Pseudonymized by design
R.Code for Claude Code keeps real names and paths out of the framework itself. Real project names, machine paths and personal identifiers live only in a local vault. Every write, every commit and every publish is checked: 0 real values in any tracked file.
The vault
Real values live only on your machine, in a local vault (gitignored, never committed). The framework’s own tracked files refer to them through tokens instead of the real value.
Several spellings of the same real thing — a short name, a long name, another casing, a path alias — can share one group, so the same real entity stays recognizable as one entity after replacement, instead of splintering into unconnected tokens.
Tokens, not placeholders
A token is an HMAC-SHA256 prefix keyed with a local secret, not a plain hash. Project and account names have too little entropy — a plain hash would be reversible by dictionary lookup; an HMAC keyed with a secret is not. On the same machine a token stays stable across sessions, so a record built over many sessions stays legible together. On a different machine, the same real value produces a different token — two developers’ vaults are never linkable against each other.
Three gates, one matcher
A real value is refused at three independent points, all sourced from the same matcher so no second, independently written check can drift from the first:
- A PreToolUse hook refuses an Edit or Write that would land a real value in a versioned file.
- A git pre-commit hook checks staged content for writers outside Claude Code itself.
- A public CI check checks the published clone, so a gap on one machine still gets caught before the public repo sees it.
Structural patterns — user/volume paths, email addresses, UUIDs, session and trigger identifiers — don’t need a vault entry to be caught, so the same three gates work even in a fresh public clone that has never had a vault.
Contributing without your private data
Working with R.Code for Claude Code naturally produces local findings — observations your own routine writes into your personal, local improvement ledger. Real project names, paths, and account identifiers may legitimately appear there; they belong on your machine, never in the published framework. To share a finding upstream without any of that leaving your machine:
- Create your local vault once (idempotent):
bash scripts/vault/vault.sh init. Register your own recurring private terms withvault.sh add. - Get a submission form: copy the submission template and fill it in by hand, or pre-fill it from a local ledger entry — every value taken from the ledger is tokenized before it is written.
- Have it checked: a clean run prints ready-to-paste issue/PR text on stdout; a finding blocks and names only the kind and token, never the real value.
- Open the printed text as a GitHub issue or PR.