152-FZ personal data anonymizer
mcp-152fz-anonymizer
An MCP server and HTTP API that find and mask personal data in text under Russia's 152-FZ before it reaches an LLM or an outside service
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Processes text containing sensitive personal data
- A network misconfiguration could expose the service externally
Install
Manual install
docker-compose up --build -dStarts the HTTP API on port 8005; the key goes into api_keys.json.
This is third-party code. Review the repository files before installing.
What it does
The service detects passports, SNILS, INN, bank cards, phone numbers, emails, IP addresses, geodata and over twenty other categories in text, using Microsoft Presidio with the spacy ru_core_news_lg model plus regex rules for Russian documents. Matches are replaced with placeholders like PERSON or PASSPORT_RF. It runs in two modes: as an MCP server for Claude Desktop and Cursor, or as a standalone FastAPI HTTP service for n8n and webhook integrations. It deploys in Docker as an unprivileged user with a read-only filesystem.
Who it is for. For developers and legal staff who need to strip customer personal data out of text before sending it to a cloud model or a third-party service.
Good fit when
- You need to strip names, passports and phone numbers before sending customer requests to a cloud LLM
- You need to anonymize logs or exports before handing them to a contractor
- You need automatic PII masking inside an n8n scenario or a webhook
Not a fit when
- You need a legal guarantee of full 152-FZ compliance: the tool reduces risk but is not a certified protection measure
- Data must never leave your perimeter at all: that needs a fully offline setup, not an MCP connection to a cloud agent
Example request
Anonymize this customer message before I send it for analysis: strip out the name, phone number and passport dataLimitations
Detection relies on regex and a spacy model, so misses and false positives are possible; results are worth spot-checking against real data. The service does not store processed data, but a misconfigured firewall could expose port 8005 externally. An API key is required for HTTP mode; the README does not document a separate key setup for MCP mode.
How to disable. Stop the container (docker-compose down) and remove the server from your MCP client config.
MCP
- Transport
- stdio
- Authentication
- not required
| Environment variables | |
|---|---|
| X-API-Key secret | HTTP API access key, set in api_keys.json; not documented for MCP mode. |
Security check
- Processes text containing sensitive personal data
- A network misconfiguration could expose the service externally
README in short
The Russian README with an English section shows the architecture as a diagram: a request goes through a proxy into a Docker container where FastAPI calls Presidio with a spacy model and regex rules. It gives a table of data categories with examples and replacements, a Docker quick start with a curl example, and separate instructions for local development in MCP mode. The security section lists container isolation, API-key-only access and no data logging.
FAQ
Does the server store the data it processes?
No, the README describes it as stateless: processed text is not logged or saved.
Which mode connects to Claude Desktop more easily?
MCP mode: install dependencies locally and run mcp run main.py, no Docker needed.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents