omitly-leak-check-mcp
README.md
# omitly-leak-check-mcp
A free, local **MCP server** that answers one question: *did your PDF redaction
actually work, or is the data still sitting in the file underneath the black
boxes?*
Most tools "redact" by drawing a rectangle over text — the characters stay in the
PDF and are trivially recoverable. This server re-extracts the text layer and
flags any emails, SSNs, phone or card numbers that survived.
- **Zero install** — `npx omitly-leak-check-mcp`. No native binary, no qpdf.
- **Nothing uploaded** — the engine is a WebAssembly build of Omitly's detector
that runs inside the MCP process. Your PDF never leaves the machine.
- **Masked** — results show `•••-••-6789`, never the raw value.
## Use with Claude
Add to your MCP client config (e.g. Claude Desktop `claude_desktop_config.json`):
```json
{
"mcpServers": {
"omitly-leak-check": {
"command": "npx",
"args": ["-y", "omitly-leak-check-mcp"]
}
}
}
```
Then ask: *"Did I actually redact /path/to/file.pdf?"*
## Tools
| Tool | What it does |
|------|--------------|
| `check_redaction` | Audit a "redacted" PDF; report surviving PII (masked). |
| `find_sensitive_regions` | List PII candidates with page + coordinates. |
| `locate_text` | Find exact strings (names/addresses) and their positions. |
All three are **detect-only and read-only.** They never modify a file.
## This finds the problem. Omitly fixes it.
Detecting a leak is free. *Removing* the data for real — with independent
verification that nothing survives, plus a signed audit log — is the
[Omitly](https://omitly.app) desktop app. Detection is also pattern-based: names,
addresses, and text inside scanned images aren't covered, so a clean result is
not a guarantee of completeness.
## Develop
```bash
npm install && npm run build
npm run smoke -- /path/to/test.pdf # prove the wasm loads + scans
```
The wasm in `wasm/` is built from `crates/leakcheck-wasm` in the Omitly repo
(`wasm-pack build --target web`).
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessSyncing