glebis/red
>- Residual re-identification RISK CHECK on text you have ALREADY redacted (defensive, dual-use). Use when the user asks to "check residual re-id risk", "red-team my redaction", "what can an attacker still infer", "is this safe to share", or assess "re-identification risk" after anonymizing. Re-runs the CONFIDE detectors on the redacted output to surface surviving identifiers (singling-out), checks multiple files for linkability, and optionally probes a local model for still-inferable attribute CATEGORIES (inference) — mapped to GDPR Art-29. Reports risk categories/counts only,
npx skills add https://github.com/glebis/claude-skills --skill red
A defensive audit of YOUR OWN already-redacted output. It does not score against
ground truth and is not a benchmark. It surfaces, qualitatively, what an attacker could
still do — mapped to GDPR Art-29: singling-out, linkability, inference.
third-party / non-consented data, refuse.
re-identification recipe or guess the hidden values.
--inference)only on synthetic or explicitly consented data.
ceiling. Always tell the user human review is still required.
red *after* redacting, on the redacted file.detect_regex (+ detect_natasha if available) on the redacted text. Anything
they still find is a surviving identifier the redaction missed. Counts by type.
surviving quasi-identifiers and flag potentially linkable pairs (count + types only).
(cfg.red_attacker_model) for the attribute categories it could still infer
(profession, location type, age band, …). Degrades gracefully if no model. WARN the
user it under-reports (floor, not ceiling).
MEDICATION), or linkable pairs exist across files.
# single redacted file (offline, deterministic)
python3 skills/red/scripts/red.py path/to/file.green.md
# a folder of redacted files (adds linkability)
python3 skills/red/scripts/red.py path/to/redacted_dir/
# add the local inference probe — synthetic/consented data ONLY
python3 skills/red/scripts/red.py path/to/file.green.md --inference
# machine-readable
python3 skills/red/scripts/red.py path/to/file.green.md --json
A residual-risk report: per-file surviving-identifier counts by type, an overall
risk tier, the inference categories claimed (if probed), the **linkable-pair
count**, and the caveat that *absence of a finding ≠ safety; human review still required*.
No PII values, no re-identification steps.
Take glebis/red from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.