confide:setup
One-shot installer + optimal-default config writer for the CONFIDE local de-identification
toolkit. After running this, confide:anon (redact a transcript) and confide:red (residual
re-identification risk check) work with no further configuration.
Local-first: all detection and redaction run on the user's machine. Readiness checks and
config writing never read, print, or transmit any transcript text or PII — only booleans and
the config path.
When to use
Trigger phrasings: "set up confide", "install confide", "configure confide de-id",
"confide setup", "get confide ready to anonymize".
How to run
The entrypoint is scripts/setup.py. It imports the shared core (shared/confide_core.py)
for the canonical DEFAULTS — do not redefine preferences here.
Check readiness (default, no install):
python3 skills/setup/scripts/setup.py --check
Prints a ✓/✗ table: Python deps importable (natasha, scrubadub, phonenumbers, pymorphy2),
Ollama reachable (GET ollama_host/api/tags), the anon_model pulled, llama.cpp on PATH
(optional), and whether the config exists. Booleans only — no PII.
Install everything (best-effort, tolerates failures):
python3 skills/setup/scripts/setup.py --install # core deps + ollama pull
python3 skills/setup/scripts/setup.py --install --with-presidio # + optional EN baseline
- pip-installs:
natasha scrubadub phonenumbers pymorphy2 pymorphy2-dicts-ru "setuptools<81"
(setuptools<81 supplies pkg_resources for pymorphy2). Optional presidio-analyzer behind
--with-presidio.
- If
ollama is on PATH, runs ollama pull qwen2.5:3b.
- Each step reports ✓/✗; a failed step never aborts the others.
Write the optimal-default config (idempotent):
python3 skills/setup/scripts/setup.py --write-config # writes only if absent
python3 skills/setup/scripts/setup.py --reconfigure # overwrites with defaults
python3 skills/setup/scripts/setup.py --show # print current config
On first run with no config present, the script writes the defaults automatically.
--write-config will not clobber an existing (user-customized) config; use
--reconfigure to force-reset.
Config lives at ~/.config/confide/config.json.
Chosen optimal preferences (from SPEC.md)
Written from confide_core.DEFAULTS:
| Key |
Value |
Why |
engine |
ollama |
zero-config, Metal-accelerated, handles long docs (llama.cpp 400s on long RU) |
anon_model |
qwen2.5:3b |
fast local LLM layer for quasi-PII |
red_attacker_model |
qwen2.5:3b |
local default; it is a floor — a stronger attacker is the true ceiling |
languages |
["ru", "en"] |
bilingual corpus |
layers |
["regex", "natasha", "llm"] |
deterministic → RU NER → quasi-PII |
redaction_style |
typed_placeholder |
[PERSON], [DATE], … (reversible map kept locally, never shipped) |
privacy.local_only |
true |
raw text never leaves the machine |
privacy.cloud_apis |
false |
cloud disabled by default |
privacy.cloud_only_on_synthetic |
true |
cloud attacker only opt-in on synthetic/consented data |
ollama_host |
http://localhost:11434 |
local Ollama |
Notes
- llama.cpp is optional (reproducible engine) — detected and recorded if present, never required.
- The bigger attacker model for
confide:red is optional; the local 3b default under-reports risk.
- Importable functions for programmatic / tested use:
readiness(), ensure_config(reconfigure=False),
install(with_presidio=False), show_config().
1---2name: setup3description: Set up, install, and configure CONFIDE local de-identification — installs Python deps (natasha, scrubadub, phonenumbers, pymorphy2), ensures Ollama + pulls the default qwen2.5:3b model, detects optional llama.cpp, and writes the optimal-default config so confide:anon and confide:red work with zero further config. Everything is local-first; raw text never leaves the machine. Use when the user says "set up confide", "install confide", "configure confide de-id", "confide setup", or "get confide ready".4---5
6# confide:setup
7
8One-shot installer + optimal-default config writer for the CONFIDE local de-identification
9toolkit. After running this, `confide:anon` (redact a transcript) and `confide:red` (residual
10re-identification risk check) work with no further configuration.
11
12**Local-first:** all detection and redaction run on the user's machine. Readiness checks and
13config writing never read, print, or transmit any transcript text or PII — only booleans and
14the config path.
15
16## When to use
17Trigger phrasings: "set up confide", "install confide", "configure confide de-id",
18"confide setup", "get confide ready to anonymize".
19
20## How to run
21
22The entrypoint is `scripts/setup.py`. It imports the shared core (`shared/confide_core.py`)
23for the canonical `DEFAULTS` — do not redefine preferences here.
24
251. **Check readiness (default, no install):**
26 ```bash
27 python3 skills/setup/scripts/setup.py --check
28 ```
29 Prints a ✓/✗ table: Python deps importable (natasha, scrubadub, phonenumbers, pymorphy2),
30 Ollama reachable (`GET ollama_host/api/tags`), the `anon_model` pulled, llama.cpp on PATH
31 (optional), and whether the config exists. Booleans only — no PII.
32
332. **Install everything (best-effort, tolerates failures):**
34 ```bash
35 python3 skills/setup/scripts/setup.py --install # core deps + ollama pull
36 python3 skills/setup/scripts/setup.py --install --with-presidio # + optional EN baseline
37 ```
38 - pip-installs: `natasha scrubadub phonenumbers pymorphy2 pymorphy2-dicts-ru "setuptools<81"`
39 (`setuptools<81` supplies `pkg_resources` for pymorphy2). Optional `presidio-analyzer` behind
40 `--with-presidio`.
41 - If `ollama` is on PATH, runs `ollama pull qwen2.5:3b`.
42 - Each step reports ✓/✗; a failed step never aborts the others.
43
443. **Write the optimal-default config (idempotent):**
45 ```bash
46 python3 skills/setup/scripts/setup.py --write-config # writes only if absent
47 python3 skills/setup/scripts/setup.py --reconfigure # overwrites with defaults
48 python3 skills/setup/scripts/setup.py --show # print current config
49 ```
50 On first run with no config present, the script writes the defaults automatically.
51 `--write-config` will **not** clobber an existing (user-customized) config; use
52 `--reconfigure` to force-reset.
53
54Config lives at `~/.config/confide/config.json`.
55
56## Chosen optimal preferences (from SPEC.md)
57
58Written from `confide_core.DEFAULTS`:
59
60| Key | Value | Why |
61|---|---|---|
62| `engine` | `ollama` | zero-config, Metal-accelerated, handles long docs (llama.cpp 400s on long RU) |
63| `anon_model` | `qwen2.5:3b` | fast local LLM layer for quasi-PII |
64| `red_attacker_model` | `qwen2.5:3b` | local default; it is a **floor** — a stronger attacker is the true ceiling |
65| `languages` | `["ru", "en"]` | bilingual corpus |
66| `layers` | `["regex", "natasha", "llm"]` | deterministic → RU NER → quasi-PII |
67| `redaction_style` | `typed_placeholder` | `[PERSON]`, `[DATE]`, … (reversible map kept locally, never shipped) |
68| `privacy.local_only` | `true` | raw text never leaves the machine |
69| `privacy.cloud_apis` | `false` | cloud disabled by default |
70| `privacy.cloud_only_on_synthetic` | `true` | cloud attacker only opt-in on synthetic/consented data |
71| `ollama_host` | `http://localhost:11434` | local Ollama |
72
73## Notes
74- llama.cpp is **optional** (reproducible engine) — detected and recorded if present, never required.
75- The bigger attacker model for `confide:red` is optional; the local 3b default under-reports risk.
76- Importable functions for programmatic / tested use: `readiness()`, `ensure_config(reconfigure=False)`,
77 `install(with_presidio=False)`, `show_config()`.