PII & Secret Redactor

io.github.tylerscomic-labv1.0.0更新於 Oct 2, 2026

Detect and redact PII and secrets before text reaches an LLM, with reversible placeholders.

已驗證Streamable HTTP可網頁執行Security & MonitoringAI & ML

概覽

AI 產生的概覽

在文字送進大型語言模型之前偵測並遮蔽其中的個人資料與金鑰,並以可還原的佔位符取代。

功能
提供偵測、遮蔽與還原工具:detect_pii 回傳類型、位置與遮罩預覽,不會回顯完整值;redact_text 可用穩定佔位符、遮罩、加鹽雜湊或移除方式處理;restore_text 依你保留的對應關係把模型回覆中的佔位符換回原文;list_detectors 說明涵蓋與未涵蓋的範圍。信用卡、IBAN、美國路由號與 SSN 經過校驗和驗證,另可辨識電子郵件、電話、出生日期、美國街道地址、IP 位址,以及多種 API 金鑰與私密金鑰。
適用情境
適合在把可能含客戶資料或憑證的文字送往模型、日誌或工單之前降低暴露風險,同時讓回覆保持可讀。也適合需要同一個值始終對應到同一個佔位符、以便事後還原的情境。
執行需求
可使用 MCPize 代管的遠端 MCP 端點(streamable HTTP,需要 MCPize 的 API key),也可自行執行:需要 Node.js,執行 npm install 後再執行 node server.js,監聽 8080 埠,MCP 路徑為 /mcp。
安裝前請注意
代管端點需要 MCPize 的 API key,免費額度為每天 10 次呼叫。偵測以模式和校驗和為基礎,無法辨識姓名或其他格式的自由文字地址,因此只能降低暴露,不構成 HIPAA、GDPR 或 PCI 合規保證。還原佔位符取決於你自行保存的對應關係,該對應關係需妥善保管。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 PII & Secret Redactor,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "pii-redactor-mcp": {
      "type": "http",
      "url": "https://pii-redactor-mcp.mcpize.run/mcp"
    }
  }
}

README

PII & Secret Redactor

Redact PII and secrets from text before it reaches an LLM. Checksum-verified cards, IBANs and routing numbers, SSN range rules, API keys, and reversible placeholders you can restore after the model responds.

Send the question, not the customer's data

Strip personal data and credentials out of text before it goes to a model, a log or a ticket, then put the originals back in the answer.

What it detects

  • Verified, not just matched: credit cards (Luhn, brand identified), IBANs (mod-97), US routing numbers (ABA checksum), SSNs (invalid ranges rejected). Order numbers and random digit strings are left alone.
  • Contact and identity: emails, phone numbers (US and international), labelled dates of birth, US street addresses, IPv4 and IPv6.
  • Secrets: Anthropic, OpenAI, AWS, GitHub, Stripe, Slack and Google keys, JWTs, private keys, database URLs with credentials.

Tools

  • detect_pii: findings with type, position and a masked preview. Never echoes full values.
  • redact_text: placeholder (stable tokens like <EMAIL_1>, same value gives the same token), mask, salted hash, or remove.
  • restore_text: swap placeholders back to the originals in the model's response, using the mapping you keep.
  • list_detectors: exactly what is and is not covered.

Be clear about the limits

Pattern and checksum based. It does not detect personal names or free-form addresses in other formats, so it reduces exposure but is not a compliance guarantee for HIPAA, GDPR or PCI. Input is processed in memory and never stored or logged.

Use it

Hosted on MCPize with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):

https://pii-redactor-mcp.mcpize.run/mcp

Or run it yourself:

bash
npm installnode server.js   # listens on :8080, MCP at /mcp

MIT licensed.

來源:README.md,提交 530eaf7

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 2, 2026