Prompt Cleaner MCP Server
Prompt Cleaner MCP Server cleans, normalizes, and redacts sensitive information from raw user prompts using an LLM.
Core Capabilities:
Clean & Normalize Prompts - Transform raw user text into well-structured requests while preserving intent, with 'general' and 'code' modes for context-appropriate processing
Redact Sensitive Data - Automatically detect and scrub PII, API keys, tokens, and secrets from prompts, logs, and outputs
Structured Output - Returns JSON with retouched text plus
notes,openQuestions,risks, andredactionsarraysMultiple Tool Interfaces - Access via
cleaner,sanitize-text, ornormalize-promptaliasesConfigurable LLM Integration - Connect to any OpenAI-compatible API with customizable model, timeout, temperature (0-2, default 0.2), and automatic retry/exponential backoff
Health Monitoring - Check server liveness with
health-pingtoolSecurity Options - Enforce local-only API access via
ENFORCE_LOCAL_API, single-model policy for deterministic behaviorSafe by Default - Read-only, idempotent operations with no side effects and automatic output normalization for clients that don't support JSON
Integrates with OpenAI-compatible APIs to provide prompt cleaning and sanitization services, using LLM models to retouch prompts, identify risks, redact sensitive information, and provide structured feedback on prompt quality.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Prompt Cleaner MCP Serverclean this prompt: 'My API key is sk-live-abc123, show user emails'"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.

Prompt Cleaner (MCP Server)
TypeScript MCP server exposing a prompt cleaning tool and health checks. All prompts route through cleaner, with secret redaction, structured schemas, and client-friendly output normalization.
Features
Tools
health-ping: liveness probe returning{ ok: true }.cleaner: clean a raw prompt; returns structured JSON with retouched string, notes, openQuestions, risks, and redactions.
Secret redaction: Sensitive patterns are scrubbed from logs and outputs in
src/redact.ts.Output normalization:
src/server.tsconverts content withtype: "json"to plain text for clients that reject JSON content types.Configurable: LLM base URL, API key, model, timeout, log level; optional local-only enforcement.
Deterministic model policy: Single model via
LLM_MODEL; no dynamic model selection/listing by default.
Related MCP server: MCP Prompt Optimizer
Requirements
Node.js >= 20
Install & Build
npm install
npm run buildRun
Dev (stdio server):
npm run devInspector (Debugging)
Use the MCP Inspector to exercise tools over stdio:
npm run inspectEnvironment
Configure via .env or environment variables:
LLM_API_BASE(string, defaulthttp://localhost:1234/v1): OpenAI-compatible base URL.LLM_API_KEY(string, optional): Bearer token for the API.LLM_MODEL(string, defaultopen/ai-gpt-oss-20b): Model identifier sent to the API.LLM_TIMEOUT_MS(number, default60000): Request timeout.LOG_LEVEL(error|warn|info|debug, defaultinfo): Log verbosity (logs JSON to stderr).ENFORCE_LOCAL_API(true|false, defaultfalse): Iftrue, only allow localhost APIs.LLM_MAX_RETRIES(number, default1): Retry count for retryable HTTP/network errors.RETOUCH_CONTENT_MAX_RETRIES(number, default1): Retries when the cleaner returns non-JSON content.LLM_BACKOFF_MS(number, default250): Initial backoff delay in milliseconds.LLM_BACKOFF_JITTER(0..1, default0.2): Jitter factor applied to backoff.
Example .env:
LLM_API_BASE=http://localhost:1234/v1
LLM_MODEL=open/ai-gpt-oss-20b
LLM_API_KEY=sk-xxxxx
LLM_TIMEOUT_MS=60000
LOG_LEVEL=info
ENFORCE_LOCAL_API=false
LLM_MAX_RETRIES=1
RETOUCH_CONTENT_MAX_RETRIES=1
LLM_BACKOFF_MS=250
LLM_BACKOFF_JITTER=0.2Tools (API Contracts)
All tools follow MCP Tool semantics. Content is returned as [{ type: "json", json: <payload> }] and normalized to type: "text" by the server for clients that require it.
health-ping
Input:
{}Output:
{ ok: true }
cleaner
Input:
{ prompt: string, mode?: "code"|"general", temperature?: number }Output:
{ retouched: string, notes?: string[], openQuestions?: string[], risks?: string[], redactions?: ["[REDACTED]"][] }Behavior: Applies a system prompt from
prompts/cleaner.md, calls the configured LLM, extracts first JSON object, validates with Zod, and redacts secrets.
sanitize-text (alias of
cleaner)Same input/output schema and behavior as
cleaner. Exposed for agents that keyword-match on “sanitize”, “PII”, or “redact”.
normalize-prompt (alias of
cleaner)Same input/output schema and behavior as
cleaner. Exposed for agents that keyword-match on “normalize”, “format”, or “preprocess”.
Per-call API key override
src/llm.ts accepts apiKey in options for per-call overrides; falls back to LLM_API_KEY.
Project Structure
src/server.ts: MCP server wiring, tool listing/calls, output normalization, logging.src/tools.ts: Tool registry and dispatch.src/cleaner.ts: Cleaner pipeline and JSON extraction/validation.src/llm.ts: LLM client with timeout, retry, and error normalization.src/redact.ts: Secret redaction utilities.src/config.ts: Environment configuration and validation.test/*.test.ts: Vitest suite covering tools, shapes, cleaner, and health.
Testing
npm testDesign decisions
Single-model policy: Uses
LLM_MODELfrom environment; no model listing/selection tool to keep behavior deterministic and reduce surface area.Output normalization:
src/server.tsconvertsjsoncontent totextfor clients that reject JSON.Secret redaction:
src/redact.tsscrubs sensitive tokens from logs and outputs.
Troubleshooting
LLM timeout: Increase
LLM_TIMEOUT_MS; check network reachability toLLM_API_BASE.Non-JSON from cleaner: Retries up to
RETOUCH_CONTENT_MAX_RETRIES. If persistent, reducetemperatureor ensure the configured model adheres to the output contract.HTTP 5xx from LLM: Automatic retries up to
LLM_MAX_RETRIESwith exponential backoff (LLM_BACKOFF_MS,LLM_BACKOFF_JITTER).Local API enforcement error: If
ENFORCE_LOCAL_API=true,LLM_API_BASEmust point to localhost.Secrets in logs/outputs: Redaction runs automatically; if you see leaked tokens, update patterns in
src/redact.ts.
Windsurf (example)
Add an MCP server in Windsurf settings, pointing to the built stdio server:
{
"mcpServers": {
"prompt-cleaner": {
"command": "node",
"args": ["/absolute/path/to/prompt-cleaner/dist/server.js"],
"env": {
"LLM_API_BASE": "http://localhost:1234/v1",
"LLM_API_KEY": "sk-xxxxx",
"LLM_MODEL": "open/ai-gpt-oss-20b",
"LLM_TIMEOUT_MS": "60000",
"LOG_LEVEL": "info",
"ENFORCE_LOCAL_API": "false",
"LLM_MAX_RETRIES": "1",
"RETOUCH_CONTENT_MAX_RETRIES": "1",
"LLM_BACKOFF_MS": "250",
"LLM_BACKOFF_JITTER": "0.2"
}
}
}
}Usage:
In a chat, ask the agent to use
cleanerwith your raw prompt.Or invoke tools from the agent UI if exposed by your setup.
LLM API compatibility
Works with OpenAI-compatible Chat Completions APIs (e.g., LM Studio local server) that expose
/v1/chat/completions.Configure via
LLM_API_BASEand optionalLLM_API_KEY. UseENFORCE_LOCAL_API=trueto restrict to localhost for development.Set
LLM_MODELto the provider-specific model identifier. This server follows a single-model policy for determinism and reproducibility.Providers must return valid JSON; the cleaner includes limited retries when content is not strictly JSON.
Links
Model Context Protocol (spec): https://modelcontextprotocol.io
Cleaner system prompt:
prompts/cleaner.md
Notes
Logs are emitted to stderr as JSON lines to avoid interfering with MCP stdio.
Some clients reject
jsoncontent types; this server normalizes them totextautomatically.
Security
Secrets are scrubbed by
src/redact.tsfrom logs and cleaner outputs.ENFORCE_LOCAL_API=truerestricts usage to local API endpoints.
Available Tools
4 toolscleanerA
Pre-reasoning prompt normalizer and PII redactor. Use when: you receive raw/free-form user text and need it cleaned before planning, tool selection, or code execution. Does: normalize tone, structure the ask, and redact secrets; preserves user intent. Safe: read-only, idempotent, no side effects (good default to run automatically). Input: { prompt, mode?, temperature? } — defaults mode='general', temperature=0.2; mode='code' only for code-related prompts. Output: JSON { retouched, notes?, openQuestions?, risks?, redactions? }. Keywords: clean, sanitize, normalize, redact, structure, preprocess, guardrails
| Name | Required | Description | Default |
|---|---|---|---|
| prompt | Yes | Raw user prompt | |
| mode | No | Retouching mode; default 'general'. Use 'code' only for code-related prompts. | |
| temperature | No | Sampling temperature (0-2); default 0.2 |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It effectively describes key traits: 'read-only, idempotent, no side effects', which clarifies safety and operational characteristics. However, it lacks details on rate limits, error handling, or specific PII types redacted, leaving some behavioral aspects unspecified.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is well-structured with clear sections (purpose, usage, behavior, input, output, keywords) and front-loaded key information. Most sentences earn their place, but the keyword list at the end is somewhat redundant with earlier content, slightly reducing efficiency without adding new insights.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's moderate complexity, no annotations, and no output schema, the description does a good job covering purpose, usage, behavior, and parameters. It explains the output format ('JSON { retouched, notes?, openQuestions?, risks?, redactions? }'), compensating for the lack of output schema. However, it could provide more detail on error cases or specific redaction rules for completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3. The description adds value by explaining parameter defaults ('defaults mode='general', temperature=0.2') and usage context for 'mode' ('mode='code' only for code-related prompts'), which enhances understanding beyond the schema's enum and descriptions. It doesn't fully elaborate on 'temperature' effects, keeping it from a perfect score.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with specific verbs ('normalize', 'redact', 'structure') and resources ('raw/free-form user text'), distinguishing it from siblings like 'normalize-prompt' and 'sanitize-text' by emphasizing pre-reasoning processing and PII redaction. It explicitly mentions preserving user intent, which adds nuance beyond basic normalization.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit guidance on when to use this tool ('when you receive raw/free-form user text and need it cleaned before planning, tool selection, or code execution') and distinguishes it from alternatives by specifying mode usage ('mode='code' only for code-related prompts'). It also positions it as a 'good default to run automatically', offering clear context for application.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
health-pingB
Liveness probe; returns { ok: true }
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It states the tool returns '{ ok: true }', which implies a read-only, non-destructive operation, but doesn't cover other traits like error handling, latency, or side effects. This is adequate as a minimal disclosure but lacks depth.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise and front-loaded, consisting of just two phrases that directly state the tool's function and output. Every word earns its place with no waste, making it highly efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (0 parameters, no output schema, no annotations), the description is complete enough for a basic liveness probe. However, it could benefit from more context, such as when to use it or what 'ok: true' signifies, but it meets the minimum viable standard for this low-complexity tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has 0 parameters, and the schema description coverage is 100%, so no parameter information is needed. The description doesn't add parameter details beyond the schema, but with no parameters, this is acceptable, aligning with the baseline of 4 for zero-parameter tools.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose as a 'liveness probe' that returns a specific response, which is a specific verb+resource combination. However, it doesn't differentiate from sibling tools like 'cleaner' or 'normalize-prompt', which appear to serve different functions, so it doesn't fully meet the highest standard for sibling differentiation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. It doesn't mention any context, prerequisites, or exclusions, leaving the agent without usage instructions. This is a basic gap in guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
normalize-promptC
Alias of cleaner. Keywords: normalize, restructure, clarify, tighten, format, preflight. Same input/output schema as 'cleaner'.
| Name | Required | Description | Default |
|---|---|---|---|
| prompt | Yes | Raw user prompt | |
| mode | No | Retouching mode; default 'general'. Use 'code' only for code-related prompts. | |
| temperature | No | Sampling temperature (0-2); default 0.2 |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It only states it's an alias with the same input/output schema as 'cleaner', but doesn't disclose behavioral traits such as whether it's read-only, destructive, has rate limits, or requires authentication. This leaves significant gaps in understanding how the tool behaves beyond basic functionality.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is brief and to the point, consisting of two sentences that efficiently convey key information (alias relationship and keywords). However, it could be more front-loaded with a clearer purpose statement, but it avoids unnecessary verbosity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no annotations, no output schema, and a vague purpose, the description is incomplete. It doesn't adequately explain what the tool does, when to use it, or its behavioral aspects, making it insufficient for an agent to fully understand the tool's role and operation in context.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema fully documents the parameters. The description adds no additional meaning beyond stating it has the 'same input/output schema as cleaner', which doesn't explain parameter semantics further. This meets the baseline of 3 since the schema handles the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states this is an 'alias of cleaner' and lists keywords like 'normalize, restructure, clarify, tighten, format, preflight', which gives a vague sense of purpose but lacks a specific verb+resource statement. It doesn't clearly explain what the tool actually does beyond being related to 'cleaner', making it somewhat ambiguous rather than tautological.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description mentions it's an alias of 'cleaner' and lists keywords, but provides no explicit guidance on when to use this tool versus alternatives like 'cleaner' or 'sanitize-text'. There's no context on use cases, prerequisites, or exclusions, leaving the agent with minimal direction.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
sanitize-textC
Alias of cleaner. Keywords: sanitize, scrub, redact, filter, pii, normalize, preprocess. Same input/output schema as 'cleaner'.
| Name | Required | Description | Default |
|---|---|---|---|
| prompt | Yes | Raw user prompt | |
| mode | No | Retouching mode; default 'general'. Use 'code' only for code-related prompts. | |
| temperature | No | Sampling temperature (0-2); default 0.2 |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It hints at functionality through keywords (e.g., 'pii', 'redact') but doesn't explain what the tool actually does behaviorally—such as whether it modifies input, returns cleaned output, or handles errors. This leaves critical operational traits unspecified.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is brief and front-loaded with key information (alias and keywords), but the second sentence about the schema is somewhat redundant given the structured input. It avoids unnecessary elaboration, though it could be more streamlined by integrating the alias and keyword info more cohesively.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no annotations and no output schema, the description is incomplete for a tool with 3 parameters. It fails to explain what the tool returns or how it behaves, relying too heavily on the schema and leaving gaps in understanding the tool's overall functionality and results, which is inadequate for effective agent use.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema fully documents parameters like 'prompt', 'mode', and 'temperature'. The description adds no additional semantic context beyond stating 'Same input/output schema as cleaner', which doesn't enhance understanding of parameter purposes or interactions, meeting the baseline for high schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states this is an 'alias of cleaner' and lists keywords like 'sanitize, scrub, redact, filter, pii, normalize, preprocess', which gives a general sense of purpose. However, it doesn't specify a clear verb+resource combination (e.g., 'sanitize text by removing PII') and doesn't distinguish it from its sibling 'cleaner' beyond stating it's an alias, leaving the relationship ambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no explicit guidance on when to use this tool versus alternatives like 'cleaner' or 'normalize-prompt'. It mentions it's an alias of 'cleaner' but doesn't clarify if they are interchangeable or if there are specific contexts favoring one over the other, offering minimal usage direction.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
4 tool updates
- First observed
cleaner - First observed
health-ping - First observed
normalize-prompt - First observed
sanitize-text
TDQS
The tool set has severe ambiguity issues, with three tools (cleaner, normalize-prompt, sanitize-text) being explicit aliases of each other, performing identical functions with the same input/output schema. This creates confusion and redundancy, making it impossible for an agent to distinguish between them based on purpose or functionality.
Naming is mixed but readable, with tools using snake_case (e.g., 'health-ping') and hyphenated forms (e.g., 'normalize-prompt'), but lacks a consistent pattern. While not chaotic, the deviation from a uniform convention like verb_noun reduces predictability across the set.
With 4 tools, the count is borderline low for the server's purpose of prompt cleaning, but the real issue is that 3 of the tools are redundant aliases. This makes the effective tool count much lower, feeling thin and poorly scoped, as it doesn't justify multiple entries for the same functionality.
For the domain of prompt cleaning, the core functionality is well-covered by the cleaner tool, including normalization, PII redaction, and structured output. The health-ping adds basic liveness. However, minor gaps exist, such as lack of tools for post-cleaning analysis or configuration management, but agents can work around these with the provided tools.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
- PromptOTOAuthcom.promptot
Manage, version, and publish LLM prompts with blocks, variables, and evaluations.
The WAF for agents. Pattern-based + heuristic firewall scans prompts, RAG documents, tool argume...
Prompt injection detection API for AI agents. Scan untrusted text before passing it to an LLM.
Deterministic trust gate for AI output: leaked-secret, prompt-injection & PII in one call.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnhances and cleans raw prompts using AI to make them more clear, actionable, and effective. Provides quality assessment, suggestions, and supports both general and code-specific optimization modes.1MIT
- AlicenseBqualityDmaintenanceAutomatically analyzes and optimizes AI prompts by calculating clarity scores, detecting risks, asking clarifying questions, and adding domain-specific requirements to improve AI interaction quality.1MIT

classifinder-mcpofficial
AlicenseAqualityBmaintenanceEnables AI agents to scan text for leaked secrets and prompt injection markers, and redact them before reaching an LLM.21MIT- AlicenseAqualityDmaintenanceScans prompts for PII and masks or redacts sensitive data locally before sending to an LLM, supporting multiple anonymization modes.1MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/dacebt/prompt-cleaner-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server