Agent skill

Anon

by glebis in glebis/claude-skills

De-identify a session transcript (file or folder) by redacting PII LOCALLY before any sharing or cloud use.

MITAuto-check passed

Install Anon

skills CLI
$ npx skills add glebis/claude-skills --skill anon -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install glebis/claude-skills anon --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/glebis/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/confide/skills/anon .claude/skills/anon && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
anon
GitHub stars
389
Token cost
~1.3k tokens
SKILL.md length
572 words
Files
2 (incl. scripts)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

De-identify a session transcript (file or folder) by redacting PII LOCALLY before any sharing or cloud use.

  • Works in 4 steps: Report the counts summary (types,… → Tell the user the GREEN copy still needs… → Remind them the .map.json is the secret… → …
  • The user says anonymize this transcript
  • SKILL.md covers Privacy invariants (do not…, Run it, After running and Setup
  • Runs Python scripts from its folder; calls python3

What it does

Anon is an agent skill from glebis/claude-skills. De-identify a session transcript (file or folder) by redacting PII LOCALLY before any sharing or cloud use. Produces a redacted GREEN copy with unique reserved-sentinel placeholders ([CONFIDEPERSON0001], [CONFIDEEMAIL0001], [CONFIDEDATE0002]...) plus a counts-only stats summary, and a local secret <name.map.json (0600, gitignored) that enables confide:rehydrate to restore real values after a cloud analysis. Use when the user says "anonymize this transcript", "redact PII", "de-identify session", "make safe to…

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/anon.py`).

The repository describes itself as: Collection of Claude Code skills for enhanced AI workflows. The licence is MIT.

When your agent uses it

  • The user says anonymize this transcript
  • De-identify session
  • Make safe to share
  • Strip personal data

Example prompts

  • “anonymize this transcript”
  • “redact PII”
  • “de-identify session”
  • “/anon”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Report the counts summary (types, layers, redaction rate) — never paste PII.
  2. Tell the user the GREEN copy still needs human review before sharing.
  3. Remind them the .map.json is the secret (originals) — it stays local, never
  4. Offer confide:red to probe what an attacker could still infer/link.

What it can do on your machine

Read from SKILL.md and the folder at commit 7524dff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Anon loads about 1.3k tokens when it runs. Until then it costs about 212 tokens; SKILL.md has 572 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~212
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from glebis/claude-skills at commit 7524dff, republished under its MIT licence (© glebis). 572 words, ~1,277 tokens.

Download SKILL.mdSave it as .claude/skills/anon/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
anon
description
De-identify a session transcript (file or folder) by redacting PII LOCALLY before any sharing or cloud use. Produces a redacted GREEN copy with unique reserved-sentinel placeholders ([CONFIDE_PERSON_0001], [CONFIDE_EMAIL_0001], [CONFIDE_DATE_0002]...) plus a counts-only stats summary, and a local secret <name>.map.json (0600, gitignored) that enables confide:rehydrate to restore real values after a cloud analysis. Use when the user says "anonymize this transcript", "redact PII", "de-identify session", "make safe to share", "strip personal data", "anonymize notes before sending to an LLM", or points at a transcript/folder that should be scrubbed. Local-only by default — raw text never leaves the machine; the map is the only artifact with originals and stays local; nothing printed is PII; human review is still required before sharing.

confide:anon — local PII redaction

Redact personally identifying information from a transcript (or a whole folder) using the layered local stack in shared/confide_core.py: regex (emails / URLs / phones / IDs / dates) → Natasha (RU named entities) → local LLM (quasi-identifiers). Spans are interval-merged and replaced with placeholders. The result is a GREEN copy safe to review.

By default anon emits a reversible map: unique reserved-sentinel placeholders (the same EXACT value always becomes the same [CONFIDE_<TYPE>_<NNNN>], e.g. [CONFIDE_PERSON_0001], [CONFIDE_EMAIL_0001], [CONFIDE_DATE_0002]) plus a sibling <name>.map.json (structured: schema_version, doc_id, green_sha256, created, entries[]) mapping each placeholder to its original. The CONFIDE_ sentinel is reserved — a real transcript essentially never contains it, so there is no collision risk and rehydrate never touches ordinary prose like "Person 1". This is exact-value matching, not entity coreference: inflected forms (e.g. RU "Марина" vs "Марины") are SEPARATE placeholders (no lemmatized merge). That map is the secret — the ONLY artifact with originals; it stays local and enables confide:rehydrate to put real values back into a cloud analysis of the GREEN text (round-trip: redact → analyze the green → rehydrate locally). Use --no-map for the legacy non-reversible [TYPE] style (no map written).

Privacy invariants (do not violate)

  • Local-only. No cloud APIs. Raw text never leaves the machine.
  • By design, original PII is written ONLY to the local, 0600, gitignored <name>.map.json, which never leaves the machine. It is never printed, and never written to the GREEN copy (the GREEN holds placeholders only; the original file is read, never rewritten). The map is the SECRET — the one artifact with originals. A .gitignore covering *.map.json, *.view.html, and *.restored.md is written/updated in the output dir so these local-only artifacts can never be committed. If the output dir looks cloud-synced (iCloud / Dropbox / OneDrive / Google Drive), anon prints a WARNING that the secret map would be uploaded.
  • Counts only. stdout and the *.stats.json files carry counts (by type, by layer, redaction rate) — never PII values or redacted text dumps.
  • Human review still required. Redaction is a floor, not a guarantee. A human must read the GREEN copy before sharing. Pair with confide:red to check residual re-identification risk.
Show full SKILL.md (229 more words)Show less

Run it

Run the script on a single file or a directory (processes every .md/.txt):

bash
python3 skills/anon/scripts/anon.py PATH

For each input it writes, next to the file (or into --out DIR):

  • <name>.green.md — the redacted text (the only thing safe to look at / share after review)
  • <name>.stats.json — counts only
  • <name>.map.json — the reversible map (secret; 0600; gitignored; local only). Skipped with --no-map. A .gitignore with *.map.json is also written/updated in the output dir.

Options:

  • --layers regex,natasha,llm — override which detection layers run (default from config). Use --layers regex for a fully offline, deterministic pass (no models/network).
  • --out DIR — write outputs to DIR instead of next to each input.
  • --dry-run — compute and print stats only; write no files.
  • --no-map — disable the reversible map; emit non-unique [TYPE] placeholders, no map.json.

Already-emitted *.green.md / *.stats.json / *.map.json are skipped, so a folder can be re-run safely.

After running

  1. Report the counts summary (types, layers, redaction rate) — never paste PII.
  2. Tell the user the GREEN copy still needs human review before sharing.
  3. Remind them the <name>.map.json is the secret (originals) — it stays local, never committed/shipped — and that confide:rehydrate uses it to restore real values into a cloud analysis of the GREEN text.
  4. Offer confide:red to probe what an attacker could still infer/link.

Setup

Layer availability (Natasha, local LLM via Ollama) and defaults come from config — run confide:setup first if Natasha/Ollama aren't installed. --layers regex always works offline.

© glebis, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in confide/skills/anon of glebis/claude-skills.

  • SKILL.md
  • scripts/anon.py

Open the folder on GitHubat commit 7524dff

Compare with similar skills

Anon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Anon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Anon this skillglebis/claude-skills389—~1.3kAutomated safety check: PassMIT
Baoyu Youtube TranscriptJimLiu/baoyu-skills26k1 repos~2.4kAutomated safety check: PassMIT
Youtube Transcriptbrowser-act/skills6.1k—~2.1kAutomated safety check: PassMIT
Transcription0xsline/OpenChatCut2.2k1 repos~1.1kAutomated safety check: PassAGPL-3.0
Youtube Transcript Skillssickn33/agentic-awesome-skills47k1 repos~1.2kAutomated safety check: PassMIT
Video Transcriptsudecode/plate17k—~1.5kAutomated safety check: PassCustom licence

Similar skills

  • Baoyu Youtube Transcript

    JimLiu/baoyu-skills

    Downloads YouTube video transcripts/subtitles and cover images by URL or video ID.

    26k GitHub starsUsed in 1 repo~2.4k tokens
    Media & CreativeAuto-check passed
  • Youtube Transcript

    browser-act/skills

    YouTube transcript extraction and content reformatting: given a YouTube video URL, opens the video's transcript panel, extracts all timestamped segments, and transforms the raw transcript into…

    6.1k GitHub stars~2.1k tokensUpdated 1 mo ago
    Knowledge ManagementAuto-check passed
  • Transcription

    0xsline/OpenChatCut

    A skill your agent uses when a video/audio task needs OpenChatCut transcription, captions, subtitles, subtitle styling, transcript search, transcript readiness checks, or enabling captions…

    2.2k GitHub starsUsed in 1 repo~1.1k tokens
    Media & CreativeAuto-check passed
  • Youtube Transcript Skills

    sickn33/agentic-awesome-skills

    Fetch YouTube video transcripts, search videos/channels, browse channels, and extract playlists via the getyoutubetranscript.com API - free tier, no card required.

    47k GitHub starsUsed in 1 repo~1.2k tokens
    Knowledge ManagementAuto-check passed
  • Video Transcripts

    udecode/plate

    Generate structured video transcripts from local files or video URLs using Gemini Files API.

    17k GitHub stars~1.5k tokensUpdated today
    Knowledge ManagementAuto-check passed
  • Video Transcript Downloader

    steipete/agent-scripts

    yt-dlp downloads: video, audio, subtitles, transcripts, clips, playlists.

    7.3k GitHub stars~558 tokensUpdated 4 days ago
    Media & CreativeAuto-check passed

More from glebis/claude-skills

All 91 skills in this repo
  • Runs a human-first workflow for labeling PII spans in a transcript, then scores inter-annotator agreement and drafts an adjudicated gold set.

    389 GitHub stars~1.3k tokensUpdated 12 days ago
    Auto-check passed
  • Automates a dedicated, logged-in Chrome instance per profile without ever closing the user's own open tabs or browser windows.

    389 GitHub stars~973 tokensUpdated 12 days ago
    Auto-check passed
  • Deep Research

    glebis/claude-skills

    This skill should be used when conducting comprehensive research on any topic using the OpenAI Deep Research API.

    389 GitHub stars~2.6k tokensUpdated 12 days ago
    Auto-check: notes
  • Elimination Research

    glebis/claude-skills

    This skill should be used for elimination-style research where the user wants to choose from a shortlist of products, tools, services, vendors, or other options using explicit criteria, numeric…

    389 GitHub stars~1.6k tokensUpdated 12 days ago
    Auto-check passed
  • Narrated HTML Presentations

    glebis/claude-skills

    Generates a self-contained HTML presentation with article and slides modes, ElevenLabs voiceover narration and optional GPT Image 2 illustrations.

    389 GitHub stars~2.3k tokensUpdated 12 days ago
    Auto-check: notes
  • Writes fictional but realistic coaching or therapy session transcripts for evals, demos and few-shot examples, in several modalities and export formats.

    389 GitHub stars~2.9k tokensUpdated 12 days ago
    Auto-check passed

Questions about Anon

What does Anon do?

De-identify a session transcript (file or folder) by redacting PII LOCALLY before any sharing or cloud use. Anon is an agent skill from glebis/claude-skills. De-identify a session transcript (file or folder) by redacting PII LOCALLY before any sharing or cloud use.

When should I use Anon?

Anon fits situations like: the user says anonymize this transcript; de-identify session; make safe to share; strip personal data.

How do I install Anon in Claude Code?

Run `npx skills add glebis/claude-skills --skill anon -a claude-code`. Or copy the skill folder (confide/skills/anon in glebis/claude-skills) into .claude/skills/anon in your project. Claude Code loads it when a task matches its description.

How do I install Anon in Codex?

Run `npx skills add glebis/claude-skills --skill anon -a codex`. Or copy the skill folder (confide/skills/anon in glebis/claude-skills) into .agents/skills/anon in your project. Codex loads it when a task matches its description.

Can I use Anon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add glebis/claude-skills --skill anon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/anon, .gemini/skills/anon, .github/skills/anon and .opencode/skills/anon in your project.

What does Anon need to run?

Going by SKILL.md and its folder, Anon needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Anon access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Anon safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Anon use?

Anon is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Anon use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Anon?

Skills that share tags, products or a category with Anon: Baoyu Youtube Transcript (JimLiu/baoyu-skills, 26k stars), Youtube Transcript (browser-act/skills, 6.1k stars), Transcription (0xsline/OpenChatCut, 2.2k stars) and Youtube Transcript Skills (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Anon?

glebis (a GitHub user) maintains it in glebis/claude-skills, which has 389 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on September 26, 2026.

Source: glebis/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.