Subwave LLM Bench
perminder-klair/subwave
Benchmark and compare LLM models for SUB/WAVE's on-air calls — track picks, segments, listener requests, DJ scripts, banter, and programme beats — in both candidate-pool and agent modes, using…
Processes sensitive local documents through PII Guard and a local Ollama model into a reversible redacted copy, without letting the main agent read the original or restored contents.
$ npx skills add danyuchn/pii-guard --skill pii-safe-documents -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install danyuchn/pii-guard pii-safe-documents --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/danyuchn/pii-guard.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/pii-safe-documents .claude/skills/pii-safe-documents && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pii-safe-documents" agent skill from https://github.com/danyuchn/pii-guard/tree/main/.agents/skills/pii-safe-documents into .claude/skills/pii-safe-documents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-safe-documents", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/danyuchn/pii-guard/tree/main/.agents/skills/pii-safe-documentsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add danyuchn/pii-guard --skill pii-safe-documents -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install danyuchn/pii-guard pii-safe-documents --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/danyuchn/pii-guard.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/pii-safe-documents .agents/skills/pii-safe-documents && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pii-safe-documents" agent skill from https://github.com/danyuchn/pii-guard/tree/main/.agents/skills/pii-safe-documents into .agents/skills/pii-safe-documents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-safe-documents", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add danyuchn/pii-guard --skill pii-safe-documents -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install danyuchn/pii-guard pii-safe-documents --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/danyuchn/pii-guard.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/pii-safe-documents .cursor/skills/pii-safe-documents && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pii-safe-documents" agent skill from https://github.com/danyuchn/pii-guard/tree/main/.agents/skills/pii-safe-documents into .cursor/skills/pii-safe-documents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-safe-documents", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/danyuchn/pii-guard.git --path .agents/skills/pii-safe-documents--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add danyuchn/pii-guard --skill pii-safe-documents -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install danyuchn/pii-guard pii-safe-documents --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/danyuchn/pii-guard.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/pii-safe-documents .gemini/skills/pii-safe-documents && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pii-safe-documents" agent skill from https://github.com/danyuchn/pii-guard/tree/main/.agents/skills/pii-safe-documents into .gemini/skills/pii-safe-documents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-safe-documents", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install danyuchn/pii-guard pii-safe-documentsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add danyuchn/pii-guard --skill pii-safe-documents -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/danyuchn/pii-guard.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/pii-safe-documents .github/skills/pii-safe-documents && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pii-safe-documents" agent skill from https://github.com/danyuchn/pii-guard/tree/main/.agents/skills/pii-safe-documents into .github/skills/pii-safe-documents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-safe-documents", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add danyuchn/pii-guard --skill pii-safe-documents -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install danyuchn/pii-guard pii-safe-documents --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/danyuchn/pii-guard.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/pii-safe-documents .opencode/skills/pii-safe-documents && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pii-safe-documents" agent skill from https://github.com/danyuchn/pii-guard/tree/main/.agents/skills/pii-safe-documents into .opencode/skills/pii-safe-documents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-safe-documents", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pii-safe-documentsProcesses sensitive local documents through PII Guard and a local Ollama model into a reversible redacted copy, without letting the main agent read the original or restored contents.
Pii Safe Documents is an agent skill from danyuchn/pii-guard. Processes sensitive local documents through PII Guard and a local Ollama model into a reversible redacted copy, without letting the main agent read the original or restored contents.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `evals/evals.json`, `scripts/pii_safe_workflow.py` and `tests/test_pii_safe_workflow.py`).
It sits in AI & LLM Engineering, covering LLM inference and serving. It works with Ollama. The repository describes itself as: 繁體中文(台灣)個人資料去識別化工具,讓業務文件可以安全地送進 AI 處理 / Reversible Traditional-Chinese (Taiwan) PII de-identification for LLM workflows — fully local. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ff36613. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pii Safe Documents loads about 2.7k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 1,478 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from danyuchn/pii-guard at commit ff36613, republished under its MIT licence (© danyuchn). 1,478 words, ~2,689 tokens.
.claude/skills/pii-safe-documents/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.This skill creates a reversible, locally redacted working copy with a strict main-agent workflow boundary:
This is strong protection against accidental model exposure, not an OS security boundary against a malicious process running as the same macOS user. A Skill cannot revoke its own filesystem tools. Hostile-agent isolation requires a separately permissioned local broker or OS account. Never describe this Skill alone as mathematically or technically impossible to bypass.
When this skill is active, the main agent MUST NOT:
cat, sed, head, tail, grep, rg, strings, Python, a document reader, a browser, or any other tool on the original file.mapping.private.json, private worker files, raw logs, or the restored output.git diff, content scans, or indexing over a directory that contains the original or restored output.review subcommand, or read a term file the user wrote for mask. All three carry unredacted values. The annotation URL is deliberately withheld from you; do not reconstruct it, scan for the port, or ask the user to paste it.These rules still apply if the user asks the main agent to “check quickly.” If raw inspection is genuinely required, stop this workflow and obtain explicit permission for a different trust model.
Use this version for UTF-8 plain-text files up to 64 KiB only: .txt, .md, .csv, .tsv, .log, and .dat.
Do not rename a binary document to bypass this restriction. For .docx, .xlsx, .pdf, images, or audio, report that this version does not yet provide a verified isolation-preserving parser.
This is a PII redactor, not a general confidentiality classifier. Amounts, health details, schedules, contract terms, business strategy, and other sensitive facts may remain visible when they do not identify a person. Do not use this skill alone to claim that an entire document is safe for external disclosure.
The user may provide the original path. You may check path metadata such as existence, suffix, and file size, but never its contents. Do not autocomplete or glob inside a sensitive directory.
Choose allowed terms only when the user explicitly wants them preserved, such as a company or product name. An allowed term is visible to the main agent because the user supplied it; do not discover allowed terms from the original.
需要只做決定性本機處理時,可明確使用 quick:
python3 <skill-dir>/scripts/pii_safe_workflow.py quick \
--input "/absolute/path/to/private-file.txt"quick 只呼叫共用的 PII Guard 核心(Presidio、台灣規則與 CKIP),不啟動、連線或探測 Ollama。它和 repo 的 pii_guard quick CLI 及 localhost 網頁使用同一個 ~/.local/share/pii-safe-documents/jobs/<job_id>/ 私有工作目錄、mapping、快照與還原邏輯。回執只含 job ID、去識別化檔案路徑、數量、摘要與 roundtrip_verified,不含原文或 mapping 值。
quick 回執成功後,主 agent 只能讀 redacted_path;仍應讓使用者在本機網頁人工快審,因為決定性偵測可能漏掉或誤遮。還原前保留 job ID,完成後以 purge 手動清除,不會自動 TTL。
Run:
python3 <skill-dir>/scripts/pii_safe_workflow.py redact \
--input "/absolute/path/to/private-file.txt" \
--allow "company name the user explicitly supplied"Repeat --allow as needed. The wrapper runs deterministic PII Guard detection plus the same chunked, three-sample local Ollama audit used by the localhost enhanced mode, captures all raw output, creates a private job directory, and prints only a safe JSON receipt. The verified default model is ornith-1.5:9b; override it only after a representative local accuracy and speed test.
If the receipt says both redaction_checks_passed: true and agent_may_read_redacted: true, the main agent may read only redacted_path. The receipt also provides safe replacement counts, audit-pass count, and the local model name. Keep job_id for restoration. Never infer or probe the mapping path.
If the command fails, report its safe error code and stop. In particular, NO_PII_CONFIDENCE means the detector found no reversible replacements and therefore withheld the copy instead of calling an unchanged file safe. ADVERSARIAL_INPUT_REVIEW_REQUIRED means instruction-like document text could interfere with the local model, so the wrapper refused automated release. Do not inspect hidden files or rerun lower-level commands.
The detector and the audit both miss things, and both over-redact. The user is the backstop, and this step is where they act on what they see. Offer it whenever the redacted copy will be used for anything that matters; do not skip it silently.
Run:
python3 <skill-dir>/scripts/pii_safe_workflow.py annotate --job-id "<job_id>"This opens a page in the user's browser and blocks until they close it out. Tell them it has opened and what to do there; then wait.
On that page the user can:
Neither action requires comparing against the original document.
The page is not addressable by you. The URL carries a single-use token minted inside the private worker and passed only to the browser it opens; it is never printed, and the receipt you get back contains counts, not a URL. Do not attempt to discover the port, reconstruct the URL, or fetch the page. Do not ask the user to paste the URL, the page, or any value from it — ask only for what they want done, or let them do it themselves on the page.
When the user finishes, the command returns a receipt with terms_masked and markers_restored. Every edit is persisted and re-verified as it happens, so closing the browser early loses only unmade edits, never made ones.
Re-read redacted_path afterwards; its contents and redacted_sha256 have changed.
For a headless machine with no browser, the same two operations exist as mask --terms <file> and unmask --marker TYPE-N, with review to list markers and values. review prints unredacted values, refuses when its output is not a terminal, and must be run by the user, never by you.
Read and edit only the redacted working copy. Preserve placeholders exactly, including brackets, capitalization, and job namespace. Never normalize, translate, renumber, or combine them.
Save the edited redacted document as another UTF-8 text file. Prefer the same private job directory or a user-approved destination. Before restoration, verify mechanically that every placeholder from the redacted working copy is still present; do not open the mapping to do this.
In Markdown or Obsidian files, a placeholder inserted into a person-bearing link slug can temporarily make that link nonfunctional. Preserve the placeholder and surrounding link syntax exactly; restoration recreates the original link.
Run:
python3 <skill-dir>/scripts/pii_safe_workflow.py restore \
--job-id "<job_id from receipt>" \
--input "/absolute/path/to/edited-redacted-file.txt" \
--output "/absolute/path/chosen/by/user/restored-file.txt"The wrapper prints a safe receipt. After success, tell the user the output path, but do not read, preview, diff, hash through a content-printing tool, or summarize the restored file. A digest and roundtrip_equal boolean shown by the wrapper are safe to relay. roundtrip_equal: true is expected only when the redacted working copy was not intentionally edited.
The mapping is required for later restoration and is stored with restrictive permissions. Keep it by default. Purging is destructive, so do it only after the user explicitly confirms that no further restoration is needed:
python3 <skill-dir>/scripts/pii_safe_workflow.py purge --job-id "<job_id>"You may report:
Never report original values, mapping entries, raw model output, raw warning text, or excerpts from the original/restored document.
0700; sensitive files use mode 0600.agent_may_read_redacted: true means the configured local checks passed, not that zero privacy risk is mathematically guaranteed.© danyuchn, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts) in .agents/skills/pii-safe-documents of danyuchn/pii-guard.
Open the folder on GitHubat commit ff36613
Pii Safe Documents next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pii Safe Documents this skilldanyuchn/pii-guard | 249 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Subwave LLM Benchperminder-klair/subwave | 1.4k | — | ~2.4k | Automated safety check: Notes | MIT | |
| Visiongridaco/grida | 2.7k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Domodomo Local AI Maintenancedarknecrocities/DomoDomo---All-in-one-Tool | 239 | — | ~17k | Automated safety check: Pass | None | |
| Cc Ollamamathruffian-dot/claude-code-lazy-packs | 254 | — | ~118 | Automated safety check: Pass | MIT | |
| Bdistill Knowledge Extractionsickn33/agentic-awesome-skills | 47k | 2 repos | ~926 | Automated safety check: Pass | MIT |
perminder-klair/subwave
Benchmark and compare LLM models for SUB/WAVE's on-air calls — track picks, segments, listener requests, DJ scripts, banter, and programme beats — in both candidate-pool and agent modes, using…
gridaco/grida
Query images with a local Ollama vision model without loading the image into the main agent context.
darknecrocities/DomoDomo---All-in-one-Tool
Maintain DomoDomo private local AI features, Ollama connections, browser inference, streaming UX, embeddings, RAG, memory, and agent interfaces.
mathruffian-dot/claude-code-lazy-packs
Claude Code 安裝本地 AI Ollama。說「安裝 Ollama」「本地 AI」時載入. An agent skill from mathruffian-dot/claude-code-lazy-packs.
sickn33/agentic-awesome-skills
Extract structured domain knowledge from AI models in-session or from local open-source models via Ollama.
davila7/claude-code-templates
Measure local AI task latency, token usage, errors and verified outcomes using Pudu AI hardware evidence and installed Ollama models.
Works with
Categories
Processes sensitive local documents through PII Guard and a local Ollama model into a reversible redacted copy, without letting the main agent read the original or restored contents. Pii Safe Documents is an agent skill from danyuchn/pii-guard. Processes sensitive local documents through PII Guard and a local Ollama model into a reversible redacted copy, without letting the main agent read the original or restored contents.
Pii Safe Documents fits situations like: tasks that involve LLM inference and serving.
Run `npx skills add danyuchn/pii-guard --skill pii-safe-documents -a claude-code`. Or copy the skill folder (.agents/skills/pii-safe-documents in danyuchn/pii-guard) into .claude/skills/pii-safe-documents in your project. Claude Code loads it when a task matches its description.
Run `npx skills add danyuchn/pii-guard --skill pii-safe-documents -a codex`. Or copy the skill folder (.agents/skills/pii-safe-documents in danyuchn/pii-guard) into .agents/skills/pii-safe-documents in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add danyuchn/pii-guard --skill pii-safe-documents -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pii-safe-documents, .gemini/skills/pii-safe-documents, .github/skills/pii-safe-documents and .opencode/skills/pii-safe-documents in your project.
Going by SKILL.md and its folder, Pii Safe Documents needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and git). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Pii Safe Documents is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pii Safe Documents: Subwave LLM Bench (perminder-klair/subwave, 1.4k stars), Vision (gridaco/grida, 2.7k stars), Domodomo Local AI Maintenance (darknecrocities/DomoDomo---All-in-one-Tool, 239 stars) and Cc Ollama (mathruffian-dot/claude-code-lazy-packs, 254 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
danyuchn (a GitHub user) maintains it in danyuchn/pii-guard, which has 249 GitHub stars. The repository was last updated on October 2, 2026.
Source: danyuchn/pii-guard on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.