A warning is emitted to stderr when secrets are found.
Coverage includes 45+ services:
| Category | Services |
|---|---|
| AI/ML | Anthropic, OpenAI, OpenRouter |
| Cloud | AWS, GCP, Azure |
| Code hosting | GitHub, GitLab |
| Communication | Slack, Twilio, SendGrid, Mailchimp |
| Payments | Stripe |
| Package registries | npm |
| Databases | MongoDB connection strings |
| Crypto | PEM private keys, JWTs |
Patterns are compiled into a single regex from src/redact/mod.rs. They match token formats (prefix + length + character set), not secret values — so they work without a secrets database.
safe-read processes two kinds of redaction:
#tlp/red block and inline sections (see /TLP skill for marker syntax)[SECRET REDACTED]Both run in a single pass. TLP redaction runs first, then secret scanning on the remaining content.
Bulk YAML frontmatter operations without reading file content. Useful for managing tlp: fields across files:
# Set a key on all .md files in a directory
Modules/forge-tlp/bin/blind-metadata set <directory> <key> <value>
# Get a key from all .md files
Modules/forge-tlp/bin/blind-metadata get <directory> <key>
# List files missing a key
Modules/forge-tlp/bin/blind-metadata has <directory> <key>
Supports absolute paths and vault-relative paths (walks up to find .tlp root).
# Classify a directory as RED
blind-metadata set Resources/Contacts tlp RED
# Audit which files have TLP frontmatter
blind-metadata has Resources/Journals tlp
# Read TLP values without opening the files
blind-metadata get Resources/Journals tlp
/TLP — classification rules, .tlp config, frontmatter overrides/SecretScan — commit-time secret scanning with gitleaks!dispatch skill-load forge-tlp