Skip to main content
0Pirate Logo

0Pirate

Local redaction proxy and zero-knowledge middleware for AI-assisted coding

License: MIT


Overview

0Pirate is a local proxy that sits between your development environment and frontier AI models. It removes credentials, replaces proprietary business logic with structural placeholders, sends the sanitized code to the AI provider, and restores the original code locally when the response arrives.

The Problem

Engineering teams face a direct trade-off between AI coding performance and code privacy:

1. Local models fall short on complex code

Running local open-weight models through tools like Ollama keeps data on your machine, but smaller models (7B to 70B) cannot match the reasoning, context tracking, and multi-file refactoring abilities of frontier cloud models. For complex system design and hard bugs, local models often slow developers down.

2. Cloud models expose sensitive assets

Sending unredacted code to third-party endpoints creates exposure risks across three areas:

  • Credentials and secrets: API keys, database connection strings, SSH keys, authentication tokens.
  • Personal and infrastructure data: Internal hostnames, private IP addresses, employee emails, customer data in test fixtures.
  • Intellectual property: Proprietary algorithms, financial formulas, patented logic, and domain-specific business rules.

3. Traditional masking tools break code

Standard data loss prevention filters and regex rules treat code like plain text:

  • Regex replacements break Abstract Syntax Tree (AST) structures, scope boundaries, and language typing.
  • Simple masks do not hide the semantics of proprietary logic.
  • Text filters are one-way. When an AI returns a code patch, regex tools cannot automatically restore the original identifiers into working code.

How 0Pirate Works

0Pirate runs entirely on your local machine or private network:

  1. AST-level abstraction: Rather than using naive text replacement, 0Pirate parses the syntax tree. Proprietary functions, internal classes, and business variables are mapped to structurally valid placeholder tokens.
  2. Secret redaction: High-entropy strings, credential formats, and sensitive constants are detected and removed before any payload is sent.
  3. Model-agnostic routing: 0Pirate does not depend on a specific AI model. It works with any modern provider:
    • Anthropic: Claude 3.7 Sonnet, Claude 3.5 Sonnet, Claude Opus
    • OpenAI: GPT-4o, o1, o3-mini
    • DeepSeek: DeepSeek-R1, DeepSeek-V3
    • Google: Gemini 2.0 Flash, Gemini 1.5 Pro
    • Meta, Mistral, and custom endpoints via OpenRouter or OpenAI-compatible APIs
  4. Local rehydration: When the model returns generated code or a diff, 0Pirate maps all placeholders back to your original variable names, functions, and secrets in local memory. The remote provider never receives the raw IP.

Using with Agentic IDEs (Cursor and Claude Code)

0Pirate runs as a local Model Context Protocol (MCP) server. When an agent in Cursor or Claude Code requests project context, 0Pirate intercepts the file read, redacts the contents, and returns the safe version.

MCP Configuration

Add 0Pirate to your Cursor or Claude Desktop configuration file:

{
  "mcpServers": {
    "0pirate-secure-proxy": {
      "command": "python3",
      "args": ["/path/to/0pirate/cli/mcp_server.py"]
    }
  }
}

Once configured, the agent reads and writes code through the proxy without exposing your underlying secrets or proprietary identifiers.

Quickstart

Run the local stack:

Prerequisites

  • Docker and Docker Compose
  • Python 3.10 or newer

Setup

# Clone the repository
git clone https://github.com/Arunmadhavan28/0pirate.git
cd 0pirate

# Set up environment variables
cp .env.example .env

# Start local services
docker-compose up -d

# Install CLI and pre-commit hook
cd cli
pip install -r requirements.txt
python main.py install-hook

Services:

  • Backend proxy: http://localhost:5001
  • Frontend dashboard: http://localhost:3000
  • Pre-commit hook: checks git commits for accidental secret leakage

Documentation

Community

License

This project is licensed under the MIT License.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

0pirate-0.1.4.tar.gz (3.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

0pirate-0.1.4-py3-none-any.whl (3.8 kB view details)

Uploaded Python 3

File details

Details for the file 0pirate-0.1.4.tar.gz.

File metadata

  • Download URL: 0pirate-0.1.4.tar.gz
  • Upload date:
  • Size: 3.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.10.13

File hashes

Hashes for 0pirate-0.1.4.tar.gz
Algorithm Hash digest
SHA256 da054497b9b7c990cd1b86d214de43ce16587c4f22253068045ddda8b17ae094
MD5 7f48d28d25f2facd9c3e9183a589dc6a
BLAKE2b-256 cf11f62ff4d6077b3ba6b30c40e426eba4db6e18eeff19875af5a136f3dfa8ad

See more details on using hashes here.

File details

Details for the file 0pirate-0.1.4-py3-none-any.whl.

File metadata

  • Download URL: 0pirate-0.1.4-py3-none-any.whl
  • Upload date:
  • Size: 3.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.10.13

File hashes

Hashes for 0pirate-0.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 f577997eb9889fd47d9d68ca9bd97feab13394dcded9b4a756ce111ddee12ae5
MD5 aec172e378fdd2243a3a67ea6772a001
BLAKE2b-256 790d4dec5127b12603d0e450dcdcbc3130b525e3b7bdf8348476155394d9a4a0

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.4 This release

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page