
PII & Secret Redactor
io.github.tylerscomic-labv1.0.0更新于 Oct 2, 2026
Detect and redact PII and secrets before text reaches an LLM, with reversible placeholders.
概览
在文本进入大模型之前检测并脱敏其中的个人数据与密钥,并用可还原的占位符替换。
- 功能
- 提供检测、脱敏和还原工具:detect_pii 返回类型、位置和掩码预览,不回显完整值;redact_text 可用稳定占位符、掩码、加盐哈希或删除方式处理;restore_text 依据你保留的映射把模型回复中的占位符换回原文;list_detectors 说明覆盖与未覆盖的范围。信用卡、IBAN、美国路由号和 SSN 经过校验和验证,另可识别邮箱、电话、出生日期、美国街道地址、IP 地址以及多种 API 密钥和私钥。
- 适用场景
- 适合在把可能含客户数据或凭据的文本发送给模型、日志或工单之前降低暴露风险,同时保持回复可读。也适合需要同一取值始终映射到同一占位符、以便事后还原的场景。
- 运行要求
- 可使用 MCPize 托管的远程 MCP 端点(streamable HTTP,需要 MCPize 的 API key),也可自行运行:需要 Node.js,执行 npm install 后运行 node server.js,监听 8080 端口,MCP 路径为 /mcp。
安装
在 SourceWeft 中
- 打开 控制台中的 PII & Secret Redactor,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"pii-redactor-mcp": {
"type": "http",
"url": "https://pii-redactor-mcp.mcpize.run/mcp"
}
}
}README
PII & Secret Redactor
Redact PII and secrets from text before it reaches an LLM. Checksum-verified cards, IBANs and routing numbers, SSN range rules, API keys, and reversible placeholders you can restore after the model responds.
Send the question, not the customer's data
Strip personal data and credentials out of text before it goes to a model, a log or a ticket, then put the originals back in the answer.
What it detects
- Verified, not just matched: credit cards (Luhn, brand identified), IBANs (mod-97), US routing numbers (ABA checksum), SSNs (invalid ranges rejected). Order numbers and random digit strings are left alone.
- Contact and identity: emails, phone numbers (US and international), labelled dates of birth, US street addresses, IPv4 and IPv6.
- Secrets: Anthropic, OpenAI, AWS, GitHub, Stripe, Slack and Google keys, JWTs, private keys, database URLs with credentials.
Tools
detect_pii: findings with type, position and a masked preview. Never echoes full values.redact_text: placeholder (stable tokens like<EMAIL_1>, same value gives the same token), mask, salted hash, or remove.restore_text: swap placeholders back to the originals in the model's response, using the mapping you keep.list_detectors: exactly what is and is not covered.
Be clear about the limits
Pattern and checksum based. It does not detect personal names or free-form addresses in other formats, so it reduces exposure but is not a compliance guarantee for HIPAA, GDPR or PCI. Input is processed in memory and never stored or logged.
Use it
Hosted on MCPize with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):
Or run it yourself:
MIT licensed.
来源:README.md,提交 530eaf7
工具
0版本历史
1- v1.0.0最新Oct 2, 2026