PrivAiTe — AI skill for Claude Code
Self-hosted PII redaction proxy for LLM APIs and agent CLIs.
How to install PrivAiTe
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open crp4222/PrivAiTe and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What PrivAiTe does
Self-hosted PII redaction proxy for LLM APIs and agent CLIs. Scrubs names, emails and secrets from Claude Code, Codex and any OpenAI-compatible app before requests leave your machine, tool-call arguments included, then restores them in the reply. Local detection, zero telemetry.
Alternatives in AI
- WindsurfAPI — Turn Windsurf / Devin Desktop's 100+ AI models (Claude, GPT, Gemini, DeepSeek, Kimi, GLM, SWE) into OpenAI-, A 3k ★
- DontFeedTheAI — Transparent anonymization proxy for AI-assisted pentesting 654 ★
- Update Branch Name — by giselles-ai - Updates branch names with proper prefixes and formats, enforcing naming conventions, supporti 502 ★
README
PrivAiTe
Self-hosted PII redaction proxy for LLM APIs.
[](https://github.com/crp4222/PrivAiTe/actions) [](https://www.python.org/downloads/) [](https://github.com/crp4222/PrivAiTe/blob/main/LICENSE) [](https://pypi.org/project/privaite/)
**A drop-in LLM proxy that replaces PII before it reaches the provider, including inside tool-call arguments and multimodal content, with zero telemetry.**
Told in writing to report its config variables but **never their values**, Claude Code sent 3 of 4 secrets to its provider anyway: the same secrets also sat in a log file the task had it read. Over that session **23 of 24** planted values reached the provider; through PrivAiTe's agent gateway, **2 of 24**. Wire-level captures of real agent sessions, and the two that still get through are documented rather than rounded away: [the measurement](https://github.com/crp4222/PrivAiTe/blob/main/docs/agent-leak-measurement.md), [what it misses](https://github.com/crp4222/PrivAiTe#threat-model).
**Shipped in 0.5.0:** local rules now target the credential fields behind those historical log misses, and overlapping detections respect irreversible and block policies, so a secret overlapping a higher-scored email stays irreversible. See [formats and limits](https://github.com/crp4222/PrivAiTe/blob/main/docs/detection.md#structured-credentials-and-overlapping-types). In the [offline regression replay](https://github.com/crp4222/privaite-bench/blob/main/agent_workflow/STRUCTURED_SECRETS.md), 9 of 10 credential occurrences survived in a 69 KB log before the change; none survived afterward. Processing still takes about 25 seconds with `onnx`.
You type: "Je m'appelle Marie Dupont, email marie@acme.com"
LLM sees: "Je m'appell
Related Skills
Mask2ai
PII redaction for ChatGPT, claude.ai and Claude Code. Masks names, emails, phone numbers, cards, IBANs and IDs
Shush
Remove PII & secrets from any file before you paste it into ChatGPT or Claude — a 100% local PII redaction CLI
Keyfence
Local proxy that keeps your API keys and secrets out of LLM requests. Works with Claude Code, Cursor, Codex an
Aigate
AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs
Datafog Python
Offline PII firewall for AI agents and LLM apps: fast local detection and redaction, Claude Code hook, LiteLLM
AI Helpdesk
AI-powered helpdesk that turns inbound support emails into tickets — Claude classifies category/urgency/sentim
Related Agents
Openrouter Agent
Runs a model from any of ~60 vendors through OpenRouter's OpenAI-compatible endpoint, billed per token against
Fable5 Apfel Engineer
Heavy-lifting Fable-5 engineer for the apfel project (Apple on-device FoundationModels CLI + OpenAI-compatible
Provider Debugger
Diagnose live-provider compatibility failures for Kimi, GLM, and other OpenAI-compatible endpoints