Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
cover — Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow. | Kitploit
ツール/GitHubGitHub/davidcarliez/cover
Defensive ToolsWeb Proxies & InterceptionPrivacySecret DetectionAPI SecurityAI Security
GitHubdavidcarliez/cover

cover

Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.

リポジトリを見る
4954419日前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
要求された言語のコンテンツは利用できません。英語版を表示しています。

Cover

Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.

CI Go License

Install · Quick start · Policies · Monitoring · Pi / OMP · Security

Cover is a bidirectional privacy proxy for AI coding agents. It replaces matched sensitive values locally with realistic, deterministic stand-ins before a request leaves your machine, then translates matching fakes in normal and streaming responses back to the originals. The model gets coherent context; your agent and tools keep working with the real environment.

Cover changes private values into protected replacements before an LLM request, then restores reversible values in the response. It also supports placeholder, mask, redact, block, and allow policies.

Use reversible pseudonymize or placeholder rules when the conversation must keep working end to end. Use one-way mask or redact rules when restoration is unnecessary, block to stop a request locally, and allow for an explicit exception.

Supported clients include Codex, Claude Code, Cursor, Pi / Oh My Pi, and OpenAI- or Anthropic-compatible SDKs and routers.

Install

The installer downloads the release for your OS and CPU, verifies it against the published SHA-256 checksums, installs it atomically to ~/.local/bin/cover, configures selected clients, and starts the proxy.

curl -fsSL https://raw.githubusercontent.com/DavidCarliez/cover/main/scripts/install.sh | bash

No Go toolchain or Git checkout is required. You only need curl, an archive extractor (tar on Linux/macOS or unzip on Windows), and sha256sum, shasum, or openssl for verification.

Prebuilt Linux, macOS, and Windows archives and their checksums are available from GitHub Releases.

For a non-interactive install:

curl -fsSL https://raw.githubusercontent.com/DavidCarliez/cover/main/scripts/install.sh | \
  COVER_AGENTS=openai,claude bash

Pin a release or install only the binary with environment variables applied to the bash process:

curl -fsSL https://raw.githubusercontent.com/DavidCarliez/cover/main/scripts/install.sh | \
  COVER_VERSION=v0.1.0 COVER_SKIP_SETUP=1 bash
Build manually or cross-compile
git clone https://github.com/DavidCarliez/cover.git
cd cover
go build -o cover ./cmd/cover
install -m 0755 cover ~/.local/bin/cover

The core binary has no cgo dependency. Standard Go cross-compilation works:

GOOS=linux GOARCH=arm64 go build -o cover-linux-arm64 ./cmd/cover
GOOS=windows GOARCH=amd64 go build -o cover.exe ./cmd/cover

Highlights

AreaCover functionality
PolicyDeclarative rules with allow, placeholder, pseudonymize, mask, redact, and block actions
Realistic replacementsDeterministic generators for IP addresses, hosts, domains, emails, usernames, passwords, UUIDs, URLs, and aliases
Context-aware rulesWhole-value protection by JSON key, including short passwords such as admin, plus regex and built-in detector selectors
Stable identitiesInstallation-keyed HMAC pseudonyms remain consistent across requests, sessions, and restarts
Mapping safetyBounded, session-isolated, memory-only reversible mappings with TTL and capacity limits
Inspectioncover inspect previews the protected JSON without contacting an LLM
Diagnosticscover doctor verifies policy, daemon health, local fail-closed behavior, and Codex routing
MonitoringMetadata-only audit and monitor views, plus explicit live-only inspection of caught and forwarded content
Proxy hardeningLoopback-by-default listeners, body and stream limits, generic safe errors, and fail-closed parsing
Streaming compatibilityOpenAI Responses, Chat Completions, and Anthropic SSE restoration across delta events, heartbeats, and interleaved channels; JSON-safe tool arguments
Codex compatibilityResponses API and router configuration, compression checks, and immutable encrypted_content fields
Optional semantic passA local llama.cpp detector can inspect free-form text that regular expressions miss

Quick start

cover init             # write ~/.config/cover/config.yaml
cover start --detach   # run in the background
cover doctor           # verify the local setup
cover test             # local redaction round trip, no network call
cover monitor          # watch privacy-safe request metadata

cover init prompts for OpenAI, Anthropic, or a custom upstream. The complete configuration is documented in configs/config.example.yaml.

Command reference

CommandPurpose
cover installConfigure clients, shell exports, and the background proxy
cover initCreate the configuration file
cover start [--detach]Start Cover in the foreground or background
cover stopStop the background process
cover restartRestart it in the background
cover status [--json]Show process, listener, and redacted upstream status
cover version [--json]Show build version, commit, and date
cover update [--version vX.Y.Z]Install a verified GitHub release; restart and check health if running (Linux/macOS)
cover update --rollbackRestore the previous binary, preserving configuration
cover envPrint shell exports for configured clients
cover testRun a synthetic local redaction and restoration check
cover inspect request.jsonPreview exactly what Cover would forward
cover doctor [--json]Run configuration, privacy, daemon, and routing checks
cover monitorShow recent safe metadata and follow new events
cover monitor --show-contentShow sensitive live transformations and outbound JSON
cover models pullDownload the optional local detector runtime and model
cover models statusReport local detector installation and configuration
cover completionGenerate shell completion scripts

Stopping Cover does not change client configuration. A client still pointed at Cover will fail to connect until Cover is restarted or the client is pointed back to its direct provider or router.

Stops and restarts drain active requests for up to 30 seconds, configurable with shutdown_timeout_ms. After that deadline, remaining connections close. New connections can fail briefly during restart; this is not a zero-downtime handover. cover status and cover doctor report when the running daemon differs from the installed binary.

ツールをダウンロード