Agent skill

Openrouter Data Privacy

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Implement data privacy controls for OpenRouter API usage. An agent skill from jeremylongshore/tons-of-skills-marketplace.

MITAuto-check passedLegal & Compliance

Install Openrouter Data Privacy

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill openrouter-data-privacy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace openrouter-data-privacy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/openrouter-data-privacy .claude/skills/openrouter-data-privacy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openrouter-data-privacy
GitHub stars
2.8k
Token cost
~2.5k tokens
SKILL.md length
526 words
Files
10 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Implement data privacy controls for OpenRouter API usage. An agent skill from jeremylongshore/tons-of-skills-marketplace.

  • Works in 5 steps: Start with PII Detection and Redaction:… → When downstream code needs the original… → Classify each workload and route it via… → …
  • Meeting GDPR/CCPA requirements
  • SKILL.md covers Overview, Prerequisites, Instructions and PII Detection and Redaction, plus 8 more sections
  • Calls pip; reaches openrouter.ai; needs OPENROUTER_API_KEY and API_KEY

What it does

Openrouter Data Privacy is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement data privacy controls for OpenRouter API usage. Use when handling PII, meeting GDPR/CCPA requirements, or protecting sensitive data in prompts. Triggers: 'openrouter privacy', 'openrouter pii', 'openrouter gdpr', 'openrouter data handling'.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `references/audit-trail.md`, `references/compliance-considerations.md` and `references/data-minimization.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Privacy and GDPR and Model routing and gateways. It works with OpenRouter. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Meeting GDPR/CCPA requirements
  • Protecting sensitive data in prompts

Example prompts

  • “openrouter privacy”
  • “openrouter pii”
  • “openrouter gdpr”
  • “/openrouter-data-privacy”

Requirements

  • Python 3
  • A credential in OPENROUTER_API_KEY
  • A credential in API_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Bash(python3:*)

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Start with PII Detection and Redaction: adapt PII_RULES (email, phone, SSN, credit card, sk-or-v1- API keys, IPs) to your data, then run…
  2. When downstream code needs the original values back, use the Placeholder Substitution Pattern instead of plain redaction…
  3. Classify each workload and route it via Provider Selection for Privacy: privacy_aware_completion() maps sensitivity to a model plus a…
  4. Wire the Privacy Middleware into every call path, choosing block_on_pii=True (raise on detection) or auto_redact=True (scrub and continue)…
  5. Apply the Enterprise Considerations: hash logged prompts (SHA-256) for GDPR right-to-erasure, and use BYOK for the most sensitive workloads.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Bash(python3:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • openrouter.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENROUTER_API_KEY
    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Openrouter Data Privacy loads about 2.5k tokens when it runs, and up to ~6.1k if it reads all its reference files. Until then it costs about 69 tokens; SKILL.md has 526 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 526 words, ~2,532 tokens.

Download SKILL.mdSave it as .claude/skills/openrouter-data-privacy/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
openrouter-data-privacy
description
Implement data privacy controls for OpenRouter API usage. Use when handling PII, meeting GDPR/CCPA requirements, or protecting sensitive data in prompts. Triggers: 'openrouter privacy', 'openrouter pii', 'openrouter gdpr', 'openrouter data handling'.
allowed-tools
Read, Write, Edit, Grep, Bash(python3:*)
compatibility
Designed for Claude Code
version
1.20.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, openrouter, privacy, security, compliance

OpenRouter Data Privacy

Overview

When sending data through OpenRouter to upstream LLM providers, you're responsible for ensuring prompts don't leak PII inappropriately. OpenRouter itself does not train on API data, but each upstream provider has its own data retention and training policies. This skill covers PII detection and redaction, placeholder substitution, provider selection for privacy, and consent tracking.

Prerequisites

  • An OpenRouter API key (sk-or-v1-...) exported as OPENROUTER_API_KEY — see the openrouter-install-auth skill for setup
  • Python 3.8+ with the OpenAI SDK (pip install openai) — every pattern in this skill is Python
  • A sensitivity classification for your workloads (public / standard / sensitive) so privacy_aware_completion() can route each one
  • A list of providers your org approves for sensitive data, to plug into provider.order with allow_fallbacks: False

Instructions

  1. Start with PII Detection and Redaction: adapt PII_RULES (email, phone, SSN, credit card, sk-or-v1- API keys, IPs) to your data, then run scan_and_redact() on representative inputs and review the findings for false positives.
  2. When downstream code needs the original values back, use the Placeholder Substitution Pattern instead of plain redaction — PrivacyProxy.anonymize() before the API call, deanonymize() on the model's reply.
  3. Classify each workload and route it via Provider Selection for Privacy: privacy_aware_completion() maps sensitivity to a model plus a provider block (order: ["Anthropic"], allow_fallbacks: False for standard/sensitive).
  4. Wire the Privacy Middleware into every call path, choosing block_on_pii=True (raise on detection) or auto_redact=True (scrub and continue) per workload.
  5. Apply the Enterprise Considerations: hash logged prompts (SHA-256) for GDPR right-to-erasure, and use BYOK for the most sensitive workloads.

PII Detection and Redaction

python
import re
from dataclasses import dataclass
from typing import Optional

@dataclass
class PiiScanResult:
    clean_text: str
    findings: list[dict]
    has_pii: bool

PII_RULES = [
    ("email", r'\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b'),
    ("phone", r'\b(?:\+1[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}\b'),
    ("ssn", r'\b\d{3}-\d{2}-\d{4}\b'),
    ("credit_card", r'\b(?:\d{4}[- ]?){3}\d{4}\b'),
    ("api_key", r'\bsk-or-v1-[a-zA-Z0-9]+\b'),
    ("ip_address", r'\b(?:\d{1,3}\.){3}\d{1,3}\b'),
]

REPLACEMENTS = {
    "email": "[EMAIL]", "phone": "[PHONE]", "ssn": "[SSN]",
    "credit_card": "[CARD]", "api_key": "[API_KEY]", "ip_address": "[IP]",
}

def scan_and_redact(text: str) -> PiiScanResult:
    """Scan text for PII and return redacted version with findings."""
    findings = []
    clean = text
    for pii_type, pattern in PII_RULES:
        matches = re.findall(pattern, clean)
        for match in matches:
            findings.append({"type": pii_type, "value_prefix": match[:4] + "..."})
        clean = re.sub(pattern, REPLACEMENTS[pii_type], clean)

    return PiiScanResult(clean_text=clean, findings=findings, has_pii=len(findings) > 0)

Placeholder Substitution Pattern

python
import os, uuid
from openai import OpenAI

client = OpenAI(
    base_url="https://openrouter.ai/api/v1",
    api_key=os.environ["OPENROUTER_API_KEY"],
    default_headers={"HTTP-Referer": "https://my-app.com", "X-Title": "my-app"},
)

class PrivacyProxy:
    """Replace PII with placeholders before API, restore after."""

    def __init__(self):
        self._map: dict[str, str] = {}

    def anonymize(self, text: str) -> str:
        """Replace PII with unique placeholders."""
        result = scan_and_redact(text)
        if not result.has_pii:
            return text

        # Use deterministic placeholders for consistent replacement
        anonymized = text
        for pii_type, pattern in PII_RULES:
            for match in re.finditer(pattern, anonymized):
                original = match.group()
                if original not in self._map:
                    placeholder = f"[{pii_type.upper()}_{len(self._map)}]"
                    self._map[placeholder] = original
                else:
                    placeholder = next(k for k, v in self._map.items() if v == original)
                anonymized = anonymized.replace(original, placeholder, 1)
        return anonymized

    def deanonymize(self, text: str) -> str:
        """Restore original values from placeholders."""
        result = text
        for placeholder, original in self._map.items():
            result = result.replace(placeholder, original)
        return result

# Usage
proxy = PrivacyProxy()
user_input = "Contact john@example.com or call 555-123-4567"
safe_input = proxy.anonymize(user_input)
# safe_input = "Contact [EMAIL_0] or call [PHONE_1]"

response = client.chat.completions.create(
    model="anthropic/claude-3.5-sonnet",
    messages=[{"role": "user", "content": safe_input}],
    max_tokens=200,
)
# Restore PII in the response if model referenced it
result = proxy.deanonymize(response.choices[0].message.content)

Provider Selection for Privacy

python
# Force specific provider to control data handling
def privacy_aware_completion(messages, sensitivity="standard"):
    """Route to appropriate provider based on data sensitivity."""

    PRIVACY_CONFIG = {
        "public": {
            "model": "openai/gpt-4o-mini",
            "provider": None,  # Any provider OK
        },
        "standard": {
            "model": "anthropic/claude-3.5-sonnet",
            "provider": {"order": ["Anthropic"], "allow_fallbacks": False},
        },
        "sensitive": {
            "model": "anthropic/claude-3.5-sonnet",
            "provider": {"order": ["Anthropic"], "allow_fallbacks": False},
            # Add PII redaction as mandatory pre-processing
        },
    }

    config = PRIVACY_CONFIG.get(sensitivity, PRIVACY_CONFIG["standard"])
    extra = {}
    if config["provider"]:
        extra["extra_body"] = {"provider": config["provider"]}

    return client.chat.completions.create(
        model=config["model"],
        messages=messages,
        max_tokens=1024,
        **extra,
    )

Privacy Middleware

python
class PrivacyMiddleware:
    """Enforce privacy policies before every API call."""

    def __init__(self, block_on_pii: bool = False, auto_redact: bool = True):
        self.block_on_pii = block_on_pii
        self.auto_redact = auto_redact

    def process(self, messages: list[dict]) -> list[dict]:
        """Scan and optionally redact PII from all messages."""
        processed = []
        for msg in messages:
            content = msg.get("content", "")
            if isinstance(content, str):
                result = scan_and_redact(content)
                if result.has_pii:
                    if self.block_on_pii:
                        raise ValueError(f"PII detected: {[f['type'] for f in result.findings]}")
                    if self.auto_redact:
                        msg = {**msg, "content": result.clean_text}
            processed.append(msg)
        return processed

Output

The privacy flows in this skill produce:

  • A PiiScanResult per scan: clean_text with placeholders substituted, findings (PII type + first-4-chars value prefix per match), and a has_pii flag
  • Anonymized prompts like "Contact [EMAIL_0] or call [PHONE_1]" plus the placeholder→original map that deanonymize() uses to restore values in the response
  • Chat completions served only by approved providers when the provider.order + allow_fallbacks: False config is applied
  • A ValueError listing the detected PII types when PrivacyMiddleware runs with block_on_pii=True
Show full SKILL.md (184 more words)Show less

Examples

Scanning a support message before it leaves your infrastructure:

python
result = scan_and_redact("Contact john@example.com or call 555-123-4567")
print(result.clean_text)  # Contact [EMAIL] or call [PHONE]
print(result.has_pii)     # True
print(result.findings)    # [{'type': 'email', 'value_prefix': 'john...'}, {'type': 'phone', ...}]

To keep the values recoverable, run the same input through PrivacyProxy.anonymize() instead, send the placeholder version to the model, then deanonymize() the reply. More worked examples: references/examples.md.

Error Handling

ErrorCauseFix
PII detected in promptUser input contains sensitive dataAuto-redact or block and prompt user to remove
Provider retained dataUsing provider with training-on-API-dataSwitch to Anthropic or use BYOK
Placeholder in responseModel used placeholder literallyMap it back with deanonymize()
False positive PII matchRegex too aggressiveTune patterns; use NLP-based PII detection for accuracy

Enterprise Considerations

  • OpenRouter does not train on API data; check each upstream provider's data use policy separately
  • Use provider.order + allow_fallbacks: false to ensure data only flows to approved providers
  • Implement PII redaction as middleware that runs on every request, not optional per-call
  • For GDPR right-to-erasure: don't log raw prompts -- hash them (SHA-256)
  • Use BYOK for sensitive workloads so data flows directly to the provider under your account
  • Build a data classification system that auto-routes based on sensitivity level

References

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (references) in skills/.curated/openrouter-data-privacy of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/audit-trail.md
  • references/compliance-considerations.md
  • references/data-minimization.md
  • references/data-retention-controls.md
  • references/errors.md
  • references/examples.md
  • references/openrouter-data-handling.md
  • references/pii-protection.md
  • references/security-best-practices.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Openrouter Data Privacy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openrouter Data Privacy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openrouter Data Privacy this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.5kAutomated safety check: PassMIT
Legal Pagestheopenco/llmgateway1.7k—~215Automated safety check: PassCustom licence
Legal AI Model Router Stephane Boghossianlawve-ai/awesome-legal-skills847—~1.5kAutomated safety check: PassAGPL-3.0-or-later
Hot Monitorliyupi/yupi-hot-monitor7171 repos~1.2kAutomated safety check: PassNone
Embeddings via 9Routerdecolua/9router31k—~604Automated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Legal Pages

    theopenco/llmgateway

    Edit LLM Gateway legal documents — Terms of Use, Privacy Policy, sub-processors, and product-specific supplemental terms such as DevPass.

    1.7k GitHub stars~215 tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Legal AI Model Router Stephane Boghossian

    lawve-ai/awesome-legal-skills

    Routes any legal task to the right LLM, like OpenRouter but for legal work and grounded in benchmarks instead of brand loyalty.

    847 GitHub stars~1.5k tokensUpdated 8 days ago
    Legal & ComplianceAuto-check passed
  • Hot Monitor

    liyupi/yupi-hot-monitor

    AI hotspot monitoring and trending topic discovery across multiple sources (Bing, Google, DuckDuckGo, HackerNews, Sogou, Bilibili, Weibo, Twitter).

    717 GitHub starsUsed in 1 repo~1.2k tokens
    DatabasesAuto-check passed
  • Embeddings via 9Router

    decolua/9router

    Generates vector embeddings through the 9Router /v1/embeddings endpoint, using models from providers such as OpenAI, Gemini, Mistral and Voyage for RAG and semantic search.

    31k GitHub stars~604 tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • OpenWork Model Alias Manager

    different-ai/openwork

    Manages OpenWork's inference model aliases, discounts and overlays over the upstream OpenRouter catalog, and triggers the GitHub workflow that refreshes base models.

    24k GitHub stars~1.1k tokensUpdated today
    Sales & SupportAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Openrouter Data Privacy

What does Openrouter Data Privacy do?

Implement data privacy controls for OpenRouter API usage. An agent skill from jeremylongshore/tons-of-skills-marketplace. Openrouter Data Privacy is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement data privacy controls for OpenRouter API usage.

When should I use Openrouter Data Privacy?

Openrouter Data Privacy fits situations like: meeting GDPR/CCPA requirements; protecting sensitive data in prompts.

How do I install Openrouter Data Privacy in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill openrouter-data-privacy -a claude-code`. Or copy the skill folder (skills/.curated/openrouter-data-privacy in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/openrouter-data-privacy in your project. Claude Code loads it when a task matches its description.

How do I install Openrouter Data Privacy in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill openrouter-data-privacy -a codex`. Or copy the skill folder (skills/.curated/openrouter-data-privacy in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/openrouter-data-privacy in your project. Codex loads it when a task matches its description.

Can I use Openrouter Data Privacy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill openrouter-data-privacy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openrouter-data-privacy, .gemini/skills/openrouter-data-privacy, .github/skills/openrouter-data-privacy and .opencode/skills/openrouter-data-privacy in your project.

What does Openrouter Data Privacy need to run?

Going by SKILL.md and its folder, Openrouter Data Privacy needs the command-line tools its instructions call (pip) and credentials named OPENROUTER_API_KEY and API_KEY. Our summary lists: Python 3; A credential in OPENROUTER_API_KEY; A credential in API_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Bash(python3:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Openrouter Data Privacy access the network?

SKILL.md names 1 domain. In commands or code: openrouter.ai; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Openrouter Data Privacy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openrouter Data Privacy use?

Openrouter Data Privacy is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openrouter Data Privacy use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Openrouter Data Privacy?

Skills that share tags, products or a category with Openrouter Data Privacy: Legal Pages (theopenco/llmgateway, 1.7k stars), Legal AI Model Router Stephane Boghossian (lawve-ai/awesome-legal-skills, 847 stars), Hot Monitor (liyupi/yupi-hot-monitor, 717 stars) and Embeddings via 9Router (decolua/9router, 31k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openrouter Data Privacy?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.