maskflow-cli
Command-line interface for MaskFlow:
maskflow config validate
maskflow config show --resolved
maskflow doctor
maskflow explain "<text>"
maskflow scan jsonl requests.jsonl --field 'messages[].content'
maskflow doctor checks installed versions, spaCy model presence (and
which entities that consequently disables), and .maskflowrc validity,
then reports enabled/disabled status for every registered entity. It
exits 0 only when every check passes.
maskflow explain "<text>" shows, span by span, why each piece of text
was (or wasn't) detected as PII -- the pattern/NER hit, checksum result,
context boost, and the threshold decision behind it. Spans that scored
below their entity's threshold are listed separately as NEAREST MISSES,
with the .maskflowrc change that would catch them. Matched text is
truncated to 8 characters unless --full is passed. Accepts the same
--config/--set overrides as maskflow config, so explanations reflect
the same resolved config a real mask() call would use.
maskflow scan -- what PII already reached your LLM providers
maskflow scan SOURCE ... answers the question a DPDP-deadline audit asks
first: what PII has this system already sent to third-party LLM
providers, and how bad is it? It reads your historical LLM traffic, runs
MaskFlow's own detection over it, and writes one self-contained HTML
report -- inline CSS/JS, zero external requests, so it prints cleanly and
can be emailed to an auditor as-is.
Features
- Eight source adapters, one interface:
jsonl/ndjson(with--fieldselectors),csv(--columns),dir(recursive),s3(streamed),postgres(server-side cursor), and thelangfuse/helicone/langsmithREST APIs.s3andpostgresneed themaskflow-cli[s3]/[postgres]extras; the rest need nothing extra. - Streaming, bounded memory -- inputs can be gigabytes.
--workers Nparallelises detection;--checkpoint FILEmakes a run resumable;--sample Nis a fast first pass. - Hybrid detection. The pattern/checksum pass (Aadhaar, PAN, GSTIN,
UPI, IFSC, cards, email, ...) covers the whole corpus. The NER pass
(bare names & addresses) runs on a sample and is reported as a clearly
labelled estimate -- pass
--deepto run it over everything. - The report: one headline number, breakdowns by entity type /
provider / model / time, a severity ranking with a plain-English "why
this matters" per row, masked excerpts only (values shown as
<AADHAAR_1>, never raw), and a DPDP Rule 6 mapping appendix. Also--format json|csv. - Runs entirely locally. Nothing is transmitted. The API sources only read from your own observability account.
Try it -- a synthetic 60-record sample ships in
examples/:
uv run maskflow scan jsonl packages/maskflow-cli/examples/sample-llm-traffic.jsonl \
--field 'messages[].content' \
--provider-field provider --service-field model --timestamp-field created_at \
--deep --out exposure-report.html
Notes: uv run runs the CLI from the workspace venv -- drop it if
maskflow-cli is on your PATH (pipx install maskflow-cli). Quote the
--field value: messages[].content contains [], which the shell would
otherwise try to expand.
Install it -- four ways, see
packaging/ and docs/scan.md:
| NER (names/addresses/DOB) | |
|---|---|
pipx install maskflow-cli + python -m spacy download en_core_web_sm |
yes |
docker run --rm -v "$PWD:/work" ghcr.io/maskflow/cli scan ... |
yes, baked in |
| standalone binary (GitHub Releases, no Python) | no -- pattern pass only |
maskflow/scan-action for CI |
yes |
Then open exposure-report.html. See examples/README.md
for a walk-through of the output, and docs/scan.md for the full reference.
See docs/configuration.md in the repo root for the full config reference.
Metadata
Release files for maskflow-cli 0.8.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| maskflow_cli-0.8.2.tar.gz | 71.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| maskflow_cli-0.8.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 144.5 kB
Release files / maskflow_cli-0.8.2.tar.gz
| Download URL | maskflow_cli-0.8.2.tar.gz |
|---|---|
| Size | 71.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
af3397853a0223cbf58021756339e6d7e2ef449c726f42988ec56e09eab34826
|
|
BLAKE2b-256 checksum How to use checksums |
72ab4d6a3ff76bc361be8c4a7df43a31a40ea58c298b48a8d0c155d1febb87a5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 10, 2026.
Transparency logRelease files / maskflow_cli-0.8.2-py3-none-any.whl
| Download URL | maskflow_cli-0.8.2-py3-none-any.whl |
|---|---|
| Size | 72.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0a89317d10d096e5d054def1aaf5371a5622685aa681d1553a3ce457b5710693
|
|
BLAKE2b-256 checksum How to use checksums |
b3d94b5d6a28c55376d301e7c9e32313c60bbd6ef32baee4f4333af1f5d9d4de
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 10, 2026.
Transparency log