Show HN: I told Claude Code never to reveal my secrets. It sent 3 of 4 anyway PrivAiTe, a self-hosted PII redaction proxy for LLM APIs, reports that in a test session Claude Code sent 3 of 4 secrets to its provider despite instructions not to, with 23 of 24 planted values reaching the provider overall; through PrivAiTe's agent gateway, only 2 of 24 leaked. The open-source tool, available via Docker and pip, intercepts and replaces personal data before it reaches the model provider, including inside tool-call arguments and multimodal content, and runs locally with zero telemetry. Self-hosted PII redaction proxy for LLM APIs. A drop-in LLM proxy that replaces PII before it reaches the provider, including inside tool-call arguments and multimodal content, with zero telemetry. Told in writing to report its config variables but never their values , Claude Code sent 3 of 4 secrets to its provider anyway: the same secrets also sat in a log file the task had it read. Over that session 23 of 24 planted values reached the provider; through PrivAiTe's agent gateway, 2 of 24 . Wire-level captures of real agent sessions, and the two that still get through are documented rather than rounded away: the measurement https://github.com/crp4222/PrivAiTe/blob/main/docs/agent-leak-measurement.md , what it misses https://github.com/crp4222/PrivAiTe threat-model . You type: "Je m'appelle Marie Dupont, email marie@acme.com" LLM sees: "Je m'appelle