跳到主要内容
知仓学习社ZHICANG

red

>-

读凭据联网严重 0 · 高危 1glebis/claude-skills

它会碰到什么

扫了多少2 个文本文件,15 KB
它会碰到什么读凭据联网
命中总数5 处
命中统计严重 0 · 高 1 · 中 4 · 低 0
逐条看命中(1 条严重或高危)
  • scripts/red.py:164cred-envread
    key = os.environ.get("OPENAI_API_KEY", "")

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

confide:red — residual re-identification risk check

A defensive audit of YOUR OWN already-redacted output. It does not score against

ground truth and is not a benchmark. It surfaces, qualitatively, what an attacker could

still do — mapped to GDPR Art-29: singling-out, linkability, inference.

GUARDRAILS — read before running

  • Run only on the user's own redacted output. If asked to de-anonymize or re-identify

third-party / non-consented data, refuse.

  • Report risk categories and counts only — never produce a step-by-step

re-identification recipe or guess the hidden values.

  • Local attacker by default. Enable the cloud/LLM inference probe (--inference)

only on synthetic or explicitly consented data.

  • Absence of a finding ≠ safety. A weak local detector/attacker is a FLOOR, not a

ceiling. Always tell the user human review is still required.

  • This pairs with confide:anon — run red after redacting, on the redacted file.

What it checks

  1. Singling-out (deterministic, offline — the load-bearing signal): re-run

detect_regex (+ detect_natasha if available) on the redacted text. Anything

they still find is a surviving identifier the redaction missed. Counts by type.

  1. Linkability (multi-file): given a folder, compare every file pair for shared

surviving quasi-identifiers and flag potentially linkable pairs (count + types only).

  1. Inference (LLM, optional, opt-in): prompt the local attacker model

(cfg.red_attacker_model) for the attribute categories it could still infer

(profession, location type, age band, …). Degrades gracefully if no model. WARN the

user it under-reports (floor, not ceiling).

Risk tier rule

  • HIGH — any DIRECT identifier survives (EMAIL, PHONE, URL, ID, PERSON).
  • MEDIUM — only QUASI identifiers survive (LOCATION, ORG, DATE, AGE, PROFESSION,

MEDICATION), or linkable pairs exist across files.

  • LOW — no surviving identifiers found (still NOT a guarantee).

How to run

# single redacted file (offline, deterministic)
python3 skills/red/scripts/red.py path/to/file.green.md

# a folder of redacted files (adds linkability)
python3 skills/red/scripts/red.py path/to/redacted_dir/

# add the local inference probe — synthetic/consented data ONLY
python3 skills/red/scripts/red.py path/to/file.green.md --inference

# machine-readable
python3 skills/red/scripts/red.py path/to/file.green.md --json

Output

A residual-risk report: per-file surviving-identifier counts by type, an overall

risk tier, the inference categories claimed (if probed), the **linkable-pair

count**, and the caveat that absence of a finding ≠ safety; human review still required.

No PII values, no re-identification steps.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。