Agent skill

Windsurf Data Handling

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Govern data processed through Devin Desktop (formerly Windsurf).

MITAuto-check passedLegal & Compliance

Install Windsurf Data Handling

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-data-handling -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace windsurf-data-handling --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/windsurf-data-handling .claude/skills/windsurf-data-handling && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windsurf-data-handling
GitHub stars
2.8k
Token cost
~1.2k tokens
SKILL.md length
459 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Govern data processed through Devin Desktop (formerly Windsurf).

  • Works in 6 steps: Inventory data flows → Minimize local context → Choose durable instructions → …
  • Mapping sensitive data
  • SKILL.md covers Overview, Prerequisites, Tool Use and Instructions, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Windsurf Data Handling is an agent skill from jeremylongshore/tons-of-skills-marketplace. Govern data processed through Devin Desktop (formerly Windsurf). Use when mapping sensitive data, configuring context exclusions, reviewing vendor controls, or preparing regulated-workload evidence. Trigger with "windsurf data privacy", "windsurf PII", "GDPR", "data residency", or "AI data boundary".

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Mapping sensitive data
  • Configuring context exclusions
  • Reviewing vendor controls
  • Preparing regulated-workload evidence

Example prompts

  • “windsurf data privacy”
  • “windsurf PII”
  • “data residency”
  • “/windsurf-data-handling”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Inventory data flows
  2. Minimize local context
  3. Choose durable instructions
  4. Review integrations
  5. Reconcile vendor evidence
  6. Test and approve

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.devin.ai
    • windsurf.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Windsurf Data Handling loads about 1.2k tokens when it runs, and up to ~1.3k if it reads all its reference files. Until then it costs about 81 tokens; SKILL.md has 459 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 459 words, ~1,205 tokens.

Download SKILL.mdSave it as .claude/skills/windsurf-data-handling/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
windsurf-data-handling
description
Govern data processed through Devin Desktop (formerly Windsurf). Use when mapping sensitive data, configuring context exclusions, reviewing vendor controls, or preparing regulated-workload evidence. Trigger with "windsurf data privacy", "windsurf PII", "GDPR", "data residency", or "AI data boundary".
allowed-tools
Read, Write, Edit
compatibility
Designed for Claude Code
argument-hint
[scope or requirements]
version
1.12.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, windsurf, privacy, compliance, data-handling

Devin Desktop Data Handling

Overview

Build an evidence-backed data map for Devin Desktop. Do not infer retention, residency, training use, certification coverage, or zero-data-retention from plan names; verify mutable vendor claims against the current contract and security documentation.

Prerequisites

  • Data-classification policy and approved repository inventory
  • Contract, DPA, or security evidence available to the authorized reviewer
  • Named security, privacy, and legal decision owners

Tool Use

  • Use Read to inspect only the repository files and configuration needed for the request.
  • Use Write only for a new artifact the user requested; never write credentials or unreviewed production configuration.
  • Use Edit for bounded, reviewable changes and preserve unrelated user work.

Instructions

Step 1: Inventory data flows

For Cascade, autocomplete, indexing, remote indexing, MCP, Hooks, diagnostics, and App Deploys, record inputs, destination, purpose, identity, retention evidence, administrator, and applicable policy. Include metadata and logs, not only source files.

Step 2: Minimize local context

Use .gitignore and repository .codeiumignore to exclude secrets, generated output, customer datasets, private keys, production exports, and irrelevant large files. Enterprise administrators may apply a global .codeiumignore under ~/.codeium/.

Ignored paths are context controls. They do not revoke filesystem access, rotate secrets, satisfy least privilege, or prove a regulatory requirement.

Step 3: Choose durable instructions

Put shared data-handling requirements in AGENTS.md or .devin/rules/*.md, for example:

markdown
# Regulated data boundary
- Never paste customer records, access tokens, or production exports into prompts.
- Use synthetic fixtures in tests and examples.
- Require security review for changes under `src/payments/`.
- Stop and escalate if a requested artifact contains regulated data.
Step 4: Review integrations

For every MCP server, Hook, deployment target, and analytics export, confirm an owner, authentication method, approved scopes, destination, log policy, revocation path, and incident contact. Disable integrations that lack an accountable owner.

Step 5: Reconcile vendor evidence

Capture the URL or contract section, observation date, product/plan scope, and reviewer for each claim. Where public documentation and negotiated terms differ, label the applicable authority rather than blending them.

Show full SKILL.md (175 more words)Show less
Step 6: Test and approve

Use synthetic canaries to verify exclusions and policy behavior. Obtain the required security/privacy/legal approval before enabling regulated workloads, remote indexing, or external MCP access.

Output

Produce a data-boundary record identifying data classes, indexed and excluded paths, integrations, organization controls, telemetry and logging decisions, retention or residency evidence, open questions, approvals, and validation results. Never reproduce sensitive values.

Error Handling

IssueResponse
Vendor claim lacks current evidenceMark unverified and request contract/security review
Sensitive data entered CascadeStop, contain sharing, rotate affected secrets, and follow incident policy
Ignore test failsCorrect syntax or scope, refresh indexing through current controls, and retest
Integration owner is unknownDisable or quarantine the integration until ownership is established

Examples

Evidence row: "Customer export; excluded by .codeiumignore; no MCP access; repository owner: Data Platform; retention claim pending DPA confirmation; synthetic canary passed during the recorded review run."

Resources

Continue with windsurf-policy-guardrails to turn approved data controls into enforceable repository, terminal, MCP, deployment, and organization policy.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/windsurf-data-handling of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Windsurf Data Handling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windsurf Data Handling compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windsurf Data Handling this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Windsurf Data Handling

What does Windsurf Data Handling do?

Govern data processed through Devin Desktop (formerly Windsurf). Windsurf Data Handling is an agent skill from jeremylongshore/tons-of-skills-marketplace. Govern data processed through Devin Desktop (formerly Windsurf).

When should I use Windsurf Data Handling?

Windsurf Data Handling fits situations like: mapping sensitive data; configuring context exclusions; reviewing vendor controls; preparing regulated-workload evidence.

How do I install Windsurf Data Handling in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-data-handling -a claude-code`. Or copy the skill folder (skills/.curated/windsurf-data-handling in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/windsurf-data-handling in your project. Claude Code loads it when a task matches its description.

How do I install Windsurf Data Handling in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-data-handling -a codex`. Or copy the skill folder (skills/.curated/windsurf-data-handling in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/windsurf-data-handling in your project. Codex loads it when a task matches its description.

Can I use Windsurf Data Handling in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-data-handling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windsurf-data-handling, .gemini/skills/windsurf-data-handling, .github/skills/windsurf-data-handling and .opencode/skills/windsurf-data-handling in your project.

What does Windsurf Data Handling need to run?

SKILL.md names no scripts, command-line tools or credentials: Windsurf Data Handling is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code.

Does Windsurf Data Handling access the network?

SKILL.md names 2 domains. As links in the text: docs.devin.ai and windsurf.com. This is read from the text; nothing was executed.

Is Windsurf Data Handling safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windsurf Data Handling use?

Windsurf Data Handling is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windsurf Data Handling use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 103 tokens, read only when the agent opens those files.

What are the alternatives to Windsurf Data Handling?

Skills that share tags, products or a category with Windsurf Data Handling: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windsurf Data Handling?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.