Senior Backend
alirezarezvani/claude-skills
Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening.
Proactive PII add-on — augments the main response with PII guidance.
$ npx skills add goSprinto/compliance-skills --skill pii-detector -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install goSprinto/compliance-skills pii-detector --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/goSprinto/compliance-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/pii-detector .claude/skills/pii-detector && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pii-detector" agent skill from https://github.com/goSprinto/compliance-skills/tree/main/pii-detector into .claude/skills/pii-detector/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-detector", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/goSprinto/compliance-skills/tree/main/pii-detectorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add goSprinto/compliance-skills --skill pii-detector -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install goSprinto/compliance-skills pii-detector --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/goSprinto/compliance-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/pii-detector .agents/skills/pii-detector && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pii-detector" agent skill from https://github.com/goSprinto/compliance-skills/tree/main/pii-detector into .agents/skills/pii-detector/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-detector", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add goSprinto/compliance-skills --skill pii-detector -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install goSprinto/compliance-skills pii-detector --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/goSprinto/compliance-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/pii-detector .cursor/skills/pii-detector && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pii-detector" agent skill from https://github.com/goSprinto/compliance-skills/tree/main/pii-detector into .cursor/skills/pii-detector/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-detector", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/goSprinto/compliance-skills.git --path pii-detector--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add goSprinto/compliance-skills --skill pii-detector -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install goSprinto/compliance-skills pii-detector --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/goSprinto/compliance-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/pii-detector .gemini/skills/pii-detector && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pii-detector" agent skill from https://github.com/goSprinto/compliance-skills/tree/main/pii-detector into .gemini/skills/pii-detector/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-detector", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install goSprinto/compliance-skills pii-detectorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add goSprinto/compliance-skills --skill pii-detector -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/goSprinto/compliance-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/pii-detector .github/skills/pii-detector && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pii-detector" agent skill from https://github.com/goSprinto/compliance-skills/tree/main/pii-detector into .github/skills/pii-detector/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-detector", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add goSprinto/compliance-skills --skill pii-detector -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install goSprinto/compliance-skills pii-detector --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/goSprinto/compliance-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/pii-detector .opencode/skills/pii-detector && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pii-detector" agent skill from https://github.com/goSprinto/compliance-skills/tree/main/pii-detector into .opencode/skills/pii-detector/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pii-detector", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pii-detectorProactive PII add-on — augments the main response with PII guidance.
Pii Detector is an agent skill from goSprinto/compliance-skills. Proactive PII add-on — augments the main response with PII guidance. Auto-trigger on any form, schema, migration, model, API route, GraphQL resolver, auth flow, or data design discussion. Also fires on: middleware, webhooks, workers, seed/fixture/factory files, delete/export/purge/anonymize functions, cron jobs, HTTP clients, controllers, services, resolvers. Trigger phrases: "build a form", "collect X data", "what fields should I include", "how should I design the schema", "POC / lead / contact / user / customer…
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files (for example `README.md`, `layers/api-layer.md` and `layers/auth-sessions.md`).
It sits in Backend & APIs, covering GraphQL, Authentication and Webhooks. It works with GraphQL. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0594a9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pii Detector loads about 1.6k tokens when it runs. Until then it costs about 212 tokens; SKILL.md has 683 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from goSprinto/compliance-skills at commit 0594a9e, republished under its MIT licence (© goSprinto). 683 words, ~1,585 tokens.
.claude/skills/pii-detector/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.Automatic PII checks during development. Fires on both what the user asks for AND what Claude is about to generate — not just on keyword matching.
Check before generating. Never produce code and then suggest fixes. The sequence is always: detect intent → run relevant checks → generate correct code.
If there is ANY ambiguity — check it. False positives are cheap. Missed PII in production is a breach, a fine, or both.
When suggesting fixes, use the language, framework, and idioms of the code being reviewed. Never suggest a fix in a different language than the one being written. If the codebase is Python, fix in Python. If Rails, fix in Ruby. If Go, fix in Go. Claude infers the language from context — no need to specify.
Read the user's request AND what Claude is about to produce. Choose the mode first — this determines everything else.
Planning / Review mode — user is discussing, designing, reviewing,
or asking Claude to read/check existing code. No new code being generated.
→ Load: modes/planning.md
→ Enrich Claude's natural response with PII notes. No standalone report.
Signals: "review", "read", "look at", "check this", "share thoughts", "how should I build", "I want to build X", "help me design", "feedback on", "thoughts on", reading or analyzing an existing file without generating new code.
Generation mode — Claude is about to write new code from scratch. → Load relevant layer(s) from the table below. Check first, generate second.
Signals: "build it", "create", "generate", "write", "implement", "scaffold", "make", "add this feature" — active code production.
Repo scan mode — user explicitly requests a full audit.
→ Load: modes/repo-scan.md + all layers.
Signals: "scan my repo", "full audit", "PII report", "check all my models", "audit my codebase".
When in doubt between planning/review and generation: default to planning/review. Enriching a response is always safer than running a check that wasn't needed.
Only applies when generating new code. Multiple layers can apply simultaneously.
| What's being built | Layers to load |
|---|---|
| Database model / schema / migration | patterns/fields.md + rules/non-negotiables.md + modes/inline.md |
| Login / signup / auth / registration | layers/auth-sessions.md + rules/non-negotiables.md |
| Frontend form / page / component | layers/frontend.md |
| API route / controller / serializer | layers/api-layer.md |
| Middleware / request handler / logger | layers/data-in-transit.md |
| JWT / token / session / cookie code | layers/auth-sessions.md |
| Webhook handler | layers/data-in-transit.md + layers/api-layer.md |
| Seed file / fixture / factory / test helper | layers/testing-seeding.md |
| Delete / purge / anonymize / export function | layers/data-lifecycle.md |
| Cron job / background worker / cleanup task | layers/data-lifecycle.md |
| External API client / HTTP call | layers/data-in-transit.md |
| Analytics / tracking integration | rules/leakage-vectors.md |
| Error handling / monitoring setup | rules/leakage-vectors.md |
| Full repo / codebase submitted | ALL layers — load modes/repo-scan.md |
When multiple layers apply (e.g. building an auth API endpoint): load all relevant layers and merge the checks.
Always load patterns/fields.md when a model or schema is involved.
Always load rules/non-negotiables.md when any PII field is detected.
| Regulation | What It Means for Code |
|---|---|
| CCPA/CPRA | Every PII field must be deletable on request |
| HIPAA | Health data encrypted at rest + in transit; access logged on every read |
| PCI-DSS | Never store CVV; tokenize card numbers; never log payment bodies |
| COPPA | Flag age/dob fields; under-13 = parental consent, no behavioral tracking |
| GLBA | Financial data: encrypt, access control, audit logs |
| BIPA | Biometric: written consent before storage; retention limit required |
| FERPA | Student records: strict access controls, no sharing without consent |
| FTC Act | Do exactly what your privacy policy says |
Never generate broken code first. Never suggest fixes as an afterthought. The check and the corrected output happen in a single pass.
Inline (any single-task coding):
⚡ PII Check — [what's being built]
🔴 Fix now:
[specific issue] → [exact fix]
🟡 Fix soon:
[specific issue] → [exact fix]
🟢 Consider:
[suggestion]
Regulations: [only ones actually triggered]Then generate the corrected code immediately after.
Repo scan: structured report with file + line references. Load modes/repo-scan.md.
Rules for all output:
ssn with AES-256, store as BYTEA" not "encrypt sensitive fields"© goSprinto, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 14 other files in pii-detector of goSprinto/compliance-skills.
Open the folder on GitHubat commit 0594a9e
Pii Detector next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pii Detector this skillgoSprinto/compliance-skills | 133 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Senior Backendalirezarezvani/claude-skills | 28k | 1 repos | ~3.8k | Automated safety check: Pass | MIT | |
| API Connector Builderericrisco/rsc-harness | 180 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Fireflies Security Basicsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1k | Automated safety check: Pass | MIT | |
| Shopify APIMicrock/ordinary-claude-skills | 404 | — | ~4.3k | Automated safety check: Pass | Custom licence | |
| Saleor GraphQL API Change Checklistsaleor/saleor | 23k | — | ~1.2k | Automated safety check: Pass | BSD-3-Clause |
alirezarezvani/claude-skills
Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening.
ericrisco/rsc-harness
A skill your agent uses when writing a client for someone else's REST or GraphQL API: auth flow choice and token refresh, pagination to exhaustion, retry-with-jitter on transient failures only…
jeremylongshore/tons-of-skills-marketplace
Harden Fireflies bearer authentication, GraphQL selections, webhook signatures, logs, and privileged mutations against secret and meeting-data exposure.
Microck/ordinary-claude-skills
Complete API integration guide for Shopify including GraphQL Admin API, REST Admin API, Storefront API, Ajax API, OAuth authentication, rate limiting, and webhooks.
saleor/saleor
Checklist for adding, changing, deprecating or removing Saleor GraphQL fields, mutations, enums and webhook event types so the change passes review first time.
ar-io/ar-io-node
Operate any AR.IO node deployment — architecture, daily ops, diagnostics, and recurring pitfalls that apply to every operator.
goSprinto/compliance-skills
Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…
Works with
Categories
Proactive PII add-on — augments the main response with PII guidance. Pii Detector is an agent skill from goSprinto/compliance-skills. Proactive PII add-on — augments the main response with PII guidance.
Pii Detector fits situations like: graphQL resolver; data design discussion; phrases: build a form; what fields should I include.
Run `npx skills add goSprinto/compliance-skills --skill pii-detector -a claude-code`. Or copy the skill folder (pii-detector in goSprinto/compliance-skills) into .claude/skills/pii-detector in your project. Claude Code loads it when a task matches its description.
Run `npx skills add goSprinto/compliance-skills --skill pii-detector -a codex`. Or copy the skill folder (pii-detector in goSprinto/compliance-skills) into .agents/skills/pii-detector in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add goSprinto/compliance-skills --skill pii-detector -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pii-detector, .gemini/skills/pii-detector, .github/skills/pii-detector and .opencode/skills/pii-detector in your project.
SKILL.md names no scripts, command-line tools or credentials: Pii Detector is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pii Detector is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pii Detector: Senior Backend (alirezarezvani/claude-skills, 28k stars), API Connector Builder (ericrisco/rsc-harness, 180 stars), Fireflies Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Shopify API (Microck/ordinary-claude-skills, 404 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
goSprinto (a GitHub organization) maintains it in goSprinto/compliance-skills, which has 133 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on May 26, 2026.
Source: goSprinto/compliance-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.