crp4222

PrivAiTe — AI skill for Claude Code

AI community

Self-hosted PII redaction proxy for LLM APIs and agent CLIs.

How to install PrivAiTe

This entry records only its repository, not the path inside it, so there is no exact command to give. Open crp4222/PrivAiTe and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What PrivAiTe does

Self-hosted PII redaction proxy for LLM APIs and agent CLIs. Scrubs names, emails and secrets from Claude Code, Codex and any OpenAI-compatible app before requests leave your machine, tool-call arguments included, then restores them in the reply. Local detection, zero telemetry.

Alternatives in AI

  • WindsurfAPI — Turn Windsurf / Devin Desktop's 100+ AI models (Claude, GPT, Gemini, DeepSeek, Kimi, GLM, SWE) into OpenAI-, A 3k ★
  • DontFeedTheAI — Transparent anonymization proxy for AI-assisted pentesting 654 ★
  • Update Branch Name — by giselles-ai - Updates branch names with proper prefixes and formats, enforcing naming conventions, supporti 502 ★

README

PrivAiTe

Self-hosted PII redaction proxy for LLM APIs.

[![CI](https://github.com/crp4222/PrivAiTe/actions/workflows/ci.yml/badge.svg)](https://github.com/crp4222/PrivAiTe/actions) [![Python 3.11+](https://img.shields.io/badge/python-3.11+-blue.svg)](https://www.python.org/downloads/) [![License](https://img.shields.io/badge/license-BSD--3--Clause-green.svg)](https://github.com/crp4222/PrivAiTe/blob/main/LICENSE) [![PyPI](https://img.shields.io/pypi/v/privaite.svg)](https://pypi.org/project/privaite/)

**A drop-in LLM proxy that replaces PII before it reaches the provider, including inside tool-call arguments and multimodal content, with zero telemetry.**

Told in writing to report its config variables but **never their values**, Claude Code sent 3 of 4 secrets to its provider anyway: the same secrets also sat in a log file the task had it read. Over that session **23 of 24** planted values reached the provider; through PrivAiTe's agent gateway, **2 of 24**. Wire-level captures of real agent sessions, and the two that still get through are documented rather than rounded away: [the measurement](https://github.com/crp4222/PrivAiTe/blob/main/docs/agent-leak-measurement.md), [what it misses](https://github.com/crp4222/PrivAiTe#threat-model).

**Shipped in 0.5.0:** local rules now target the credential fields behind those historical log misses, and overlapping detections respect irreversible and block policies, so a secret overlapping a higher-scored email stays irreversible. See [formats and limits](https://github.com/crp4222/PrivAiTe/blob/main/docs/detection.md#structured-credentials-and-overlapping-types). In the [offline regression replay](https://github.com/crp4222/privaite-bench/blob/main/agent_workflow/STRUCTURED_SECRETS.md), 9 of 10 credential occurrences survived in a 69 KB log before the change; none survived afterward. Processing still takes about 25 seconds with `onnx`.

You type: "Je m'appelle Marie Dupont, email marie@acme.com"
LLM sees: "Je m'appell