Agent skill

Data Protection And Encryption

by cbrock84 in cbrock84/headcount

Protects data itself rather than the systems around it — classifying what you hold, encrypting in transit and at rest and understanding what each actually defends against, managing keys and their…

MITAuto-check passedLegal & Compliance

Install Data Protection And Encryption

skills CLI
$ npx skills add cbrock84/headcount --skill data-protection-and-encryption -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cbrock84/headcount data-protection-and-encryption --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cbrock84/headcount.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/security/skills/data-protection-and-encryption .claude/skills/data-protection-and-encryption && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
data-protection-and-encryption
GitHub stars
2k
Token cost
~1.3k tokens
SKILL.md length
678 words
Files
2 (incl. references)
Skills in repo
178
Repo updated
First seen
Licence
MIT

At a glance

Protects data itself rather than the systems around it — classifying what you hold, encrypting in transit and at rest and understanding what each actually defends against, managing keys and their…

  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Classify before you protect,…, Know what each kind of…, Keys are the whole control and Secrets are the credential…, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Cryptography

What it does

Data Protection And Encryption is an agent skill from cbrock84/headcount. Protects data itself rather than the systems around it — classifying what you hold, encrypting in transit and at rest and understanding what each actually defends against, managing keys and their rotation, handling secrets in applications and pipelines, minimizing and de-identifying, and deleting on purpose. Use this to design data protection for a system, assess an encryption claim, set up key or secret management, or work out what a stolen backup would actually expose.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/sources.md`).

It sits in Legal & Compliance, covering Privacy and GDPR, Cryptography and Secrets management. The repository describes itself as: An agent organization structured as a company — 15+ departments, 125+ skills, each independently installable, citing the standards and regulators that settle the question. Runs… The licence is MIT.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Cryptography
  • Tasks that involve Secrets management

Example prompts

  • “Use the data-protection-and-encryption skill to protect data itself rather than the systems around it — classifying what you hold, encrypting in…”
  • “/data-protection-and-encryption”

What it can do on your machine

Read from SKILL.md and the folder at commit 98d1c17. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Data Protection And Encryption loads about 1.3k tokens when it runs, and up to ~1.7k if it reads all its reference files. Until then it costs about 127 tokens; SKILL.md has 678 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~127
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cbrock84/headcount at commit 98d1c17, republished under its MIT licence (© cbrock84). 678 words, ~1,266 tokens.

Download SKILL.mdSave it as .claude/skills/data-protection-and-encryption/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
data-protection-and-encryption
description
Protects data itself rather than the systems around it — classifying what you hold, encrypting in transit and at rest and understanding what each actually defends against, managing keys and their rotation, handling secrets in applications and pipelines, minimizing and de-identifying, and deleting on purpose. Use this to design data protection for a system, assess an encryption claim, set up key or secret management, or work out what a stolen backup would actually expose.

Data protection and encryption

Perimeter and identity controls protect access to data. These controls protect the data when those have already failed, which is the scenario worth designing for.

Classify before you protect, because you cannot protect everything equally

A short scale beats a detailed one — three or four levels that people can apply without a manual. What matters is that each level carries concrete handling rules: where it may be stored, who may access it, whether it may leave the environment, and how long it is kept.

Find it before you classify it. Sensitive data is rarely only where the architecture says it is: it accumulates in exports, analytics environments, test databases seeded from production, support tickets, and log files.

Know what each kind of encryption actually defends against

This is where claims get made loosely and expectations diverge from reality.

  • In transit protects against interception on the network. Enforce it everywhere, including internal service-to-service traffic, and prefer a modern configuration over one accumulated over years.
  • At rest, provider-managed protects against physical media theft and disk disposal. It does not protect against an application bug, a compromised credential, or an over-broad query — the storage layer decrypts transparently for anything with legitimate access. Full-disk encryption on a running server protects almost nothing about that server.
  • Application-level or field-level protects specific fields from anything below the application, including database administrators and backups. It costs you searchability and indexing on those fields, which is a real design constraint rather than a footnote.

Choose deliberately. "Encrypted at rest" as a blanket assurance usually means the first of these, and answers far less than the person asking believes.

Keys are the whole control

Encryption moves the problem to key management; it does not remove it. A key stored beside the data it protects provides documentation, not protection.

  • Use a managed key service or hardware-backed store. Keys in configuration files, environment variables committed to a repository, or application code are the common real-world failure.
  • Separate duties so the people who administer the data are not the people who administer the keys.
  • Plan rotation before you need it, including how you re-encrypt existing data. Rotation nobody has practiced is a policy, and the moment you need it is after a suspected exposure.
  • Know what key destruction means. Deleting a key makes the data unrecoverable, which is either a deletion mechanism you designed for or an outage you did not.
Show full SKILL.md (275 more words)Show less

Secrets are the credential case of the same problem

Application secrets — database passwords, API keys, service tokens — belong in a secret manager, injected at runtime, scoped narrowly, and rotated on a schedule and on staff departure.

Scan for committed secrets in CI and pre-commit, and treat any secret that has ever reached a repository as compromised. Removing the commit does not un-publish it; rotation is the only remediation.

Minimize, de-identify, and delete

The most reliable protection is not holding the data.

  • Collect what the purpose needs. Every extra field is a permanent liability with no owner.
  • Do not seed test environments from production without de-identification. This is one of the most common exposures and one of the easiest to fix.
  • Understand that removing names is not anonymization. A combination of ordinary fields often re-identifies people; treat de-identified data as still sensitive unless someone has actually tested that it is not.
  • Delete on a schedule you can evidence, and confirm deletion reaches backups, replicas, analytics copies and archives — where it usually does not.

Sources

references/sources.md in this skill lists the outside authorities that settle the questions here — what each one is authoritative for, and what you may do with it. Check them before answering on anything they cover, and cite what you used. Most are free to read and not free to reproduce; the use note on each is binding.

Never

  • Describe data as encrypted without saying against which threat.
  • Store a key or secret in the same place as the data or code it protects.
  • Rotate credentials without confirming the old ones stop working.
  • Copy production data into a test environment without de-identifying it first.

© cbrock84, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/security/skills/data-protection-and-encryption of cbrock84/headcount.

  • SKILL.md
  • references/sources.md

Open the folder on GitHubat commit 98d1c17

Compare with similar skills

Data Protection And Encryption next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Data Protection And Encryption compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Data Protection And Encryption this skillcbrock84/headcount2k—~1.3kAutomated safety check: PassMIT
Implementing Hashicorp Vault Dynamic Secretsmukul975/Anthropic-Cybersecurity-Skills34k—~5.2kAutomated safety check: PassApache-2.0
Implementing Homomorphic Encryptionmukul975/Privacy-Data-Protection-Skills297—~2.2kAutomated safety check: PassApache-2.0
Pseudonymization Riskmukul975/Privacy-Data-Protection-Skills297—~3.2kAutomated safety check: PassApache-2.0
Selecting Privacy Enhancing Technologiesmukul975/Privacy-Data-Protection-Skills297—~2.6kAutomated safety check: PassApache-2.0
Supplementary Measuresmukul975/Privacy-Data-Protection-Skills297—~3.8kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Hashicorp Vault Dynamic Secrets

    mukul975/Anthropic-Cybersecurity-Skills

    Configures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates, with automatic generation, lease management, and rotation to eliminate static secrets…

    34k GitHub stars~5.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Homomorphic Encryption

    mukul975/Privacy-Data-Protection-Skills

    Guide to implementing homomorphic encryption for privacy-preserving computation under GDPR.

    297 GitHub stars~2.2k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Pseudonymization Risk

    mukul975/Privacy-Data-Protection-Skills

    Assessment of pseudonymization techniques and re-identification risk.

    297 GitHub stars~3.2k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Selecting Privacy Enhancing Technologies

    mukul975/Privacy-Data-Protection-Skills

    Comprehensive PET selection guide covering differential privacy, homomorphic encryption, secure multi-party computation, federated learning, zero-knowledge proofs, and trusted execution environments.

    297 GitHub stars~2.6k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Supplementary Measures

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020.

    297 GitHub stars~3.8k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed

More from cbrock84/headcount

All 178 skills in this repo
  • Agent Hierarchy

    cbrock84/headcount

    Designs orchestrator-and-subagent hierarchies for a repository — splitting agents by exclusive write surface, pairing every producer with an independent auditor, and enforcing the split with a…

    2k GitHub stars~1.2k tokensUpdated 21 days ago
    Auto-check passed
  • Access And Identity

    cbrock84/headcount

    Designs and audits who can reach what — authentication, authorization models, privileged access, service credentials, and joiner-mover-leaver process.

    2k GitHub stars~1.1k tokensUpdated 21 days ago
    Auto-check passed
  • Account Based Marketing

    cbrock84/headcount

    Concentrates marketing and sales effort on a named set of accounts rather than on volume — qualifying whether the model fits your economics at all, building the account list and the buying group…

    2k GitHub stars~1.2k tokensUpdated 21 days ago
    Auto-check passed
  • Activation

    cbrock84/headcount

    Gets new users from signup to first real value — signup flow, onboarding, time-to-value, and the early experience that determines whether someone becomes a user or a lapsed account.

    2k GitHub stars~865 tokensUpdated 21 days ago
    Auto-check passed
  • AI ML Governance

    cbrock84/headcount

    Governs models and AI systems in production — intended use, evaluation, monitoring, human oversight, documentation, and the decision to deploy or retire.

    2k GitHub stars~1k tokensUpdated 21 days ago
    Auto-check passed
  • AI Research Analyst

    cbrock84/headcount

    Produces executive-level research — market sizing, competitor mapping, trend analysis, and strategic intelligence — grounded in cited sources with the confidence in each claim made explicit.

    2k GitHub stars~916 tokensUpdated 21 days ago
    Auto-check passed

Questions about Data Protection And Encryption

What does Data Protection And Encryption do?

Protects data itself rather than the systems around it — classifying what you hold, encrypting in transit and at rest and understanding what each actually defends against, managing keys and their…. Data Protection And Encryption is an agent skill from cbrock84/headcount. Protects data itself rather than the systems around it — classifying what you hold, encrypting in transit and at rest and understanding what each actually defends against, managing keys and their rotation, handling secrets in applications and pipelines, minimizing and de-identifying, and deleting on purpose.

When should I use Data Protection And Encryption?

Data Protection And Encryption fits situations like: tasks that involve Privacy and GDPR; tasks that involve Cryptography; tasks that involve Secrets management.

How do I install Data Protection And Encryption in Claude Code?

Run `npx skills add cbrock84/headcount --skill data-protection-and-encryption -a claude-code`. Or copy the skill folder (plugins/security/skills/data-protection-and-encryption in cbrock84/headcount) into .claude/skills/data-protection-and-encryption in your project. Claude Code loads it when a task matches its description.

How do I install Data Protection And Encryption in Codex?

Run `npx skills add cbrock84/headcount --skill data-protection-and-encryption -a codex`. Or copy the skill folder (plugins/security/skills/data-protection-and-encryption in cbrock84/headcount) into .agents/skills/data-protection-and-encryption in your project. Codex loads it when a task matches its description.

Can I use Data Protection And Encryption in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cbrock84/headcount --skill data-protection-and-encryption -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/data-protection-and-encryption, .gemini/skills/data-protection-and-encryption, .github/skills/data-protection-and-encryption and .opencode/skills/data-protection-and-encryption in your project.

What does Data Protection And Encryption need to run?

SKILL.md names no scripts, command-line tools or credentials: Data Protection And Encryption is instructions for the agent only.

Does Data Protection And Encryption access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Data Protection And Encryption safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Data Protection And Encryption use?

Data Protection And Encryption is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Data Protection And Encryption use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 453 tokens, read only when the agent opens those files.

What are the alternatives to Data Protection And Encryption?

Skills that share tags, products or a category with Data Protection And Encryption: Implementing Hashicorp Vault Dynamic Secrets (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Homomorphic Encryption (mukul975/Privacy-Data-Protection-Skills, 297 stars), Pseudonymization Risk (mukul975/Privacy-Data-Protection-Skills, 297 stars) and Selecting Privacy Enhancing Technologies (mukul975/Privacy-Data-Protection-Skills, 297 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Data Protection And Encryption?

cbrock84 (a GitHub user) maintains it in cbrock84/headcount, which has 2,016 GitHub stars. The repository holds 178 skills in this directory. The repository was last updated on September 17, 2026.

Source: cbrock84/headcount on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.