Skip to main content

maskflow-cli

Command-line interface for MaskFlow:

maskflow config validate
maskflow config show --resolved
maskflow doctor
maskflow explain "<text>"
maskflow scan jsonl requests.jsonl --field 'messages[].content'

maskflow doctor checks installed versions, spaCy model presence (and which entities that consequently disables), and .maskflowrc validity, then reports enabled/disabled status for every registered entity. It exits 0 only when every check passes.

maskflow explain "<text>" shows, span by span, why each piece of text was (or wasn't) detected as PII -- the pattern/NER hit, checksum result, context boost, and the threshold decision behind it. Spans that scored below their entity's threshold are listed separately as NEAREST MISSES, with the .maskflowrc change that would catch them. Matched text is truncated to 8 characters unless --full is passed. Accepts the same --config/--set overrides as maskflow config, so explanations reflect the same resolved config a real mask() call would use.

maskflow scan -- what PII already reached your LLM providers

maskflow scan SOURCE ... answers the question a DPDP-deadline audit asks first: what PII has this system already sent to third-party LLM providers, and how bad is it? It reads your historical LLM traffic, runs MaskFlow's own detection over it, and writes one self-contained HTML report -- inline CSS/JS, zero external requests, so it prints cleanly and can be emailed to an auditor as-is.

Features

  • Eight source adapters, one interface: jsonl / ndjson (with --field selectors), csv (--columns), dir (recursive), s3 (streamed), postgres (server-side cursor), and the langfuse / helicone / langsmith REST APIs. s3 and postgres need the maskflow-cli[s3] / [postgres] extras; the rest need nothing extra.
  • Streaming, bounded memory -- inputs can be gigabytes. --workers N parallelises detection; --checkpoint FILE makes a run resumable; --sample N is a fast first pass.
  • Hybrid detection. The pattern/checksum pass (Aadhaar, PAN, GSTIN, UPI, IFSC, cards, email, ...) covers the whole corpus. The NER pass (bare names & addresses) runs on a sample and is reported as a clearly labelled estimate -- pass --deep to run it over everything.
  • The report: one headline number, breakdowns by entity type / provider / model / time, a severity ranking with a plain-English "why this matters" per row, masked excerpts only (values shown as <AADHAAR_1>, never raw), and a DPDP Rule 6 mapping appendix. Also --format json|csv.
  • Runs entirely locally. Nothing is transmitted. The API sources only read from your own observability account.

Try it -- a synthetic 60-record sample ships in examples/:

uv run maskflow scan jsonl packages/maskflow-cli/examples/sample-llm-traffic.jsonl \
  --field 'messages[].content' \
  --provider-field provider --service-field model --timestamp-field created_at \
  --deep --out exposure-report.html

Notes: uv run runs the CLI from the workspace venv -- drop it if maskflow-cli is on your PATH (pipx install maskflow-cli). Quote the --field value: messages[].content contains [], which the shell would otherwise try to expand.

Install it -- four ways, see packaging/ and docs/scan.md:

NER (names/addresses/DOB)
pipx install maskflow-cli + python -m spacy download en_core_web_sm yes
docker run --rm -v "$PWD:/work" ghcr.io/maskflow/cli scan ... yes, baked in
standalone binary (GitHub Releases, no Python) no -- pattern pass only
maskflow/scan-action for CI yes

Then open exposure-report.html. See examples/README.md for a walk-through of the output, and docs/scan.md for the full reference.

See docs/configuration.md in the repo root for the full config reference.

Metadata

Release files for maskflow-cli 0.8.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for maskflow-cli 0.8.0
File Size Uploaded
maskflow_cli-0.8.0.tar.gz 70.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for maskflow-cli 0.8.0
File Interpreter ABI Platform
maskflow_cli-0.8.0-py3-none-any.whl Python 3 none any Details

Total release size: 143.5 kB

Release files / maskflow_cli-0.8.0.tar.gz

Download URL maskflow_cli-0.8.0.tar.gz
Size 70.8 kB
Tags Source
SHA-256 checksum
How to use checksums
c32f7ca7c838743dc3131f3b77cb2dcaa37f1a4fda1dfac3eb7dfed2d122d3c8
BLAKE2b-256 checksum
How to use checksums
9c0e4f1c0ebe8f71aa22856b8b8e6bc80cbd366bb7ad72d9fa269646e7aa15e8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 12, 2026.

Transparency log

Release files / maskflow_cli-0.8.0-py3-none-any.whl

Download URL maskflow_cli-0.8.0-py3-none-any.whl
Size 72.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
dfe9d7e7f08ab880e4f579a83958d9bad260627fe34f3e7a0f2f188208d08df0
BLAKE2b-256 checksum
How to use checksums
2e401f4637c87fc74acbad73e2e5200300c462bf4f7da173f874da989a793ce7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 12, 2026.

Transparency log

Release history Release notifications | RSS feed

0.8.2

2 release files

0.8.1

2 release files

This release

0.8.0 This release

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page