pi-pii-mask

内容来源:README.md(说明文档) · 原始地址 · 查看安装指南

原始内容

pi-pii-mask

Lightweight regex-based PII mask/unmask extension for Pi coding agent.

Redacts sensitive data before it reaches the LLM provider and transparently restores original values in responses. No ML model, no downloads, zero npm dependencies.

Install

pi install npm:pi-pii-mask

What it masks

Pattern Example
Email addresses user@example.com[EMAIL_1]
Phone numbers +1 (555) 123-4567[PHONE_1]
Social Security numbers 123-45-6789[SSN_1]
Credit card numbers 4111-1111-1111-1111[CC_1]
Private IPs 10.0.0.1, 192.168.1.1[PRIVATE_IP_1]
API keys sk-..., ghp_..., AIza...[API_KEY_*]
JWTs eyJ...[JWT_1]
AWS access keys AKIA...[AWS_KEY_1]
Connection strings mongodb://user:pass@host[CONN_STR_1]

How it works

User: "my email is test@example.com"
  ↓ context hook masks
LLM sees: "my email is [EMAIL_1]"
  ↓ LLM calls tool with [EMAIL_1]
  ↓ tool_call hook unmasks in place
Tool runs with real value: test@example.com
  ↓ context hook (next turn) masks result
LLM sees: "[EMAIL_1]"
  ↓ LLM responds with [EMAIL_1]
  ↓ message_end hook unmasks
User sees: "test@example.com"

Commands

  • /pii-map — show current placeholder → original mapping

Requirements

  • Pi coding agent >= 0.73.0
  • Node.js >= 20