Phi Guard Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Phi Guard Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server and CLI for detecting, redacting, and auditing PHI before medical text is sent to AI agents.
phi-guard-mcp is healthcare AI safety infrastructure, not a clinical product. It is a local, rule-based guardrail that helps developers identify PHI-like identifiers in plain text, redact them with stable placeholders, and produce audit-friendly JSON before content reaches an AI agent or MCP workflow.
Proof points for maintainers:
Important scope limits:
The project aligns its documentation vocabulary with HHS HIPAA de-identification concepts such as Safe Harbor and Expert Determination, while intentionally avoiding clinical decision support scope. See HHS de-identification guidance, FDA CDS guidance, and FDA device software functions.
python -m pip install phi-guard-mcpFor local development:
python -m pip install -e ".[dev]"Scan a synthetic note:
phi-guard scan examples/synthetic_clinical_note.txtRedact PHI-like identifiers:
phi-guard redact examples/synthetic_clinical_note.txt --out /tmp/synthetic_redacted.txtAudit a note:
phi-guard audit examples/synthetic_clinical_note.txtValidate text before it enters an AI agent:
phi-guard validate examples/synthetic_clean_note.txtRun the synthetic benchmark:
phi-guard benchmark benchmarks/synthetic/cases --out benchmarks/synthetic-report.jsonRun the repository privacy gate:
phi-guard gate --config .phi-guard.tomlAll CLI commands output stable JSON for automation.
See docs/demo.md for a complete CLI and MCP transcript.
Run the stdio MCP server:
phi-guard-mcpAvailable tools:
scan_phi(text)redact_phi(text, mode="placeholder")audit_deidentification(text)validate_no_phi(text)MCP tools return the same finding schema as the CLI, including safe_harbor_identifier.
Example MCP client config:
{
"mcpServers": {
"phi-guard": {
"command": "phi-guard-mcp"
}
}
}from phi_guard_mcp import audit_text, evaluate_benchmark, redact_text, scan_text, validate_no_phi
result = scan_text("Patient Name: Jordan Rivera, MRN: MRN-48291")
redacted = redact_text("Patient Name: Jordan Rivera, MRN: MRN-48291")
audit = audit_text("Patient Name: Jordan Rivera, MRN: MRN-48291")
validation = validate_no_phi("No identifiers are present in this synthetic note.")
benchmark = evaluate_benchmark("benchmarks/synthetic/cases")The first release focuses on plain text and common PHI-like identifiers:
This is a deterministic heuristic engine. It favors transparent behavior and repeatable JSON over opaque model judgment.
Safe Harbor mapping is included as a review aid only. It does not make output HIPAA compliant and does not replace Expert Determination or legal review.
python -m compileall -q src tests
python -m pytest -q
ruff check .
phi-guard gate --config .phi-guard.toml
python -m build
twine check dist/*~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.