0Pirate presents its published Python package as an AST-level code anonymizer and MCP proxy for frontier LLMs, potentially reducing source-code disclosure in hosted coding-agent workflows.
state: expiredheat: lowuncertainty: highknownscott: lowcode-privacy mcp-security ast-anonymization0Pirate
What is this?
The case presents 0Pirate as a published Python package combining AST-level code anonymization with an MCP proxy, intended to reduce source-code disclosure to hosted frontier LLMs. However, none of the supplied search-result snippets identifies 0Pirate or its maintainers; they discuss adjacent coding-agent, AST, and MCP tooling instead. The web answer repeats the claimed functionality, but the snippets do not substantiate package publication, provider support, implementation details, or privacy effectiveness, and the truncated initial-commit evidence title establishes no release timeline.
Why it matters to Scott
The claimed anonymization boundary repeats Scott’s existing inbound-airlock position in Separation of Powers for Cognition and his Privacy-tokenized agent boundary implementation pattern, though AST anonymization is not established as equivalent to vault-backed tokenisation. No radar hit tracks 0Pirate itself, but the supplied evidence establishes neither a consequential new adopter nor verified source-code protection or coding-accuracy results, so this remains an unverified example rather than a reason to change what Scott builds or argues.
ip:framework.separation-of-powers-for-cognitionip:concept.proxy-mediated-tokenisationdev:concept.privacy-tokenized-agent-boundaryradar:codex-private-repo-uploadradar:customhouse-mcp-exfiltration-proxyradar:concept.mcp-security
queries asked of Scott's wikis
- hosted coding agents source-code disclosure trust boundaries
- AST anonymization semantic preservation coding accuracy
- MCP proxies security controls tool data exposure
- coding harness outbound context filtering redaction
- local versus hosted inference proprietary code privacy
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (3) — ⭐ canonical anchor
Interpretation history
2026-09-10T22:37:12Z
The review horizon passed without substantive follow-up or an expected confirming event, leaving 0Pirate an unvalidated implementation lead rather than a demonstrated privacy boundary. Keyfence remains an adjacent project, not independent validation of 0Pirate; archive this episode without treating its claims as disproved.
2026-09-08T21:47:04Z
Keyfence adds an independent example of interest in local LLM-egress controls, not corroboration of 0Pirate’s AST anonymization or privacy effectiveness. Secret filtering and source-code anonymization protect different boundaries; the new announcement leaves 0Pirate an unvalidated implementation lead.
2026-09-08T19:24:38Z
evidence attached: hn.story.49615382 — A first-party local proxy for blocking secrets from LLM APIs independently reinforces the relevance of source and secret-egress controls in hosted agent workflows.
2026-09-08T07:33:08Z
No substantive new evidence changes the interpretation: 0Pirate remains an implementation lead, not a demonstrated privacy boundary for hosted coding agents. The reconstructed repository account adds architectural claims but is neither direct inspection nor independent validation of disclosure reduction or preserved coding accuracy.
2026-09-08T07:27:19Z
grounded: known/low — The claimed anonymization boundary repeats Scott’s existing inbound-airlock position in Separation of Powers for Cognition and his Privacy-tokenized agent bound
2026-09-08T07:24:28Z
origin walked (codex/luna, conf 0.92): anchor hn.story.49606267 -> echo.github.0142403cc5 by Arunmadhavan EVR
2026-09-08T07:22:45Z
case created — A linked PyPI package establishes a distinct, inspectable tooling episode, but the title alone does not establish a reliable privacy boundary.
Decision trace
- 09-11 08:37expireThe review horizon passed without substantive follow-up or an expected confirming event, leaving 0Pirate an unvalidated implementation lead rather than a demonstrated privacy boundary. Keyfence remain
- 09-11 08:37alert_silentThere is no new release, implementation result, adoption, or actionable change to surface. Expiration reflects a dormant evidence trail, not a verdict on the announced package or its effectiveness.
- 09-11 08:37alert_routeThere is no new release, implementation result, adoption, or actionable change to surface. Expiration reflects a dormant evidence trail, not a verdict on the announced package or its effectiveness.
- 09-09 07:47repriceKeyfence adds an independent example of interest in local LLM-egress controls, not corroboration of 0Pirate’s AST anonymization or privacy effectiveness. Secret filtering and source-code anonymization
- 09-09 07:47alert_silentThe Keyfence announcement establishes a separate tool-discovery event, but supplies no distinctive implementation result, adoption, or change to 0Pirate that would affect Scott’s decisions today. It c
- 09-09 07:47alert_routeThe Keyfence announcement establishes a separate tool-discovery event, but supplies no distinctive implementation result, adoption, or change to 0Pirate that would affect Scott’s decisions today. It c
- 09-09 05:26alert_silentKeyfence is newly presented as a local secrets-filtering proxy for LLM APIs, a separate project rather than a demonstrated advance in 0Pirate. The supplied announcement establishes the public presenta
- 09-09 05:26alert_routeKeyfence is newly presented as a local secrets-filtering proxy for LLM APIs, a separate project rather than a demonstrated advance in 0Pirate. The supplied announcement establishes the public presenta
- 09-09 05:24attachA first-party local proxy for blocking secrets from LLM APIs independently reinforces the relevance of source and secret-egress controls in hosted agent workflows.
- 09-09 05:24propose_attachA first-party local proxy for blocking secrets from LLM APIs independently reinforces the relevance of source and secret-egress controls in hosted agent workflows.
- 09-08 17:33repriceNo substantive new evidence changes the interpretation: 0Pirate remains an implementation lead, not a demonstrated privacy boundary for hosted coding agents. The reconstructed repository account adds
- 09-08 17:33alert_silentThis recheck adds no release, technical result, adoption, or actionable change beyond the previously assessed package availability. It can wait for routine review; the unresolved issue is protection e
- 09-08 17:33alert_routeThis recheck adds no release, technical result, adoption, or actionable change beyond the previously assessed package availability. It can wait for routine review; the unresolved issue is protection e
- 09-08 17:31alert_silentThe supplied evidence supports a public package and repository presenting AST anonymization and an MCP proxy, but the HN submission adds no consequential change beyond that availability. This is a rel
- 09-08 17:31alert_routeThe supplied evidence supports a public package and repository presenting AST anonymization and an MCP proxy, but the HN submission adds no consequential change beyond that availability. This is a rel
- 09-08 17:27groundThe claimed anonymization boundary repeats Scott’s existing inbound-airlock position in Separation of Powers for Cognition and his Privacy-tokenized agent boundary implementation pattern, though AST a
- 09-08 17:24promote_anchororigin walk conf 0.92
- 09-08 17:22createA linked PyPI package establishes a distinct, inspectable tooling episode, but the title alone does not establish a reliable privacy boundary.