Agent skill

Scanning For Data Privacy Issues

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Scan for data privacy issues and sensitive information exposure.

MITAuto-check passedLegal & Compliance

Install Scanning For Data Privacy Issues

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-for-data-privacy-issues -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace scanning-for-data-privacy-issues --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/scanning-for-data-privacy-issues .claude/skills/scanning-for-data-privacy-issues && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
scanning-for-data-privacy-issues
GitHub stars
2.8k
Token cost
~1.7k tokens
SKILL.md length
795 words
Files
4 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Scan for data privacy issues and sensitive information exposure.

  • Works in 10 steps: Define the PII categories relevant to… → Scan source code for hardcoded PII using… → Examine logging statements (console.log,… → …
  • Reviewing data handling practices
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • With scan privacy issues

What it does

Scanning For Data Privacy Issues is an agent skill from jeremylongshore/tons-of-skills-marketplace. Scan for data privacy issues and sensitive information exposure. Use when reviewing data handling practices. Trigger with 'scan privacy issues', 'check sensitive data', or 'validate data protection'.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/README.md` and `scripts/README.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Reviewing data handling practices
  • With scan privacy issues
  • Check sensitive data
  • Validate data protection

Example prompts

  • “scan privacy issues”
  • “check sensitive data”
  • “validate data protection”
  • “/scanning-for-data-privacy-issues”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(security:*), Bash(scan:*), Bash(audit:*)

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Define the PII categories relevant to the application: email addresses, phone numbers, Social Security numbers, credit card numbers, IP…
  2. Scan source code for hardcoded PII using regex patterns -- detect email patterns ([a-zA-Z0-9+_.-]+@[a-zA-Z0-9.-]+), SSN patterns…
  3. Examine logging statements (console.log, logger.info, logging.debug, Log.d) for PII field references -- flag any logging of user email…
  4. Analyze database schemas and ORM models for PII fields stored without encryption -- check for columns named email, phone, ssn…
  5. Review data transmission: verify PII is transmitted over TLS only, check for PII in URL query parameters (visible in server logs and…
  6. Assess consent management: search for cookie consent implementations, privacy policy links, data processing agreements, and opt-in/opt-out…
  7. Check data retention: look for automated data deletion jobs, retention policy configurations, and user data export/deletion endpoints…
  8. Evaluate anonymization and pseudonymization: verify that analytics, reporting, and non-production environments use anonymized or…
  9. Scan configuration files and environment variables for PII used as defaults, seeds, or test data -- flag hardcoded test emails or phone…
  10. Classify findings by severity and regulation, produce a data flow diagram identifying where PII enters, is stored, is processed, and exits…

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(security:*)
    • Bash(scan:*)
    • Bash(audit:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cwe.mitre.org
    • gdpr-info.eu
    • oag.ca.gov
    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Scanning For Data Privacy Issues loads about 1.7k tokens when it runs, and up to ~1.7k if it reads all its reference files. Until then it costs about 58 tokens; SKILL.md has 795 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 795 words, ~1,730 tokens.

Download SKILL.mdSave it as .claude/skills/scanning-for-data-privacy-issues/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
scanning-for-data-privacy-issues
description
Scan for data privacy issues and sensitive information exposure. Use when reviewing data handling practices. Trigger with 'scan privacy issues', 'check sensitive data', or 'validate data protection'.
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(security:*), Bash(scan:*), Bash(audit:*)
compatibility
Designed for Claude Code
version
1.23.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
security, scanning-data

Scanning for Data Privacy Issues

Overview

Scan codebases for data privacy violations, PII exposure, and non-compliance with privacy regulations including GDPR, CCPA, HIPAA, and LGPD. This skill detects hardcoded personal data, unprotected PII in logs and databases, missing consent mechanisms, improper data retention, and insufficient anonymization or pseudonymization of sensitive fields.

Prerequisites

  • Access to the target codebase and configuration files in ${CLAUDE_SKILL_DIR}/
  • Knowledge of the data types processed by the application (PII categories, PHI, financial data)
  • Standard shell utilities and Grep/Glob available for pattern matching
  • Reference: ${CLAUDE_SKILL_DIR}/references/README.md for scanner API documentation, GDPR compliance guide, and sensitive data pattern definitions

Instructions

  1. Define the PII categories relevant to the application: email addresses, phone numbers, Social Security numbers, credit card numbers, IP addresses, geolocation data, biometric data, health records, and any domain-specific identifiers.
  2. Scan source code for hardcoded PII using regex patterns -- detect email patterns ([a-zA-Z0-9+_.-]+@[a-zA-Z0-9.-]+), SSN patterns (\d{3}-\d{2}-\d{4}), credit card patterns (Luhn-valid 13-19 digit sequences), and phone number patterns. Flag each as CWE-312 (Cleartext Storage of Sensitive Information).
  3. Examine logging statements (console.log, logger.info, logging.debug, Log.d) for PII field references -- flag any logging of user email, password, token, SSN, or credit card fields as CWE-532 (Insertion of Sensitive Information into Log File), severity high.
  4. Analyze database schemas and ORM models for PII fields stored without encryption -- check for columns named email, phone, ssn, date_of_birth, address that lack encryption-at-rest annotations or transparent data encryption.
  5. Review data transmission: verify PII is transmitted over TLS only, check for PII in URL query parameters (visible in server logs and browser history), and flag unencrypted API responses containing sensitive fields.
  6. Assess consent management: search for cookie consent implementations, privacy policy links, data processing agreements, and opt-in/opt-out mechanisms. Flag applications collecting PII without documented consent flows as a GDPR Article 6/7 gap.
  7. Check data retention: look for automated data deletion jobs, retention policy configurations, and user data export/deletion endpoints (GDPR Article 17 Right to Erasure). Flag absence of retention controls.
  8. Evaluate anonymization and pseudonymization: verify that analytics, reporting, and non-production environments use anonymized or pseudonymized data rather than production PII. Flag test fixtures containing real PII.
  9. Scan configuration files and environment variables for PII used as defaults, seeds, or test data -- flag hardcoded test emails or phone numbers that match real-world patterns.
  10. Classify findings by severity and regulation, produce a data flow diagram identifying where PII enters, is stored, is processed, and exits the system.

Output

  • PII inventory: Table of all detected PII types, their locations (file:line), storage mechanism, and encryption status
  • Findings report: Each finding includes severity, regulation reference (GDPR Article, CCPA Section, HIPAA Rule), CWE reference (CWE-312, CWE-532, CWE-359), affected file, and remediation steps
  • Data flow analysis: Summary of PII entry points (forms, APIs, imports), processing locations, storage mechanisms, and exit points (exports, API responses, logs)
  • Compliance gap matrix: GDPR/CCPA/HIPAA requirement mapped to implementation status (Compliant, Gap, Not Applicable)
  • Remediation plan: Prioritized actions including field encryption, log sanitization, consent implementation, and retention policy setup
Show full SKILL.md (298 more words)Show less

Error Handling

ErrorCauseSolution
High false positive rate on PII patternsRegex patterns matching non-PII strings (e.g., UUIDs matching SSN patterns)Refine patterns with context-aware checks; filter results by file type and surrounding code context
Encrypted PII not detectedApplication uses transparent encryption that masks PII at the code levelCheck encryption configuration separately; mark encrypted fields as "protected" in the inventory
Third-party data processors not visiblePII sent to external services via API callsGrep for HTTP client calls and map destination URLs; flag external services requiring Data Processing Agreements
Large codebase scan timeoutMillions of lines to scanScope to high-risk directories first (src/, api/, config/); exclude node_modules/, vendor/, and build artifacts
Test data flagged as PII exposureTest fixtures use realistic but fake dataVerify test data is synthetic; recommend using obviously fake data (e.g., test@example.com) to avoid false positives

Examples

PII in Application Logs

Grep ${CLAUDE_SKILL_DIR}/src/ for logging statements that reference user fields: logger.info.*email, console.log.*password, Log.d.*phone. Flag each match as CWE-532, severity high. Recommend implementing a log sanitizer middleware that redacts PII fields before writing to log output.

GDPR Data Subject Rights

Scan ${CLAUDE_SKILL_DIR}/src/api/ for endpoints supporting data subject rights: user data export (GET /api/users/:id/export), data deletion (DELETE /api/users/:id), and consent withdrawal. Flag missing endpoints as GDPR Article 15/17/21 gaps, severity high. Recommend implementing a data subject request handler.

Credit Card Data in Codebase

Search for credit card number patterns across all source files using \b[0-9]{13,19}\b with Luhn validation context. Check that any payment processing code uses tokenization rather than storing raw card numbers. Flag PAN storage as PCI DSS Requirement 3 violation and CWE-312, severity critical.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references, assets) in skills/.curated/scanning-for-data-privacy-issues of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • references/README.md
  • scripts/README.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Scanning For Data Privacy Issues next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Scanning For Data Privacy Issues compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Scanning For Data Privacy Issues this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Scanning For Data Privacy Issues

What does Scanning For Data Privacy Issues do?

Scan for data privacy issues and sensitive information exposure. Scanning For Data Privacy Issues is an agent skill from jeremylongshore/tons-of-skills-marketplace. Scan for data privacy issues and sensitive information exposure.

When should I use Scanning For Data Privacy Issues?

Scanning For Data Privacy Issues fits situations like: reviewing data handling practices; with scan privacy issues; check sensitive data; validate data protection.

How do I install Scanning For Data Privacy Issues in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-for-data-privacy-issues -a claude-code`. Or copy the skill folder (skills/.curated/scanning-for-data-privacy-issues in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/scanning-for-data-privacy-issues in your project. Claude Code loads it when a task matches its description.

How do I install Scanning For Data Privacy Issues in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-for-data-privacy-issues -a codex`. Or copy the skill folder (skills/.curated/scanning-for-data-privacy-issues in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/scanning-for-data-privacy-issues in your project. Codex loads it when a task matches its description.

Can I use Scanning For Data Privacy Issues in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-for-data-privacy-issues -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scanning-for-data-privacy-issues, .gemini/skills/scanning-for-data-privacy-issues, .github/skills/scanning-for-data-privacy-issues and .opencode/skills/scanning-for-data-privacy-issues in your project.

What does Scanning For Data Privacy Issues need to run?

SKILL.md names no scripts, command-line tools or credentials: Scanning For Data Privacy Issues is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(security:*), Bash(scan:*), Bash(audit:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Scanning For Data Privacy Issues access the network?

SKILL.md names 4 domains. As links in the text: cwe.mitre.org, gdpr-info.eu, oag.ca.gov and owasp.org. This is read from the text; nothing was executed.

Is Scanning For Data Privacy Issues safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Scanning For Data Privacy Issues use?

Scanning For Data Privacy Issues is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Scanning For Data Privacy Issues use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16 tokens, read only when the agent opens those files.

What are the alternatives to Scanning For Data Privacy Issues?

Skills that share tags, products or a category with Scanning For Data Privacy Issues: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Scanning For Data Privacy Issues?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.