Skip to content
Back to skills

Sensitive Data

BSecurity

MUST activate when you suspect, there is a slight chance, encounter, read, process, or are about to output any sensitive or possibly sensitive data including PII, PCI, HIPAA, PHI, GDPR, SOC2, FedRAMP, secrets, API keys, passwords, credentials, tokens, certificates, or any sensitive data. Follow compliance/regulations.

  • 352 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 3, 2026
ai-agentsgosqlawsgitapi

Works with

  • cli
  • api

Security analysis

B75/100
  • criticalReads or references SSH private keys

Pro scans all 2 files and shows the line behind each finding

Scanned September 3, 2026

npx -y skills add griddynamics/rosetta --skill sensitive-data --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sensitive Data?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Sensitive Data
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/griddynamics-sensitive-data-0505fee9/badge)](https://www.skillsdirectory.com/skills/griddynamics-sensitive-data-0505fee9)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: sensitive-data
description: "MUST activate when you suspect, there is a slight chance, encounter, read, process, or are about to output any sensitive or possibly sensitive data including PII, PCI, HIPAA, PHI, GDPR, SOC2, FedRAMP, secrets, API keys, passwords, credentials, tokens, certificates, or any sensitive data. Follow compliance/regulations."
---

<sensitive_data>

<process>

1. DO NOT read, query, store, tell, write, log, or distribute any SENSITIVE information (PII, PCI, HIPAA, PHI, GDPR, SOC2, FedRAMP, Secrets, etc)
2. IF encountered - report without exposing raw value
3. IF needed as-is - MUST ask explicit user approval first
4. User may override (mocked data)
5. NEVER output, echo, print, log, summarize, or reference the raw value of any sensitive data in chat or in any file
6. MASK immediately using `[REDACTED:<type>]` (e.g. `[REDACTED:API_KEY]`, `[REDACTED:PASSWORD]`)
7. Scan information of your output or artifacts for: `Bearer `, `Authorization:`, `password:`, `api_key=`, `client_secret`, `eyJ` (JWT), `AKIA` (AWS key), `ghp_`/`gho_`/`github_pat_` (GitHub), `xox[baprs]-` (Slack), `BEGIN PRIVATE KEY`, `BEGIN RSA PRIVATE KEY`, `BEGIN OPENSSH PRIVATE KEY`, `postgresql://user:pass@`, `mongodb+srv://user:pass@`; plus emails outside `example.com`/`example.org`, phones outside the `+1-555-01xx` reserved range, card-number shapes `\d{4}[\s\-]\d{4}[\s\-]\d{4}[\s\-]\d{4}`, and real customer names alongside any of the above. This list is a **non-exhaustive floor** -- redact any secret-shaped token even if unlisted. Fail-closed -- if the scan cannot run, do not emit
8. Use IETF reserved ranges for PII placeholders: emails `test.user-1@example.com`; phones `+1-555-0100`–`+1-555-0199`; official PSP test cards (cite source)

</process>

<coding>

- DO NOT read, query, store, tell, write, log, or distribute any SENSITIVE information
- Identify and apply respective guidance for handling data like that
- Guide user for correct implementation 

</coding>

<pitfalls>

- Echoing secrets in summaries or diffs.
- Logging sensitive data to AGENT MEMORY.md.

</pitfalls>

</sensitive_data>

Files in this skill

  • README.md7.2 KB
  • SKILL.md2.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…