← 返回 Skill 列表
extension
分类: 内容与媒体API Key 暂未确认

外发密盾

基于 OpenVINO 与 PP-OCRv4 在本地识别 PDF、扫描件和图片中的敏感信息,输出可审计的风险报告,并在不覆盖原文件的前提下生成脱敏副本。所有内容只在本机处理。

person作者: a18976231571hubModelScope

Local Doc Guardian

Quick start

Use the fixed entry point only:

scripts\run.ps1 "C:\path\to\document.pdf" --redact

Do not call client.py, server.py, or model files directly.

Workflows

Inspect a document

scripts\run.ps1 "C:\path\to\document.png"

Inspect and create a redacted copy

scripts\run.ps1 "C:\path\to\document.pdf" --redact

Return machine-readable JSON

scripts\run.ps1 "C:\path\to\document.pdf" --redact --format json

Check or stop the resident service

scripts\run.ps1 --health
scripts\run.ps1 --shutdown

Discover capabilities and local devices

scripts\run.ps1 --capabilities --format json
scripts\run.ps1 --devices --format json

--capabilities is a stable, machine-readable contract for Agent hosts. --devices probes the installed OpenVINO runtime without loading OCR models and reports the available local devices (for example CPU or GPU). OCR uses AUTO by default and falls back to CPU when a requested plugin is unavailable.

Interpreting the reply

The reply contains:

  • 风险等级: high, medium, low, or none.
  • 发现数量: validated findings grouped by severity and type.
  • 报告路径: Markdown and JSON reports with masked values only.
  • 脱敏副本: present only when --redact is requested.
  • 耗时: local processing time in milliseconds.
  • 建议: a risk-based next action for the Agent to present to the user.
  • 脱敏副本 SHA-256: an integrity digest for the newly generated artifact.
  • 源文件未改动: a post-run integrity check that the input digest is unchanged.

Failure handling

  • Exit 1: invalid input, unsupported file, or inference failure.
  • Exit 2: local service communication failure.
  • Exit 3: first-run setup is still in progress; rerun with --continue.
  • Never upload the input or fall back to a cloud OCR service.
  • If a result is uncertain, report it as requiring manual review; do not claim a file is safe merely because no pattern matched.

Important

  • The first call creates an isolated environment and may take several minutes.
  • All environments, models, caches, logs, and outputs stay under this skill directory.
  • Input files are capped at 50 MiB, policy JSON at 1 MiB, and PDFs at 100 pages with per-page and aggregate render budgets.
  • Pass --min-confidence 0.0..1.0 when a workflow needs a stricter or more permissive per-request OCR threshold.
  • Reports never include complete detected secrets or identity numbers.
  • Redaction creates a new file and never overwrites the source.