Agent skill

Pii Detector

by goSprinto in goSprinto/compliance-skills

Proactive PII add-on — augments the main response with PII guidance.

MITAuto-check passedBackend & APIs

Install Pii Detector

skills CLI
$ npx skills add goSprinto/compliance-skills --skill pii-detector -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install goSprinto/compliance-skills pii-detector --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/goSprinto/compliance-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/pii-detector .claude/skills/pii-detector && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pii-detector
GitHub stars
133
Token cost
~1.6k tokens
SKILL.md length
683 words
Files
15
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Proactive PII add-on — augments the main response with PII guidance.

  • Works in 4 steps: Detect the Mode → Generation Mode: Map to Layers → Regulations (Always Apply All, Never Ask) → …
  • GraphQL resolver
  • SKILL.md covers Core Principle, Step 1 — Detect the Mode, Step 2 — Generation Mode: Map… and Step 3 — Regulations (Always…, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Pii Detector is an agent skill from goSprinto/compliance-skills. Proactive PII add-on — augments the main response with PII guidance. Auto-trigger on any form, schema, migration, model, API route, GraphQL resolver, auth flow, or data design discussion. Also fires on: middleware, webhooks, workers, seed/fixture/factory files, delete/export/purge/anonymize functions, cron jobs, HTTP clients, controllers, services, resolvers. Trigger phrases: "build a form", "collect X data", "what fields should I include", "how should I design the schema", "POC / lead / contact / user / customer…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files (for example `README.md`, `layers/api-layer.md` and `layers/auth-sessions.md`).

It sits in Backend & APIs, covering GraphQL, Authentication and Webhooks. It works with GraphQL. The licence is MIT.

When your agent uses it

  • GraphQL resolver
  • Data design discussion
  • Phrases: build a form
  • What fields should I include

Example prompts

  • “build a form”
  • “collect X data”
  • “what fields should I include”
  • “/pii-detector”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Detect the Mode
  2. Generation Mode: Map to Layers
  3. Regulations (Always Apply All, Never Ask)
  4. Run Checks, Then Generate (Inline Mode Only)

What it can do on your machine

Read from SKILL.md and the folder at commit 0594a9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pii Detector loads about 1.6k tokens when it runs. Until then it costs about 212 tokens; SKILL.md has 683 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~212
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from goSprinto/compliance-skills at commit 0594a9e, republished under its MIT licence (© goSprinto). 683 words, ~1,585 tokens.

Download SKILL.mdSave it as .claude/skills/pii-detector/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.
name
pii-detector
description
Proactive PII add-on — augments the main response with PII guidance. Auto-trigger on any form, schema, migration, model, API route, GraphQL resolver, auth flow, or data design discussion. Also fires on: middleware, webhooks, workers, seed/fixture/factory files, delete/export/purge/anonymize functions, cron jobs, HTTP clients, controllers, services, resolvers. Trigger phrases: "build a form", "collect X data", "what fields should I include", "how should I design the schema", "POC / lead / contact / user / customer information", "store / save / persist X", "sign up / login / auth / registration", "share thoughts on how to build". Trigger on field names: email, phone, name, dob, ssn, card, cvv, password, token, secret, api_key, health, biometric, ip_address, salary, session, device_id, notes, metadata (on user-facing models).

PII Developer Skill — USA Focus

Automatic PII checks during development. Fires on both what the user asks for AND what Claude is about to generate — not just on keyword matching.


Core Principle

Check before generating. Never produce code and then suggest fixes. The sequence is always: detect intent → run relevant checks → generate correct code.

If there is ANY ambiguity — check it. False positives are cheap. Missed PII in production is a breach, a fine, or both.

When suggesting fixes, use the language, framework, and idioms of the code being reviewed. Never suggest a fix in a different language than the one being written. If the codebase is Python, fix in Python. If Rails, fix in Ruby. If Go, fix in Go. Claude infers the language from context — no need to specify.


Step 1 — Detect the Mode

Read the user's request AND what Claude is about to produce. Choose the mode first — this determines everything else.

Planning / Review mode — user is discussing, designing, reviewing, or asking Claude to read/check existing code. No new code being generated. → Load: modes/planning.md → Enrich Claude's natural response with PII notes. No standalone report.

Signals: "review", "read", "look at", "check this", "share thoughts", "how should I build", "I want to build X", "help me design", "feedback on", "thoughts on", reading or analyzing an existing file without generating new code.

Generation mode — Claude is about to write new code from scratch. → Load relevant layer(s) from the table below. Check first, generate second.

Signals: "build it", "create", "generate", "write", "implement", "scaffold", "make", "add this feature" — active code production.

Repo scan mode — user explicitly requests a full audit. → Load: modes/repo-scan.md + all layers.

Signals: "scan my repo", "full audit", "PII report", "check all my models", "audit my codebase".

When in doubt between planning/review and generation: default to planning/review. Enriching a response is always safer than running a check that wasn't needed.


Step 2 — Generation Mode: Map to Layers

Only applies when generating new code. Multiple layers can apply simultaneously.

What's being builtLayers to load
Database model / schema / migrationpatterns/fields.md + rules/non-negotiables.md + modes/inline.md
Login / signup / auth / registrationlayers/auth-sessions.md + rules/non-negotiables.md
Frontend form / page / componentlayers/frontend.md
API route / controller / serializerlayers/api-layer.md
Middleware / request handler / loggerlayers/data-in-transit.md
JWT / token / session / cookie codelayers/auth-sessions.md
Webhook handlerlayers/data-in-transit.md + layers/api-layer.md
Seed file / fixture / factory / test helperlayers/testing-seeding.md
Delete / purge / anonymize / export functionlayers/data-lifecycle.md
Cron job / background worker / cleanup tasklayers/data-lifecycle.md
External API client / HTTP calllayers/data-in-transit.md
Analytics / tracking integrationrules/leakage-vectors.md
Error handling / monitoring setuprules/leakage-vectors.md
Full repo / codebase submittedALL layers — load modes/repo-scan.md

When multiple layers apply (e.g. building an auth API endpoint): load all relevant layers and merge the checks.

Always load patterns/fields.md when a model or schema is involved. Always load rules/non-negotiables.md when any PII field is detected.


Show full SKILL.md (231 more words)Show less

Step 3 — Regulations (Always Apply All, Never Ask)

RegulationWhat It Means for Code
CCPA/CPRAEvery PII field must be deletable on request
HIPAAHealth data encrypted at rest + in transit; access logged on every read
PCI-DSSNever store CVV; tokenize card numbers; never log payment bodies
COPPAFlag age/dob fields; under-13 = parental consent, no behavioral tracking
GLBAFinancial data: encrypt, access control, audit logs
BIPABiometric: written consent before storage; retention limit required
FERPAStudent records: strict access controls, no sharing without consent
FTC ActDo exactly what your privacy policy says

Step 4 — Run Checks, Then Generate (Inline Mode Only)

  1. Load the relevant layer file(s) from Step 1
  2. Run all checks defined in those layers against what's about to be built
  3. Output findings in the standard format (see below)
  4. Generate corrected code immediately — with all fixes already applied

Never generate broken code first. Never suggest fixes as an afterthought. The check and the corrected output happen in a single pass.


Output Format

Inline (any single-task coding):

⚡ PII Check — [what's being built]

🔴 Fix now:
  [specific issue] → [exact fix]

🟡 Fix soon:
  [specific issue] → [exact fix]

🟢 Consider:
  [suggestion]

Regulations: [only ones actually triggered]

Then generate the corrected code immediately after.

Repo scan: structured report with file + line references. Load modes/repo-scan.md.

Rules for all output:

  • Reference actual field names, file names, and line numbers — never be generic
  • "Encrypt ssn with AES-256, store as BYTEA" not "encrypt sensitive fields"
  • Skip empty sections — don't pad with N/A categories
  • List only regulations actually triggered by findings

© goSprinto, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 14 other files in pii-detector of goSprinto/compliance-skills.

  • SKILL.md
  • README.md
  • layers/api-layer.md
  • layers/auth-sessions.md
  • layers/data-in-transit.md
  • layers/data-lifecycle.md
  • layers/frontend.md
  • layers/legal-consent.md
  • layers/testing-seeding.md
  • modes/inline.md
  • modes/planning.md
  • modes/repo-scan.md
  • patterns/fields.md
  • rules/leakage-vectors.md
  • rules/non-negotiables.md

Open the folder on GitHubat commit 0594a9e

Compare with similar skills

Pii Detector next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pii Detector compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pii Detector this skillgoSprinto/compliance-skills133—~1.6kAutomated safety check: PassMIT
Senior Backendalirezarezvani/claude-skills28k1 repos~3.8kAutomated safety check: PassMIT
API Connector Builderericrisco/rsc-harness180—~3.6kAutomated safety check: PassMIT
Fireflies Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMIT
Shopify APIMicrock/ordinary-claude-skills404—~4.3kAutomated safety check: PassCustom licence
Saleor GraphQL API Change Checklistsaleor/saleor23k—~1.2kAutomated safety check: PassBSD-3-Clause

Similar skills

  • Senior Backend

    alirezarezvani/claude-skills

    Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening.

    28k GitHub starsUsed in 1 repo~3.8k tokens
    Backend & APIsAuto-check passed
  • API Connector Builder

    ericrisco/rsc-harness

    A skill your agent uses when writing a client for someone else's REST or GraphQL API: auth flow choice and token refresh, pagination to exhaustion, retry-with-jitter on transient failures only…

    180 GitHub stars~3.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Fireflies Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Harden Fireflies bearer authentication, GraphQL selections, webhook signatures, logs, and privileged mutations against secret and meeting-data exposure.

    2.8k GitHub stars~1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Shopify API

    Microck/ordinary-claude-skills

    Complete API integration guide for Shopify including GraphQL Admin API, REST Admin API, Storefront API, Ajax API, OAuth authentication, rate limiting, and webhooks.

    404 GitHub stars~4.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Checklist for adding, changing, deprecating or removing Saleor GraphQL fields, mutations, enums and webhook event types so the change passes review first time.

    23k GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Ar Io Gateway Operator

    ar-io/ar-io-node

    Operate any AR.IO node deployment — architecture, daily ops, diagnostics, and recurring pitfalls that apply to every operator.

    127 GitHub stars~8.8k tokensUpdated today
    Backend & APIsAuto-check: notes

More from goSprinto/compliance-skills

  • Gdpr Compliance Checker

    goSprinto/compliance-skills

    Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…

    133 GitHub stars~8.6k tokensUpdated 4 mo ago
    Auto-check: notes

Works with

Categories

Questions about Pii Detector

What does Pii Detector do?

Proactive PII add-on — augments the main response with PII guidance. Pii Detector is an agent skill from goSprinto/compliance-skills. Proactive PII add-on — augments the main response with PII guidance.

When should I use Pii Detector?

Pii Detector fits situations like: graphQL resolver; data design discussion; phrases: build a form; what fields should I include.

How do I install Pii Detector in Claude Code?

Run `npx skills add goSprinto/compliance-skills --skill pii-detector -a claude-code`. Or copy the skill folder (pii-detector in goSprinto/compliance-skills) into .claude/skills/pii-detector in your project. Claude Code loads it when a task matches its description.

How do I install Pii Detector in Codex?

Run `npx skills add goSprinto/compliance-skills --skill pii-detector -a codex`. Or copy the skill folder (pii-detector in goSprinto/compliance-skills) into .agents/skills/pii-detector in your project. Codex loads it when a task matches its description.

Can I use Pii Detector in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add goSprinto/compliance-skills --skill pii-detector -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pii-detector, .gemini/skills/pii-detector, .github/skills/pii-detector and .opencode/skills/pii-detector in your project.

What does Pii Detector need to run?

SKILL.md names no scripts, command-line tools or credentials: Pii Detector is instructions for the agent only.

Does Pii Detector access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pii Detector safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pii Detector use?

Pii Detector is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pii Detector use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pii Detector?

Skills that share tags, products or a category with Pii Detector: Senior Backend (alirezarezvani/claude-skills, 28k stars), API Connector Builder (ericrisco/rsc-harness, 180 stars), Fireflies Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Shopify API (Microck/ordinary-claude-skills, 404 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pii Detector?

goSprinto (a GitHub organization) maintains it in goSprinto/compliance-skills, which has 133 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on May 26, 2026.

Source: goSprinto/compliance-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.