Skip to content
Aarav Jain
All work

Independent project, May – Jun 2026

MCP-DLP

Agents that can’t leak.

1 min read

My role
Solo
Where
Independent project
When
May – Jun 2026
Stack
  • Python
  • FastMCP
  • pytest

Try to leak something.

Try to leak something

All 11 rules from scanner.py, running in your browser

What the agent gets back

Ship to Jane Doe, [REDACTED_EMAIL], SSN [REDACTED_SSN], card [REDACTED_CREDIT_CARD]. Thanks!

Each finding becomes its scanner.py label. The rest passes through.

Verdict

Redact

3 findings: CREDIT_CARD, EMAIL, SSN

Audit log

Append-only

    Runs entirely in your browser. Nothing you type leaves this page.

    The rulesPorted in order. On overlap the earlier rule wins, so the SECRET catch-all goes last.
    RuleTypeActionHits
    EMAILPIIRedact1
    PHONEPIIRedact0
    PHONE_BARElowPIIRedact0
    SSNPIIRedact1
    SSN_BARElowPIIRedact0
    CREDIT_CARDPIIRedact1
    BEARER_TOKENCredentialBlock0
    API_KEYCredentialBlock0
    AWS_ACCESS_KEYCredentialBlock0
    PRIVATE_KEYCredentialBlock0
    SECRETCredentialRedact0

    Only high-confidence credentials block. SECRET is a fuzzy keyword match, so it redacts instead. Rules marked low are low-confidence guesses.

    1. The problem

      Preflop

      Agents wired into Drive, Slack and Notion can pass a document’s SSNs, card numbers and API keys straight to a model.

    2. The approach

      Flop

      An MCP server that sits between the connector and the agent: scan on read, then allow, redact, or block.

    3. The hard part

      Turn

      The raw text never leaves the function. Only the redacted result or a block message is returned, and every read is written to an append-only audit log.

    4. What shipped

      River

      11 PII and credential rules, label-preserving redaction, hard blocks on high-confidence credentials.

    The result, or as poker players say, the showdown

    24-test pytest suite, end to end.