Skip to main content
Glama
ekaone

ekaone/mcp-tools

by ekaone

@ekaone/mcp-tools

Under Active Development

MCP (Model Context Protocol) server exposing @ekaone utility tools for AI-assisted data masking via stdio transport.

npm version License: MIT TypeScript

Tools

Tool

Package

Description

mask_card

@ekaone/mask-card

Masks credit/debit card numbers (PCI DSS compliant)

mask_email

@ekaone/mask-email

Masks email addresses for privacy protection

Related MCP server: postgres-safe-mcp

Usage

1. With MCP Clients (Windsurf, Cursor, VS Code, Claude Desktop)

Add this configuration to your MCP client:

{
  "mcpServers": {
    "masker": {
      "command": "npx",
      "args": [
        "@ekaone/mcp-tools@latest"
      ]
    }
  }
}

2. With Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "masker": {
      "command": "npx",
      "args": [
        "@ekaone/mcp-tools@latest"
      ]
    }
  }
}

Then just talk to Claude naturally:

"Hide all card numbers in this table"
"Mask the email john.doe@example.com"
"Show only last 4 digits of this card: 4532-1234-5678-9012"

3. Available Commands

Once connected, you can use these commands:

  • Mask email addresses: "Can you mask this email: user@domain.com?"

  • Mask card numbers: "Please mask this credit card: 4532-1234-5678-9012"

  • Custom masking: "Mask this card showing only first 4 digits: 4532-1234-5678-9012"

Tool Reference

mask_card

Parameter

Type

Required

Default

Description

value

string

Card number to mask

maskChar

string

*

Masking character

unmaskedStart

number

0

Digits visible at start

unmaskedEnd

number

4

Digits visible at end

Examples:

Input : "4532-1234-5678-9012"
Output: "************9012"

Input : "4532-1234-5678-9012", unmaskedStart: 4
Output: "4532********9012"

Input : "4532-1234-5678-9012", maskChar: "•"
Output: "••••••••••••9012"

mask_email

Parameter

Type

Required

Default

Description

email

string

Email address to mask

maskChar

string

*

Masking character

visibleChars

number

2

Characters visible at start

maskDomain

boolean

false

Also mask the domain

Examples:

Input : "john.doe@example.com"
Output: "jo******@example.com"

Input : "john.doe@example.com", visibleChars: 4
Output: "john**@example.com"

Input : "john.doe@example.com", maskDomain: true
Output: "jo******@e******.com"

Local Development

# Install dependencies
pnpm install

# Development with hot reload
pnpm dev

# Run tests
pnpm test

# Build for production
pnpm build

# Test the built package locally
pnpm start

Testing Locally

Test the MCP server locally:

# Build first
pnpm build

# Test stdio communication
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | node dist/index.js

Publishing

# Build and test before publishing
pnpm run prepublishOnly

# Publish to NPM
pnpm publish

Branch Structure

This repository has two main branches:

  • stdio (current branch) - For stdio MCP client usage (this README)

  • HTTP/SSE - For HTTP/SSE endpoint deployment

License

MIT © Eka Prasetia


⭐ If this library helps you, please consider giving it a star on GitHub!

Available Tools

2 tools
mask_cardA

Masks a credit or debit card number to protect sensitive payment information. Use when the user wants to hide, protect, or anonymize card numbers in a table, display, or logs. Supports Visa, Mastercard, Amex, Discover, JCB, and all major card types. Follows PCI DSS compliance by default (shows last 4 digits only).

ParametersJSON Schema
NameRequiredDescriptionDefault
valueYesThe card number to mask. Accepts formatted input like '4532-1234-5678-9012' or plain digits.
maskCharNoCharacter used for masking. Default is '*'.
unmaskedEndNoNumber of digits to keep visible at the end. Default is 4.
unmaskedStartNoNumber of digits to keep visible at the beginning. Default is 0.

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the burden of behavioral disclosure. It reveals PCI DSS compliance by default (last 4 digits only) and lists supported card types. However, it does not describe return behavior or error handling, leaving some ambiguity.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is four sentences long, with each sentence contributing distinct information: purpose, usage, supported types, and compliance. It is efficient and front-loaded with the primary action.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's simplicity and full schema coverage, the description covers purpose, usage, and key behavioral defaults. It does not explicitly describe the return value, but for a masking operation this is largely implied. Overall, it is sufficiently complete for an agent to use correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema provides 100% description coverage for all four parameters, so the description adds little beyond what the schema already states. The schema itself explains the value parameter accepts formatted input, so there is no additional semantic value from the description.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool masks credit/debit card numbers to protect sensitive payment information, using the specific verb 'masks' and resource. It distinguishes from sibling 'mask_email' by focusing on card types. The purpose is unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides clear usage context: 'Use when the user wants to hide, protect, or anonymize card numbers in a table, display, or logs.' However, it does not explicitly mention alternatives or exclusions, so it stops short of full guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

mask_emailA

Masks an email address to protect user privacy. Use when the user wants to hide, anonymize, or partially obscure email addresses in a table, UI, or logs. By default shows the first 2 characters of the username and keeps the domain visible.

ParametersJSON Schema
NameRequiredDescriptionDefault
emailYesThe email address to mask. Example: 'john.doe@example.com'.
maskCharNoCharacter used for masking. Default is '*'.
maskDomainNoIf true, also masks the domain part after @. Default is false.
visibleCharsNoNumber of characters to keep visible at the beginning of the username. Default is 2.

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the burden. It discloses default behavior: 'By default shows the first 2 characters of the username and keeps the domain visible.' This adds context not available in the schema, such as the exact masking behavior. It could be richer by describing output format or edge cases, but for a simple pure function it is adequate.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences long, the first stating the core purpose and the second conveying usage context and default behavior. Every word serves a purpose, with no redundancy or unrelated information. It is front-loaded with the action.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given that the tool is a simple string transformation with no output schema and no annotations, the description adequately covers purpose, usage, and defaults. It does not explicitly describe the return value or behavior for invalid input, but these are not critical for a straightforward masking function. The overall definition is sufficiently complete for an agent to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so all four parameters are documented with defaults and examples. The description's statement about default behavior (first 2 characters, domain visible) essentially re-states the schema defaults for visibleChars and maskDomain, adding no new parameter-level meaning. Hence, baseline is 3 with no additional value.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description begins with a specific verb and resource: 'Masks an email address to protect user privacy.' This clearly distinguishes it from the sibling tool mask_card by specifying the resource type (email address) and the action (masking).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides clear usage context: 'Use when the user wants to hide, anonymize, or partially obscure email addresses in a table, UI, or logs.' This tells the agent when to apply the tool, though it does not explicitly mention alternatives or exclusions. The sibling mask_card inferentially covers cards, so the usage boundary is clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 2 tool updatesv0.0.5
    • First observedmask_card
    • First observedmask_email

TDQS

A4.1/5.0
Disambiguation5/5

The two tools are clearly distinct: one masks credit/debit card numbers and the other masks email addresses. There is no overlap in their purposes.

Naming Consistency5/5

Both tools follow the same verb_noun pattern: mask_card and mask_email. The naming is consistent and predictable.

Tool Count3/5

With only two tools, the server feels somewhat thin. The count is borderline for the apparent purpose of data masking, though not excessively small.

Completeness2/5

The domain appears to be masking sensitive data, but only card and email are covered. Common types like phone numbers, SSNs, or IP addresses are missing, leaving notable gaps.

Maintenance

ActivityInactive
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    An MCP server that enables LLMs to detect and anonymize over 25 types of Personally Identifiable Information (PII) using Microsoft Presidio. It supports various redaction strategies and can process both plain text and structured data to help ensure data privacy.
    10
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    A PostgreSQL MCP server that automatically detects and obfuscates personally identifiable information (PII) in query results using column-name heuristics and NLP analysis. It enables AI agents to interact securely with databases by masking sensitive data by default while allowing selective unmasking under user control.
    4
    -
  • A
    license
    A
    quality
    B
    maintenance
    AI-powered sensitive info detection and masking MCP server supporting 14+ types with regex, checksum, and optional LLM semantic detection, enabling flexible masking strategies like mask, replace, hash, and redact.
    6
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    MCP server for automatic detection and redaction of PII in text, with anonymization and deanonymization capabilities, all local processing.
    1
    -

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/ekaone/mcp-tools'

If you have feedback or need assistance with the MCP directory API, please join our Discord server