Agent skill

Detect Data Leaks

by LedgerHQ in LedgerHQ/ledger-live

Detect new PII leaks introduced by the current branch. An agent skill from LedgerHQ/ledger-live.

MITAuto-check passed

Install Detect Data Leaks

skills CLI
$ npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LedgerHQ/ledger-live detect-data-leaks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LedgerHQ/ledger-live.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/detect-data-leaks .claude/skills/detect-data-leaks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detect-data-leaks
GitHub stars
622
Token cost
~1.3k tokens
SKILL.md length
467 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Detect new PII leaks introduced by the current branch. An agent skill from LedgerHQ/ledger-live.

  • Works in 7 steps: Run git diff develop...HEAD. This is the… → In added lines, identify → In removed lines, identify → …
  • Asked to check for potential data leaks for the current changes
  • Calls git

What it does

Detect Data Leaks is an agent skill from LedgerHQ/ledger-live. Detect new PII leaks introduced by the current branch. Use when asked to check for potential data leaks for the current changes.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Mono-repository for Ledger Wallet apps and related packages. The licence is MIT.

When your agent uses it

  • Asked to check for potential data leaks for the current changes

Example prompts

  • “/detect-data-leaks”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Run git diff develop...HEAD. This is the primary source — start here, not from grep.
  2. In added lines, identify
  3. In removed lines, identify
  4. For each high-risk variable in added lines, trace its lineage
  5. For each new sink call in the diff
  6. Use the grep commands below only to trace a pattern already found in the diff. Never run them independently to source findings.
  7. Score each finding 1–10. Report only those scoring 7 or higher with a concrete fix.

What it can do on your machine

Read from SKILL.md and the folder at commit 30d7883. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detect Data Leaks loads about 1.3k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 467 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LedgerHQ/ledger-live at commit 30d7883, republished under its MIT licence (© LedgerHQ). 467 words, ~1,265 tokens.

Download SKILL.mdSave it as .claude/skills/detect-data-leaks/SKILL.md (or your agent's skills folder).
name
detect-data-leaks
description
Detect new PII leaks introduced by the current branch. Use when asked to check for potential data leaks for the current changes.

Scope — what is PII, what is NOT

We only consider PII that is sent to third-party services. Any call to our own backend with PII is not considered a data leak.

Every third-party service should be considered, but each has a different risk level. Logging services are the highest risk.

Some information is only PII in context — for example, public addresses are not PII by themselves, but on a logging service such as Datadog, an address can be linked to a location and device, allowing identification of the person behind it.

Crash reports need to be studied alongside logs — they are a common source of data leaks.

Any service that queries the blockchain for an address is not a concern — the query is mandatory for the system to function and the data is not linked to any other identifiable information. This applies to all coin modules. Examples:

  • Kaspa → api.kaspa.org
  • EVM (Ethereum, BSC, Polygon…) → Etherscan-family
  • Tron → TronGrid (api.trongrid.io)

Known third-party sinks in this repo

Prioritize these, but do not exclude others:

  • Datadog
  • Sentry
  • Mixpanel

High-risk variables

Treat any of these as high-risk when found in added lines:

location.pathname, window.location.hash, address, walletAccountId, txId, publicKey, signature, rawData, payinAddress, fromAccountAddress, toAccountAddress, binaryPayload

Process

  1. Run git diff develop...HEAD. This is the primary source — start here, not from grep.

  2. In added lines, identify:

    • Assignments of high-risk variables (see above)
    • New calls to third-party sinks or wrappers: track(), trackPage(), logger.*(), captureException()
  3. In removed lines, identify:

    • Removed guards: confidentialityFilter, scrubbing calls, PII-stripping wrappers — flag each removal as a potential leak enabler.
  4. For each high-risk variable in added lines, trace its lineage:

    • Check if it flows into a sink call within the diff
    • If it may pass through intermediate calls, read the affected file to follow the chain
  5. For each new sink call in the diff:

    • Read surrounding context in the file
    • Follow the call chain to determine what gets serialized
    • If the call is a wrapper (e.g. track()), read its implementation — do not assume from the name
  6. Use the grep commands below only to trace a pattern already found in the diff. Never run them independently to source findings.

  7. Score each finding 1–10. Report only those scoring 7 or higher with a concrete fix.

Show full SKILL.md (94 more words)Show less

Grep helpers (investigation only)

location.pathname flowing into track() — pathname often assigned before the call:

bash
find apps \( -name "*.ts" -o -name "*.tsx" \) | grep -vE "\.test\.|/__tests__/|/tests/" | \
  xargs perl -0777 -ne 'BEGIN { exit unless @ARGV } print "$ARGV\n" if /track(?:Page)?\([\s\S]{0,500}?location\.pathname/'

window.location.hash in analytics:

bash
grep -rn "window\.location\.hash" apps/ --include="*.ts" --include="*.tsx"

Address interpolated into new Error(...) in coin modules:

bash
find libs \( -name "*.ts" -o -name "*.tsx" \) | grep -vE "live-e2e-shared|coin-tester-modules|__tests__|tests|\.test\." | \
  xargs perl -0777 -ne 'BEGIN { exit unless @ARGV } print "$ARGV\n" if /new Error\(`[\s\S]{0,300}?\$\{[^}]*(address|sender|hash|walletAccountId|txId|publicKey)[^}]*\}/i'

Signed tx payload on broadcast failure:

bash
grep -rn -E "broadcast_failure|broadcastLogger" apps/ --include="*.ts" | grep -v "\.test\."

Full transaction object spread into analytics:

bash
grep -rn -E "value:[[:space:]]*(params|transaction)\b" apps/ --include="*.ts" --include="*.tsx" \
  | grep -v "\.test\." \
  | grep -vE "value:[[:space:]]*(params|transaction)\."

Signed payload fields in track():

bash
grep -rn -E "binaryPayload|payinAddress|fromAccountAddress|toAccountAddress" libs/ apps/ --include="*.ts" --include="*.tsx" \
  | grep -vE "\.test\.|/__tests__/|/tests/"

Props filter registration (the shared pipeline applies it to both track() and trackPage()):

bash
grep -rn "setPropsFilter(" apps/ --include="*.ts" --include="*.tsx" | grep -v test

Desktop registers confidentialityFilter; check whether any other app that sends analytics needs a filter.

Output format

  • Score mapping: 9-10 → 🔴 Critical, 7–8 → 🟡 Suggestion. Scores below 7 are not reported.
  • If no findings reach score 7, produce no output.
🔴 Critical (10/10) — apps/.../useActivityIndicator.ts:39
track("SyncErrorList", { page: location.pathname, ... });
Fix: remove `page` from the payload or replace with a static route label stripped of account IDs.

🟡 Suggestion (8/10) — apps/.../someFile.ts:12
track("Event", { hash: window.location.hash });
Fix: pass only the route segment before the `#`, not the full hash.

References

.agents/skills/client-ids/SKILL.md

© LedgerHQ, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/detect-data-leaks of LedgerHQ/ledger-live.

Open the folder on GitHubat commit 30d7883

Compare with similar skills

Detect Data Leaks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detect Data Leaks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detect Data Leaks this skillLedgerHQ/ledger-live622—~1.3kAutomated safety check: PassMIT
Pii Detectruvnet/ruflo74k1 repos~350Automated safety check: NotesMIT
Detecting Memory Leaksjeremylongshore/tons-of-skills-marketplace2.8k—~934Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Threat Detectionalirezarezvani/claude-skills28k—~3.5kAutomated safety check: PassMIT
Branchesredis/RedisInsight8.9k—~409Automated safety check: PassCustom licence

Similar skills

  • Pii Detect

    ruvnet/ruflo

    Detect and flag personally identifiable information (PII) in text, code, and configurations.

    74k GitHub starsUsed in 1 repo~350 tokens
    Auto-check: notes
  • Detecting Memory Leaks

    jeremylongshore/tons-of-skills-marketplace

    Detect potential memory leaks and analyze memory usage patterns in code.

    2.8k GitHub stars~934 tokensUpdated today
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Threat Detection

    alirezarezvani/claude-skills

    A skill your agent uses when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.

    28k GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Branches

    redis/RedisInsight

    Official

    Create and name git branches following project conventions. An agent skill from redis/RedisInsight.

    8.9k GitHub stars~409 tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Conventional Branch

    github/awesome-copilot

    Official

    Create Git branches following the Conventional Branch specification (feature/, bugfix/, hotfix/, release/, chore/).

    40k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed

More from LedgerHQ/ledger-live

All 50 skills in this repo
  • Impacting PRs

    LedgerHQ/ledger-live

    Find which open PRs are impacted by a migration/sunset/refactor and notify their authors — blocking review when the old path is already gone from develop, heads-up comment when it is only deprecated…

    622 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Cloud Sync Module

    LedgerHQ/ledger-live

    Write, review or debug a cloudSyncModule.ts — a CloudSyncDataManager that syncs one slice of user data through Ledger Sync (Cloud Sync).

    622 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Codeownership

    LedgerHQ/ledger-live

    Maintain CODEOWNERS file and team directories. An agent skill from LedgerHQ/ledger-live.

    622 GitHub stars~687 tokensUpdated today
    Auto-check passed
  • Coin Families Contract

    LedgerHQ/ledger-live

    Coin-specific families logic must live in families/. An agent skill from LedgerHQ/ledger-live.

    622 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Data Layer Advanced

    LedgerHQ/ledger-live

    Structure a Ledger Wallet data layer where one API response serves several entities.

    622 GitHub stars~509 tokensUpdated today
    Auto-check passed
  • Debug Rn Native Crash

    LedgerHQ/ledger-live

    Investigate native React Native crashes (Fabric/Hermes/iOS) in ledger-live-mobile when JS error logs are missing or unhelpful.

    622 GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Questions about Detect Data Leaks

What does Detect Data Leaks do?

Detect new PII leaks introduced by the current branch. An agent skill from LedgerHQ/ledger-live. Detect Data Leaks is an agent skill from LedgerHQ/ledger-live. Detect new PII leaks introduced by the current branch.

When should I use Detect Data Leaks?

Detect Data Leaks fits situations like: asked to check for potential data leaks for the current changes.

How do I install Detect Data Leaks in Claude Code?

Run `npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a claude-code`. Or copy the skill folder (.agents/skills/detect-data-leaks in LedgerHQ/ledger-live) into .claude/skills/detect-data-leaks in your project. Claude Code loads it when a task matches its description.

How do I install Detect Data Leaks in Codex?

Run `npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a codex`. Or copy the skill folder (.agents/skills/detect-data-leaks in LedgerHQ/ledger-live) into .agents/skills/detect-data-leaks in your project. Codex loads it when a task matches its description.

Can I use Detect Data Leaks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detect-data-leaks, .gemini/skills/detect-data-leaks, .github/skills/detect-data-leaks and .opencode/skills/detect-data-leaks in your project.

What does Detect Data Leaks need to run?

Going by SKILL.md and its folder, Detect Data Leaks needs the command-line tools its instructions call (git).

Does Detect Data Leaks access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Detect Data Leaks safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Detect Data Leaks use?

Detect Data Leaks is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detect Data Leaks use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Detect Data Leaks?

Skills that share tags, products or a category with Detect Data Leaks: Pii Detect (ruvnet/ruflo, 74k stars), Detecting Memory Leaks (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Finishing a Development Branch (obra/superpowers, 296k stars) and Threat Detection (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detect Data Leaks?

LedgerHQ (a GitHub organization) maintains it in LedgerHQ/ledger-live, which has 622 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 8, 2026.

Source: LedgerHQ/ledger-live on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.