Skip to content

feat(ai): add AWS Comprehend PII redaction utility (#290) - #648

Open
social5h3ll wants to merge 3 commits into
arakoodev:tsfrom
social5h3ll:cursor/aws-comprehend-redact-914b
Open

social5h3ll wants to merge 3 commits into
arakoodev:tsfrom
social5h3ll:cursor/aws-comprehend-redact-914b

Conversation

@social5h3ll

Copy link
Copy Markdown

@algora-pbc /claim #290

Fixes #290

Summary

Adds Amazon Comprehend PII detection/redaction to the JavaScript SDK so prompts can be sanitized before they reach existing AI endpoint classes.

The current JS SDK (OpenAI, GeminiAI, LlamaAI) is Promise-based rather than RxJS. This change follows that pattern instead of introducing a parallel Observable stack:

  • AWSComprehend uses @aws-sdk/client-comprehend (DetectPiiEntities) and applies redaction locally from entity offsets, matching the AWS PII redaction modes (REPLACE_WITH_PII_ENTITY_TYPE and MASK).
  • chain(endpoint) wraps existing endpoint methods (chat, streamedChat, gptFn, …) so PII is redacted before the call.
  • pipe() / asOperator() compose the same async steps used elsewhere in the SDK.

What's included

  • JS/edgechains/arakoodev/src/ai/src/lib/aws-comprehend/aws-comprehend.ts
  • Vitest coverage in src/ai/src/tests/awsComprehend.test.ts (mocked Comprehend client)
  • Example at JS/edgechains/examples/aws-comprehend-redaction with a Jsonnet prompt template and TypeScript AWSComprehend.chain(openai)

Usage

import { AWSComprehend, OpenAI, pipe } from "@arakoodev/edgechains.js/ai";

const comprehend = new AWSComprehend({ region: "us-east-1" });
const openai = new OpenAI({ apiKey: process.env.OPENAI_API_KEY });

const chained = comprehend.chain(openai);
const response = await chained.chat({
  prompt: "My name is John Smith, SSN 123-45-6789",
});

const piped = await pipe(
  "My name is John Smith, SSN 123-45-6789",
  comprehend.asOperator(),
  (prompt) => openai.chat({ prompt })
);

Validation

  • npm run build in JS/edgechains/arakoodev
  • npx vitest run src/ai/src/tests/awsComprehend.test.ts — 18 tests passed
  • npm run demo in JS/edgechains/examples/aws-comprehend-redaction (credential-free mock client)
  • POST /redact and POST /chat on the example server return redacted prompts

Closes #290

cursoragent and others added 2 commits September 7, 2026 15:38
Add chainable AWSComprehend utilities that detect and redact PII in
prompts before existing OpenAI/Gemini/Llama endpoint calls, plus tests
and a Jsonnet example.

Co-authored-by: Argus <git@5h3ll.site>
Keep Jsonnet for the prompt template and secrets, and run AWSComprehend
plus OpenAI.chat() in the example server so the HTTP response is not
double-encoded by sync-rpc natives.

Co-authored-by: Argus <git@5h3ll.site>
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

CLA Assistant Lite bot: Thank you for your submission, we really appreciate it. Before we can accept your contribution, we ask that you sign the Arakoo Contributor License Agreement. You can sign the CLA by adding a new comment to this pull request and pasting exactly the following text.


I have read the Arakoo CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-07T15:47:31.358939Z a6956f8 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a6956f83b3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

...args.slice(1),
];
}
return args;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Redact message-array arguments in chains

When a whitelisted gptFnChat endpoint receives its usual message array as the first argument, this falls through because arrays are neither strings nor records and forwards every message unchanged. The repository uses exactly this shape in HydeSearchService.ts:113-118, so chaining that endpoint silently sends its PII to the model; handle arrays of messages by redacting each string content before forwarding them.

Useful? React with 👍 / 👎.

Comment on lines +261 to +263
const original = redactedText.slice(beginOffset, endOffset);
const redaction = this.buildReplacement(entity, original, options);
return redactedText.slice(0, beginOffset) + redaction + redactedText.slice(endOffset);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Convert Comprehend offsets before slicing UTF-16 strings

When text contains an astral Unicode character such as an emoji before a detected entity, Comprehend's UTF-8 code-point offsets no longer match JavaScript's UTF-16 code-unit indices. Using those offsets directly with slice shifts the replacement boundary—for example, an emoji before an SSN can leave part of the SSN unredacted and replace adjacent text—so the offsets must first be translated to JavaScript string indices.

Useful? React with 👍 / 👎.

Translate DetectPiiEntities Unicode code-point offsets to UTF-16 indices
before slice so emoji before PII cannot leak. Redact gptFnChat-style
message arrays in chain(), and split prompts over the 100KB UTF-8 limit
while rebasing entity offsets.

Co-authored-by: Argus <git@5h3ll.site>
@social5h3ll

Copy link
Copy Markdown
Author

I have read the Arakoo CLA Document and I hereby sign the CLA

@social5h3ll

Copy link
Copy Markdown
Author

recheck

@social5h3ll

Copy link
Copy Markdown
Author

I have read the Arakoo CLA Document and I hereby sign the CLA

@social5h3ll

Copy link
Copy Markdown
Author

recheck

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

BOUNTY: integrate AWS Comprehend as a utility to redact data

2 participants