Agent skill

Call Data Minimization Auditor

by CALLE-AI in CALLE-AI/awesome-phone-call-agents

Offline experimental CALL-E transcript helper that audits whether the agent requests only the personal data the goal file requires, flagging out-of-scope PII asks, redundant re-asks and full-datum…

MITAuto-check passed

Install Call Data Minimization Auditor

skills CLI
$ npx skills add CALLE-AI/awesome-phone-call-agents --skill call-data-minimization-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CALLE-AI/awesome-phone-call-agents call-data-minimization-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CALLE-AI/awesome-phone-call-agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/call-data-minimization-auditor .claude/skills/call-data-minimization-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
call-data-minimization-auditor
GitHub stars
107
Token cost
~1.8k tokens
SKILL.md length
901 words
Files
11 (incl. scripts, references)
Skills in repo
101
Repo updated
First seen
Licence
MIT

At a glance

Offline experimental CALL-E transcript helper that audits whether the agent requests only the personal data the goal file requires, flagging out-of-scope PII asks, redundant re-asks and full-datum…

  • Works in 3 steps: Regulation (EU) 2016/679 (GDPR), Article… → European Data Protection Board - "AI… → Ngong, Kadhe, Wang, Murugesan, Weisz,…
  • SKILL.md covers When To Use, What It Checks, Research Grounding and Limitations, plus 1 more section
  • Runs Python scripts from its folder; calls python3

What it does

Call Data Minimization Auditor is an agent skill from CALLE-AI/awesome-phone-call-agents. Offline experimental CALL-E transcript helper that audits whether the agent requests only the personal data the goal file requires, flagging out-of-scope PII asks, redundant re-asks and full-datum echo-backs, plus a minimal-collection goal template. It is not a legal determination, proof of unlawful collection, or authorization to act.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `references/example-transcript-overcollection.json`, `references/example-transcript-unverifiable.json` and `references/example-transcript.json`).

The repository describes itself as: Portable phone-call Agent Skills, apps, examples, adapters, and scheduler recipes for AI agents. The licence is MIT.

Example prompts

  • “/call-data-minimization-auditor”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Regulation (EU) 2016/679 (GDPR), Article 5(1)(c) - principle of data
  2. European Data Protection Board - "AI Privacy Risks & Mitigations -
  3. Ngong, Kadhe, Wang, Murugesan, Weisz, Dhurandhar, Natesan Ramamurthy -

What it can do on your machine

Read from SKILL.md and the folder at commit 38d4118. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • eur-lex.europa.eu
    • edpb.europa.eu

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Call Data Minimization Auditor loads about 1.8k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 901 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from CALLE-AI/awesome-phone-call-agents at commit 38d4118, republished under its MIT licence (© CALLE-AI). 901 words, ~1,778 tokens.

Download SKILL.mdSave it as .claude/skills/call-data-minimization-auditor/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
call-data-minimization-auditor
description
Offline experimental CALL-E transcript helper that audits whether the agent requests only the personal data the goal file requires, flagging out-of-scope PII asks, redundant re-asks and full-datum echo-backs, plus a minimal-collection goal template. It is not a legal determination, proof of unlawful collection, or authorization to act.
license
MIT

call-data-minimization-auditor

The goal file is the shopping list. The agent buys the list - nothing else, not twice, and never reads the numbers back in full.

Data minimization is the principle that a data collector asks for what the task needs and nothing more (GDPR Article 5(1)(c): "adequate, relevant and limited to what is necessary"). A calling agent that follows the principle in its goal file but drifts on the line - "while I have you, what is your date of birth?", re-asking a name it already captured, or repeating a full card number back "to confirm" - collects data the task never authorized, one polite sentence at a time.

On a phone call the risk compounds. The line is recorded, the transcript is stored, and every extra datum the agent elicits or repeats in full becomes another copy of sensitive personal data in another log. An agent that asks for two fields and repeats one masked is a smaller liability than one that asks for five and echoes a card number verbatim. This skill audits the agent's asks against the goal file's scope, lexically and offline.

When To Use

  • after any CALL-E call that collects personal data, together with the goal file (plain text or plan JSON) the call was built from
  • when a transcript shows the agent asking for data nobody put in the goal, re-asking for data the caller already gave, or reading a full card or ID number back instead of a masked confirmation
  • before placing calls, to craft a minimal-collection intake goal with an explicit fields list, a refusal line, a masking policy, and a no-re-asking rule

What It Checks

Verdicts
VerdictMeaning
MINIMALEvery agent data request is in the goal's scope, none redundant, no full-datum echo
OVERCOLLECTION_DETECTEDAt least one request is out of scope, redundant, or an echo of a full sensitive datum (attached to the request or listed under echoes)
NO_DATA_REQUESTEDThe agent made no lexically detectable data requests (callee volunteering never counts against it)
GOAL_FILE_LACKS_FIELD_LISTRequests exist but the goal file names no recognizable data categories; every request is unverifiable
The 14 categories
CategoryHigh sensitivity
full_name, date_of_birth, address, email, phone_number-
employer, income, relative_dob-
payment_card, bank_account, national_id, credentials, passport, drivers_licenseyes
Rules
  • Request: an agent sentence containing BOTH a category match (for example "card number", "date of birth", "where do you work") AND a request cue ("tell me", "verify", "can I have", "what's", "what is", ...). A category noun without a cue ("your card number is stored securely") is a statement, not a request. Callee turns are never scanned - what the caller volunteers is structurally never flagged.
  • Redundant re-ask: a new request for a category the callee already provided (by answer shape, or an explicit "I already gave you"), unless the agent's previous turn, another sentence in the same turn as the re-ask, or the re-ask sentence itself shows a hearing problem ("sorry, I didn't catch that", "couldn't hear", "one more time", "louder"). Politeness sorry ("sorry to bother you again") does not excuse a re-ask.
  • Echo-back: an agent turn repeating a 7+-digit run whose digit content the callee already gave - whether the agent asked for it or the callee volunteered it. The category is inferred from the digit-run shape (4 groups of 4 or 13-19 digits = payment_card, 9 digits = national_id, anything else = unknown_number); an unrecognized shape is still reported. The agent should confirm masked (last two digits), not in full. When a request entry exists the echo lands on it with the echoing turn and sentence; when the number was volunteered with no request, the finding is listed under a top-level echoes key instead. Echo flags even when the category is in scope.
Show full SKILL.md (292 more words)Show less

Research Grounding

  1. Regulation (EU) 2016/679 (GDPR), Article 5(1)(c) - principle of data minimisation: "adequate, relevant and limited to what is necessary" - https://eur-lex.europa.eu/eli/reg/2016/679/oj
  2. European Data Protection Board - "AI Privacy Risks & Mitigations - Large Language Models (LLMs)" (published 2025-04-10, Support Pool of Experts report, Isabel Barbera; recommends input validation and filters to prevent over-collection of data) - https://www.edpb.europa.eu/documents/support-pool-of-experts/ai-privacy-risks-mitigations-large-language-models-llms_en
  3. Ngong, Kadhe, Wang, Murugesan, Weisz, Dhurandhar, Natesan Ramamurthy - "Protecting Users From Themselves: Safeguarding Contextual Privacy in Interactions with Conversational Agents" - Findings of ACL 2025 - arXiv:2502.18509

Limitations

  • The goal file is the only ground truth for scope; a category the goal omits may still be lawful to collect, and findings route to review, never to automated action.
  • Category detection is lexical: paraphrases outside the lexicon ("your nine digits", "the code on the back") are missed; "account number" may over-trigger bank_account. Standalone "security code" outside a payment context (a gate or door code) is not treated as card data.
  • Elliptical questions ("And your date of birth?") count as requests via their question mark; agent rhetorical questions mentioning a category ("Why would I need your card number?") can also match.
  • The re-ask excuse is lexical ("sorry, I didn't catch that", "couldn't hear"); a genuine audio failure phrased differently still flags as redundant, and politeness sorry never excuses.
  • A JSON goal object carrying none of the seven recognized keys (goal/task/objective/required/required_fields/needed/ fields) yields an empty scope, so any request verdicts GOAL_FILE_LACKS_FIELD_LIST.
  • Lowercased transcripts weaken provided-detection that relies on a capitalized given name; digit-, email- and date-shape detection are unaffected.
  • English-only; ASCII transcripts.
  • The skill audits the AGENT's asks, never what the callee volunteers.

Usage

bash
python3 scripts/data_minimization_auditor.py analyze \
  --transcript path/to/call-result.json --goal-file path/to/goal.txt
bash
python3 scripts/data_minimization_auditor.py craft --scenario minimal-intake

See references/examples.md for byte-real runs and references/safety.md for data-handling policy. The goal file is plain text or a JSON object whose goal/task/objective/required/ required_fields/needed/fields values define the scope.

© CALLE-AI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts, references) in skills/call-data-minimization-auditor of CALLE-AI/awesome-phone-call-agents.

  • SKILL.md
  • references/example-goal-unverifiable.txt
  • references/example-goal-vague.txt
  • references/example-goal.txt
  • references/example-transcript-overcollection.json
  • references/example-transcript-unverifiable.json
  • references/example-transcript.json
  • references/examples.md
  • references/safety.md
  • scripts/data_minimization_auditor.py
  • scripts/test_data_minimization_auditor.py

Open the folder on GitHubat commit 38d4118

Compare with similar skills

Call Data Minimization Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Call Data Minimization Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Call Data Minimization Auditor this skillCALLE-AI/awesome-phone-call-agents107—~1.8kAutomated safety check: PassMIT
Audit Trail Helperjeremylongshore/tons-of-skills-marketplace2.8k—~565Automated safety check: PassMIT
Hipaa Audit Helperjeremylongshore/tons-of-skills-marketplace2.8k—~565Automated safety check: PassMIT
Audit Preparationsickn33/agentic-awesome-skills47k1 repos~5.3kAutomated safety check: PassMIT
Minimalismsickn33/agentic-awesome-skills47k1 repos~2.2kAutomated safety check: PassMIT
Production Auditaffaan-m/ECC276k1 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Audit Trail Helper

    jeremylongshore/tons-of-skills-marketplace

    Audit Trail Helper - Auto-activating skill for Enterprise Workflows.

    2.8k GitHub stars~565 tokensUpdated today
    Auto-check passed
  • Hipaa Audit Helper

    jeremylongshore/tons-of-skills-marketplace

    Assist with hipaa audit helper operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~565 tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Audit Preparation

    sickn33/agentic-awesome-skills

    Audit preparation register: required document, period covered, request and receipt dates, preparer and reviewer, auditor queries and adjustments.

    47k GitHub starsUsed in 1 repo~5.3k tokens
    Legal & ComplianceAuto-check passed
  • Minimalism

    sickn33/agentic-awesome-skills

    Web and App implementation guide for the Minimalism design style.

    47k GitHub starsUsed in 1 repo~2.2k tokens
    MobileAuto-check passed
  • Production Audit

    affaan-m/ECC

    Local-evidence production readiness audit for shipped apps, pre-launch reviews, post-merge checks, and "what breaks in prod?" questions without sending repo data to an external audit service.

    276k GitHub starsUsed in 1 repo~1.9k tokens
    Product & Project ManagementAuto-check passed
  • Baoyu Youtube Transcript

    JimLiu/baoyu-skills

    Downloads YouTube video transcripts/subtitles and cover images by URL or video ID.

    27k GitHub starsUsed in 1 repo~2.4k tokens
    Media & CreativeAuto-check passed

More from CALLE-AI/awesome-phone-call-agents

All 101 skills in this repo
  • Accessible Outing Verifier

    CALLE-AI/awesome-phone-call-agents

    Demonstrates advisory accessibility-planning checks with offline fixtures and a proposed bounded CALL-E workflow; use for exploring unknown or qualified venue claims without making calls.

    107 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Ground Truth Gate

    CALLE-AI/awesome-phone-call-agents

    A skill your agent uses when an agent holds some evidence for a physical-world claim but the evidence is broader, narrower, or older than the exact question asked, and it must first decide whether a…

    107 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Is It Accessible

    CALLE-AI/awesome-phone-call-agents

    Call a venue and ask the accessibility questions that matter to one specific person — step-free entry, hearing loop, guide dogs, quiet hours, changing places — then return a per-need verdict backed…

    107 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Landmark Navigation Assist

    CALLE-AI/awesome-phone-call-agents

    Turns a pre-written, building-level location config into a CALL-E outbound phone-call task that guides a delivery driver through the last few hundred metres to a specific building using landmarks…

    107 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Research Gap Call Verifier

    CALLE-AI/awesome-phone-call-agents

    Turn cited business research into a bounded, approval-gated phone-call plan that asks only unresolved factual questions, then reconcile CALL-E-compatible results without treating voicemail, refusal…

    107 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Structured Outcome Followup Call

    CALLE-AI/awesome-phone-call-agents

    Place a goal-driven CALL-E call that collects specific structured answers, score those answers against a deterministic rubric you supply, and conditionally trigger a follow-up action — all runnable…

    107 GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Questions about Call Data Minimization Auditor

What does Call Data Minimization Auditor do?

Offline experimental CALL-E transcript helper that audits whether the agent requests only the personal data the goal file requires, flagging out-of-scope PII asks, redundant re-asks and full-datum…. Call Data Minimization Auditor is an agent skill from CALLE-AI/awesome-phone-call-agents. Offline experimental CALL-E transcript helper that audits whether the agent requests only the personal data the goal file requires, flagging out-of-scope PII asks, redundant re-asks and full-datum echo-backs, plus a minimal-collection goal template.

How do I install Call Data Minimization Auditor in Claude Code?

Run `npx skills add CALLE-AI/awesome-phone-call-agents --skill call-data-minimization-auditor -a claude-code`. Or copy the skill folder (skills/call-data-minimization-auditor in CALLE-AI/awesome-phone-call-agents) into .claude/skills/call-data-minimization-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Call Data Minimization Auditor in Codex?

Run `npx skills add CALLE-AI/awesome-phone-call-agents --skill call-data-minimization-auditor -a codex`. Or copy the skill folder (skills/call-data-minimization-auditor in CALLE-AI/awesome-phone-call-agents) into .agents/skills/call-data-minimization-auditor in your project. Codex loads it when a task matches its description.

Can I use Call Data Minimization Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CALLE-AI/awesome-phone-call-agents --skill call-data-minimization-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/call-data-minimization-auditor, .gemini/skills/call-data-minimization-auditor, .github/skills/call-data-minimization-auditor and .opencode/skills/call-data-minimization-auditor in your project.

What does Call Data Minimization Auditor need to run?

Going by SKILL.md and its folder, Call Data Minimization Auditor needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Call Data Minimization Auditor access the network?

SKILL.md names 2 domains. As links in the text: eur-lex.europa.eu and edpb.europa.eu. This is read from the text; nothing was executed.

Is Call Data Minimization Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Call Data Minimization Auditor use?

Call Data Minimization Auditor is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Call Data Minimization Auditor use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.

What are the alternatives to Call Data Minimization Auditor?

Skills that share tags, products or a category with Call Data Minimization Auditor: Audit Trail Helper (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Hipaa Audit Helper (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Audit Preparation (sickn33/agentic-awesome-skills, 47k stars) and Minimalism (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Call Data Minimization Auditor?

CALLE-AI (a GitHub organization) maintains it in CALLE-AI/awesome-phone-call-agents, which has 107 GitHub stars. The repository holds 101 skills in this directory. The repository was last updated on October 10, 2026.

Source: CALLE-AI/awesome-phone-call-agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.