- My role
- Solo
- Where
- Independent project
- When
- May – Jun 2026
- Stack
- Python
- FastMCP
- pytest
Try to leak something.
Try to leak something
All 11 rules from scanner.py, running in your browser
What the agent gets back
Each finding becomes its scanner.py label. The rest passes through.
Verdict
Redact
3 findings: CREDIT_CARD, EMAIL, SSN
Audit log
Append-only
Runs entirely in your browser. Nothing you type leaves this page.
| Rule | Type | Action | Hits |
|---|---|---|---|
| PII | Redact | 1 | |
| PHONE | PII | Redact | 0 |
| PHONE_BARElow | PII | Redact | 0 |
| SSN | PII | Redact | 1 |
| SSN_BARElow | PII | Redact | 0 |
| CREDIT_CARD | PII | Redact | 1 |
| BEARER_TOKEN | Credential | Block | 0 |
| API_KEY | Credential | Block | 0 |
| AWS_ACCESS_KEY | Credential | Block | 0 |
| PRIVATE_KEY | Credential | Block | 0 |
| SECRET | Credential | Redact | 0 |
Only high-confidence credentials block. SECRET is a fuzzy keyword match, so it redacts instead. Rules marked low are low-confidence guesses.
The problem
Preflop
Agents wired into Drive, Slack and Notion can pass a document’s SSNs, card numbers and API keys straight to a model.
The approach
Flop
An MCP server that sits between the connector and the agent: scan on read, then allow, redact, or block.
The hard part
Turn
The raw text never leaves the function. Only the redacted result or a block message is returned, and every read is written to an append-only audit log.
What shipped
River
11 PII and credential rules, label-preserving redaction, hard blocks on high-confidence credentials.
The result, or as poker players say, the showdown
24-test pytest suite, end to end.