See where personal data reaches your LLM prompts and logs.

“Summarise this customer” is one prompt away from sending their name, email, and phone number to a model provider, and logging all three on the way.

npx @neuralaxis/vibedoctor scan

What it looks like

It compiles. It ships. It’s wrong.

Every prompt is a transfer of data to a third party. Every log line is a copy you now have to retain, secure, and delete.

Neither shows up in a code review that only checks whether the feature works.

src/service.ts
console.log("processing user", user.email, user.phone);logger.info("customer payload", user);content: `Summarise account for ${user.name} email=${user.email}`return client.chat.completions.create({ model, messages });

Example: fixtures/dpdp/projects/llm-logs in the VibeDoctor repository.

What VibeDoctor reports

A ranked finding with the exact location.

  • Personal-data fields such as email, phone, address, date of birth, passport, Aadhaar, and PAN.
  • The scan and its results stay on your machine. Nothing is sent to a model to find this.
FindingSeverityEvidenceFrom
PII in LLM prompts or embeddings
Personal-data fields near chat.completions, Anthropic messages, embeddings, Pinecone, or vector-store calls.
critical observed DPDP-SEC-002
PII in application logs
Logger calls that include personal-data fields or whole user objects.
high observed DPDP-SEC-001
Whole user objects sent to third parties
A full user object passed to analytics, error-tracking, or LLM vendors.
high observed DPDP-THIRD-001
External processors and recipients inventory
Lists the LLM SDKs in use: OpenAI, Anthropic, Google, Cohere, Hugging Face.
info observed DPDP-PROC-001

Evidence grades say how sure the finding is. What verified, observed and heuristic mean →

How to fix it

  1. Send the model only what the task needs: an internal ID instead of a name, a redacted field instead of an email.
  2. Log IDs, not user objects.
  3. Record which providers receive personal data, then re-run the scan.

What this check can’t see

  • This is proximity, not data-flow tracing: a personal-data field close to a prompt call. Expect some findings you will dismiss.
  • It cannot see prompts built in another service or loaded from a database at runtime.

Fixing it, and the limits of this check

Run it

Check your repo now.

npx @neuralaxis/vibedoctor scan

Runs locally on JavaScript, TypeScript and Python repos. Hand the result to Cursor, Claude Code, Codex or Copilot with agent-plan. Agent setup →