// the find
badlogic/pi-share-hf
Collect, review, and upload redacted pi session files to a Hugging Face dataset
A CLI from the pi.dev author for publishing redacted pi coding-agent session logs to a Hugging Face dataset. It runs each session through literal-secret redaction, a deny-pattern filter, a TruffleHog scan, and an LLM review before anything gets uploaded. Useful if you run pi and want to share real traces publicly without hand-scrubbing every file, but it's built for one specific session format, not a general agent-log sanitizer.
The redaction pipeline is layered rather than relying on one mechanism: exact-match redaction for known secrets, TruffleHog as a backstop for secret patterns the exact-match step missed, and an LLM pass for sensitive context (project names, counterparties) that isn't a 'secret' in any regex sense. The workspace is properly incremental — review results are cache-keyed on content hash plus provider/model/thinking/prompt-version, so changing a flag doesn't force a full reprocess of untouched sessions. `list --uploadable`, `grep`, and `upload --dry-run` give you a real look-before-you-leap step instead of trusting the automated checks blindly. Shipping its own TS Hugging Face client avoids pulling in the Python `huggingface-cli` just for upload.
It's narrowly coupled to pi's own session JSONL format, so there's no path to reusing it for Claude Code, Cursor, or other agent logs without rewriting the parser. The security story has a real gap baked into the design: deterministic redaction only strips secrets you remember to list, TruffleHog only scans what's left after that (not the raw file), and the LLM review is a judgment call, not a guarantee — three partial nets stacked on top of each other, which the README is honest about but which still means a forgotten secret can make it past all three if you're unlucky. There's no visible test suite in the repo despite this being exactly the kind of tool where a redaction regression should be caught by CI, not by someone grepping the uploadable set after the fact. TruffleHog is an external binary dependency (brew on macOS, manual install elsewhere) rather than bundled, which is one more thing that can be stale or missing when you run `collect`.