Brikko CLI: PII masking before LLM
brikko-cli
The official CLI for installing Brikko Studio and reversibly masking personal data before it reaches an LLM, with a local 152-FZ compliant proxy
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Proxies requests through api.brikko.ru and a local daemon reachable on 127.0.0.1
- Handling customer personal data requires trusting the masking logic and key storage
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/brikko-cliDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
npm install -g brikko-cliInstall the CLI with npm install -g brikko-cli, get a key at brikko.ru/app/keys, and use brikko safe-chat for chat with automatic masking, or brikko init for a full Studio install via Docker.
Other ways from the author
npm install -g brikko-cliGlobal CLI install.
This is third-party code. Review the repository files before installing.
What it does
The CLI installs and manages Brikko Studio (a local desktop AI agent with MCP) via docker compose: a single brikko init command starts the containers and opens the browser at localhost:3737. Separately, API commands talk directly to api.brikko.ru with no Studio needed: chat talks to an LLM through a smart router, anonymize masks personal data (INN, full names, and more) with placeholders and returns a mapping_id, restore returns the real data for that id, and safe-chat runs anonymize, chat and restore in one command. The brikko proxy command starts a local daemon on 127.0.0.1 compatible with the OpenAI API: existing OpenAI SDK code starts working through Brikko after changing only OPENAI_BASE_URL, with personal-data masking and restoration happening transparently, including for streaming responses.
Who it is for. For companies and developers who need to send LLM requests containing customer personal data without exposing that data to the model directly.
Good fit when
- You want to proxy existing OpenAI SDK code through a local daemon with automatic PII masking
- You need to mask text containing an INN and full names before sending it to a model and restore it in the response
- You want a CLI to install and update Brikko Studio instead of running docker compose by hand
Not a fit when
- You cannot run Docker Desktop or Docker Engine and spare 2 GB for images: Studio will not install without Docker
- You need on-the-fly audio masking: Whisper transcription is proxied without real-time masking
- You need multiple proxy ports at once: version 0.3 supports only one daemon per user
Example request
Mask this text with a customer's INN and full name, then draft a letter from it via safe-chatLimitations
Studio requires Docker and about 600 MB for the first image pull. API commands and the proxy need a paid BRIKKO_API_KEY from brikko.ru/app/keys. The proxy does not support WebSocket, it returns 501. brikko uninstall irreversibly removes containers, volumes and the install folder.
How to disable. Stop the daemon with brikko proxy stop, stop Studio's containers with brikko stop (data is kept), or remove everything with brikko uninstall --yes.
Security check
- Proxies requests through api.brikko.ru and a local daemon reachable on 127.0.0.1
- Handling customer personal data requires trusting the masking logic and key storage
README in short
The bilingual README describes three command groups: API commands for chat and masking without Studio, proxy commands for a local OpenAI-compatible daemon with on-the-fly masking, and Studio management commands via Docker. It shows examples for each group, a comparison table against the curl installer, known 0.3 limitations (one daemon per user, no WebSocket, no on-the-fly audio masking), and a list of related Brikko products: a browser extension, a skill for Claude Code and Cursor, and an n8n node.
FAQ
Does the model see real personal data?
No, with anonymize and safe-chat the model receives text with placeholders like <INN_1> and <NAME_1>; the CLI substitutes the real data back using the mapping_id.
Do I need to rewrite my code for Brikko?
Not for proxy mode: just change OPENAI_BASE_URL to the local daemon's address, and the rest of your OpenAI SDK code works unchanged.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents