Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add po4yka/llm-wiki-skills --skill llm-wiki-privacy-redactorgit clone --depth 1 https://github.com/po4yka/llm-wiki-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/po4yka/llm-wiki-skills/llm-wiki-privacy-redactor)<a href="https://agentmods.dev/skills/po4yka/llm-wiki-skills/llm-wiki-privacy-redactor"><img src="https://agentmods.dev/badge/skills/po4yka/llm-wiki-skills/llm-wiki-privacy-redactor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/po4yka/llm-wiki-skills/llm-wiki-privacy-redactor"><img src="https://agentmods.dev/badge/skills/po4yka/llm-wiki-skills/llm-wiki-privacy-redactor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00055 | $0.00587 |
| Opus 5 | $0.00028 | $0.00293 |
| Sonnet 5 | $0.00011 | $0.00117 |
| Haiku 4.5 | $0.00006 | $0.00059 |
Grade A, and why
llm-wiki-privacy-redactor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 99 lines — stays where its author put it; the contents beside it link to each section on GitHub.
LLM-Wiki Privacy Redactor
Goal
Prevent private content from leaking through public exports, model-boundary payloads or shared reports.
When to use
- Before exporting wiki pages, folders, or bundles to an external destination.
- Before sending LLM-Wiki context across a model boundary to a third-party LLM.
- When a page or raw source is tagged
privacy: sensitiveor marked internal. - When preparing a publishable report that may contain unreviewed generated claims.
- When a redaction policy file exists and must be applied before publication.
Inputs
- Target pages, folders or export bundle.
- Redaction policy file if present.
- Desired mode: preview-only or approved patch.
- Publication or model-boundary target.
Procedure
1. Load policy
Read references/docs/security/redaction-policy.md and references/templates/redaction-policy.yml when available, and re-verify the policy file is the current version before applying it, since redaction rules can change between publications.
2. Classify content
Flag:
- email addresses;
- phone numbers;
- internal URLs;
- secret-like strings;
- private tags;
- pages with
privacy: sensitive; - raw sources marked internal/sensitive;
- unreviewed generated claims in publishable output.
3. Preview redactions
Run or recommend:
node scripts/redact-preview.mjs <path>
Show redaction candidates without modifying files.
4. Propose replacements
Use stable placeholders:
[REDACTED_EMAIL]
[REDACTED_INTERNAL_URL]
[REDACTED_SECRET]
[REDACTED_PHONE]
5. Apply only after approval
Apply changes only to an export copy unless the user explicitly asks to patch the source wiki.
Output
## Redaction summary
## Files inspected
## Findings by category
## Proposed redactions
## Export safety decision
## Review required
Safety gates
- Do not print sensitive findings verbatim in final reports.
- Do not mutate source wiki files by default.
- Do not send sensitive content to external models without explicit approval.
- Do not treat redaction as proof that publication is safe.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 99 lines · 55 tokens per session scan A 46f9a0d94466
llm-wiki-privacy-redactor is a skill published in the GitHub repository po4yka/llm-wiki-skills (3 stars, last pushed 19d ago), licensed MIT. It adds 55 tokens to every session and 587 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
wiki-lint
Health-check a wiki vault. Finds orphan pages (no inbound links), dead wikilinks (point to non-existent pages), missing frontmatter fields, stale claims, empty sections, and pages absent from catalog.md. Produces a structured report with severity tiers and proposes concrete fixes — but does not auto-apply them unless…
save
File the current Claude conversation (or a specific insight from it) as a structured wiki note. Auto-detects the right type (decision, answer, session-log, technique, ADR), writes appropriate frontmatter, places the file in the correct wiki folder, and updates catalog.md, journal.md, hot.md. Use when the user says…
wiki-export
Export a vault's wiki either as a single portable file (llms.txt or llms-full.txt per the llmstxt.org standard) or as an OKF knowledge bundle (Google's Open Knowledge Format v0.1 — a shareable directory of markdown files any AI agent can consume). Use when the user says "export my wiki", "make an llms.txt", "share my…
wiki-query
Answer a question using ONLY the existing wiki vault as the knowledge base — no web search, no general LLM knowledge. Reads hot.md first (cheap recent context), then catalog.md to navigate, then drills into specific pages, then optionally semantic-searches the wiki, and synthesizes an answer with citations. Use when…
wiki-fold
Roll up the wiki's journal.md entries into structured fold pages — like 2^k log compaction. Reads the last 2, 4, 8, 16... entries and writes a fold page that summarizes them by extractive summarization (no invention), with backlinks to children. Idempotent at the structural level — re-running with the same window…
wiki
Bootstrap or check a Karpathy-style "LLM wiki" structure inside an Obsidian vault — a self-maintaining knowledge base where pages reference each other and the LLM keeps it tidy. Sets up catalog.md (curated page catalog), journal.md (append-only operation history), hot.md (recent-context cache), and overview.md…