Skip to main content
Glama

Mask Personally Identifiable Information

civify_mask_pii

Sanitize and redact sensitive PII (email, phone, physical address) from a CV document, exporting an anonymized PDF. May consume AI credits; do not automatically retry.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
fileNoA user-selected chat attachment supplied by the client. Never invent a download URL or file ID.
file_urlNoActual HTTPS download URL supplied by the client or user. Never use a sandbox path, file ID alone or an invented URL.
filenameNoOriginal filename for base64 data, including extension (PDF, DOCX, PNG or JPG). Inferred from bytes when omitted.
file_base64NoBase64 encoded resume file (PDF, DOCX). Recommended for remote/cloud MCP servers.
resume_textNoComplete resume text read from the attachment. Preferred fallback when the client cannot forward bytes. Do not summarize or invent missing content.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
dataYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • removedInput schema / properties / api_key
      Removed value: -{
      -  "description": "Optional API key override.",
      -  "type": "string"
      -}
  2. Changed13 schema fields changed
    • addedInput schema / anyOf
      Added value: +[
      +  {
      +    "required": [
      +      "file"
      +    ]
      +  },
      +  {
      +    "required": [
      +      "file_url"
      +    ]
      +  },
      +  {
      +    "required": [
      +      "resume_text"
      +    ]
      +  },
      +  {
      +    "required": [
      +      "file_base64"
      +    ]
      +  }
      +]
    • addedInput schema / properties / file
      Added value: +{
      +  "additionalProperties": false,
      +  "description": "A user-selected chat attachment supplied by the client. Never invent a download URL or file ID.",
      +  "properties": {
      +    "download_url": {
      +      "type": "string"
      +    },
      +    "file_id": {
      +      "type": "string"
      +    },
      +    "file_name": {
      +      "type": "string"
      +    },
      +    "mime_type": {
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "download_url",
      +    "file_id"
      +  ],
      +  "type": "object"
      +}
    • addedInput schema / properties / file_url
      Added value: +{
      +  "description": "Actual HTTPS download URL supplied by the client or user. Never use a sandbox path, file ID alone or an invented URL.",
      +  "type": "string"
      +}
    • addedInput schema / properties / filename
      Added value: +{
      +  "description": "Original filename for base64 data, including extension (PDF, DOCX, PNG or JPG). Inferred from bytes when omitted.",
      +  "type": "string"
      +}
    • removedInput schema / properties / output_path
      Removed value: -{
      -  "description": "Optional destination path on the server to save the masked PDF.",
      -  "type": "string"
      -}
    • addedInput schema / properties / resume_text
      Added value: +{
      +  "description": "Complete resume text read from the attachment. Preferred fallback when the client cannot forward bytes. Do not summarize or invent missing content.",
      +  "minLength": 1,
      +  "type": "string"
      +}
    • removedInput schema / properties / server_file_path
      Removed value: -{
      -  "description": "Local file path on the MCP server machine. For local CLI/stdio usage only. In ChatGPT or Claude, pass 'file_base64' instead.",
      -  "type": "string"
      -}
    • addedOutput schema / properties / data
      Added value: +{}
    • removedOutput schema / properties / message
      Removed value: -{
      -  "description": "Details on the exported sanitized document",
      -  "type": "string"
      -}
    • removedOutput schema / properties / path
      Removed value: -{
      -  "description": "Filesystem path to saved masked PDF",
      -  "type": "string"
      -}
    • removedOutput schema / properties / pdf_base64
      Removed value: -{
      -  "description": "Base64 encoded masked PDF if saved to memory",
      -  "type": "string"
      -}
    • removedOutput schema / properties / status
      Removed value: -{
      -  "description": "Redaction status (SUCCESS)",
      -  "type": "string"
      -}
    • changedOutput schema / required
      Previous value: -[
      -  "status",
      -  "message"
      -]New value: +[
      +  "data"
      +]
  3. Changed4 schema fields changed
    • changedInput schema / properties / file_base64 / description
      Previous value: -"Base64 encoded resume file."New value: +"Base64 encoded resume file (PDF, DOCX). Recommended for remote/cloud MCP servers."
    • removedInput schema / properties / file_path
      Removed value: -{
      -  "description": "Path to resume file to redact.",
      -  "type": "string"
      -}
    • changedInput schema / properties / output_path / description
      Previous value: -"Optional destination path to save the masked PDF."New value: +"Optional destination path on the server to save the masked PDF."
    • addedInput schema / properties / server_file_path
      Added value: +{
      +  "description": "Local file path on the MCP server machine. For local CLI/stdio usage only. In ChatGPT or Claude, pass 'file_base64' instead.",
      +  "type": "string"
      +}
  4. First observed

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only provide negative hints (readOnlyHint false, idempotentHint false, destructiveHint false), so the description carries the burden. It adds a valuable behavioral warning about AI credit consumption and advises against automatic retries, which is critical for an agent. It also implies a transformation (sanitization) that produces a PDF, but does not disclose details like error handling or irreversibility. The credit warning adds significant transparency beyond the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences with zero waste. The core purpose is front-loaded, and the cost/retry warning is a separate, essential callout. Every sentence earns its place; no redundant phrasing.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values are covered. The description covers the PII types and output format, and the cost warning addresses a key operational concern. It does not mention supported input formats (though the schema does for base64), nor does it note any limitations or prerequisites beyond credits. Given the tool's complexity (multiple input modes) and the presence of an output schema, this is reasonably complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with each parameter having a detailed description (e.g., 'Never invent a download URL or file ID' for file_url, and 'Do not summarize or invent missing content' for resume_text). The description itself adds no parameter-specific detail, but the schema already handles semantics well. Baseline 3 is appropriate given the high coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states a specific action (sanitize and redact PII) on a CV document and the output (anonymized PDF). It lists the specific PII types (email, phone, physical address), distinguishing it from sibling tools like parse_cv or tailor_cv. The verb 'sanitize and redact' and resource 'CV document' are precise.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage when anonymization is needed but does not explicitly mention when to choose this tool over siblings or provide exclusions. The cost warning ('May consume AI credits; do not automatically retry') gives some operational context but does not guide selection among alternatives. Clear context but no explicit 'when not to use'.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources