Two things go wrong with tools in this shape, and both of them end with nobody reading the output.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
# A catalogue with nothing personal in it: every value examined, nothing matched.
node bin/pii-discovery-report.mjs --dataset examples/clean/dataset.json
# exit 0, status "pass"
# The seeded corpus: seven fields of invented personal data, twelve without.
node bin/pii-discovery-report.mjs \
--dataset examples/seeded/dataset.json \
--config examples/seeded/config.json
# exit 1, status "fail"
# A partial export: one record is not an object and one value is over the limit.
node bin/pii-discovery-report.mjs \
--dataset examples/incomplete/dataset.json \
--config examples/incomplete/config.json
# exit 2, status "incomplete" -- and every field reported as undetermined,
# because a record nobody read could have held anything.Read the result
stdout carries the JSON report and nothing else, so it pipes straight into a parser. The human summary goes to stderr, and --json silences it.
Where this check stops
Each limit is enforced before the work it bounds. The file size is taken from the file system before any byte is read; the record, field and depth bounds stop the traversal rather than trimming its result; a value past maxValueLength is left unexamined rather than shortened, so a cut value is never classified as though it were whole; and maxRecords maxFields is checked against a cap of 2000000 field observations while the configuration is validated, before a file is opened.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.