
PII & Secret Redactor
io.github.tylerscomic-labv1.0.0更新於 Oct 2, 2026
Detect and redact PII and secrets before text reaches an LLM, with reversible placeholders.
概覽
在文字送進大型語言模型之前偵測並遮蔽其中的個人資料與金鑰,並以可還原的佔位符取代。
- 功能
- 提供偵測、遮蔽與還原工具:detect_pii 回傳類型、位置與遮罩預覽,不會回顯完整值;redact_text 可用穩定佔位符、遮罩、加鹽雜湊或移除方式處理;restore_text 依你保留的對應關係把模型回覆中的佔位符換回原文;list_detectors 說明涵蓋與未涵蓋的範圍。信用卡、IBAN、美國路由號與 SSN 經過校驗和驗證,另可辨識電子郵件、電話、出生日期、美國街道地址、IP 位址,以及多種 API 金鑰與私密金鑰。
- 適用情境
- 適合在把可能含客戶資料或憑證的文字送往模型、日誌或工單之前降低暴露風險,同時讓回覆保持可讀。也適合需要同一個值始終對應到同一個佔位符、以便事後還原的情境。
- 執行需求
- 可使用 MCPize 代管的遠端 MCP 端點(streamable HTTP,需要 MCPize 的 API key),也可自行執行:需要 Node.js,執行 npm install 後再執行 node server.js,監聽 8080 埠,MCP 路徑為 /mcp。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 PII & Secret Redactor,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"pii-redactor-mcp": {
"type": "http",
"url": "https://pii-redactor-mcp.mcpize.run/mcp"
}
}
}README
PII & Secret Redactor
Redact PII and secrets from text before it reaches an LLM. Checksum-verified cards, IBANs and routing numbers, SSN range rules, API keys, and reversible placeholders you can restore after the model responds.
Send the question, not the customer's data
Strip personal data and credentials out of text before it goes to a model, a log or a ticket, then put the originals back in the answer.
What it detects
- Verified, not just matched: credit cards (Luhn, brand identified), IBANs (mod-97), US routing numbers (ABA checksum), SSNs (invalid ranges rejected). Order numbers and random digit strings are left alone.
- Contact and identity: emails, phone numbers (US and international), labelled dates of birth, US street addresses, IPv4 and IPv6.
- Secrets: Anthropic, OpenAI, AWS, GitHub, Stripe, Slack and Google keys, JWTs, private keys, database URLs with credentials.
Tools
detect_pii: findings with type, position and a masked preview. Never echoes full values.redact_text: placeholder (stable tokens like<EMAIL_1>, same value gives the same token), mask, salted hash, or remove.restore_text: swap placeholders back to the originals in the model's response, using the mapping you keep.list_detectors: exactly what is and is not covered.
Be clear about the limits
Pattern and checksum based. It does not detect personal names or free-form addresses in other formats, so it reduces exposure but is not a compliance guarantee for HIPAA, GDPR or PCI. Input is processed in memory and never stored or logged.
Use it
Hosted on MCPize with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):
Or run it yourself:
MIT licensed.
來源:README.md,提交 530eaf7
工具
0版本歷史
1- v1.0.0最新Oct 2, 2026