Pii Detect
ruvnet/ruflo
Detect and flag personally identifiable information (PII) in text, code, and configurations.
Detect new PII leaks introduced by the current branch. An agent skill from LedgerHQ/ledger-live.
$ npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LedgerHQ/ledger-live detect-data-leaks --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LedgerHQ/ledger-live.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/detect-data-leaks .claude/skills/detect-data-leaks && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "detect-data-leaks" agent skill from https://github.com/LedgerHQ/ledger-live/tree/develop/.agents/skills/detect-data-leaks into .claude/skills/detect-data-leaks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-data-leaks", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LedgerHQ/ledger-live/tree/develop/.agents/skills/detect-data-leaksType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LedgerHQ/ledger-live detect-data-leaks --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LedgerHQ/ledger-live.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/detect-data-leaks .agents/skills/detect-data-leaks && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "detect-data-leaks" agent skill from https://github.com/LedgerHQ/ledger-live/tree/develop/.agents/skills/detect-data-leaks into .agents/skills/detect-data-leaks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-data-leaks", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LedgerHQ/ledger-live detect-data-leaks --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LedgerHQ/ledger-live.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/detect-data-leaks .cursor/skills/detect-data-leaks && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "detect-data-leaks" agent skill from https://github.com/LedgerHQ/ledger-live/tree/develop/.agents/skills/detect-data-leaks into .cursor/skills/detect-data-leaks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-data-leaks", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LedgerHQ/ledger-live.git --path .agents/skills/detect-data-leaks--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LedgerHQ/ledger-live detect-data-leaks --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LedgerHQ/ledger-live.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/detect-data-leaks .gemini/skills/detect-data-leaks && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "detect-data-leaks" agent skill from https://github.com/LedgerHQ/ledger-live/tree/develop/.agents/skills/detect-data-leaks into .gemini/skills/detect-data-leaks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-data-leaks", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LedgerHQ/ledger-live detect-data-leaksInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LedgerHQ/ledger-live.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/detect-data-leaks .github/skills/detect-data-leaks && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "detect-data-leaks" agent skill from https://github.com/LedgerHQ/ledger-live/tree/develop/.agents/skills/detect-data-leaks into .github/skills/detect-data-leaks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-data-leaks", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LedgerHQ/ledger-live detect-data-leaks --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LedgerHQ/ledger-live.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/detect-data-leaks .opencode/skills/detect-data-leaks && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "detect-data-leaks" agent skill from https://github.com/LedgerHQ/ledger-live/tree/develop/.agents/skills/detect-data-leaks into .opencode/skills/detect-data-leaks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-data-leaks", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
detect-data-leaksDetect new PII leaks introduced by the current branch. An agent skill from LedgerHQ/ledger-live.
Detect Data Leaks is an agent skill from LedgerHQ/ledger-live. Detect new PII leaks introduced by the current branch. Use when asked to check for potential data leaks for the current changes.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Mono-repository for Ledger Wallet apps and related packages. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 30d7883. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Detect Data Leaks loads about 1.3k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 467 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LedgerHQ/ledger-live at commit 30d7883, republished under its MIT licence (© LedgerHQ). 467 words, ~1,265 tokens.
.claude/skills/detect-data-leaks/SKILL.md (or your agent's skills folder).We only consider PII that is sent to third-party services. Any call to our own backend with PII is not considered a data leak.
Every third-party service should be considered, but each has a different risk level. Logging services are the highest risk.
Some information is only PII in context — for example, public addresses are not PII by themselves, but on a logging service such as Datadog, an address can be linked to a location and device, allowing identification of the person behind it.
Crash reports need to be studied alongside logs — they are a common source of data leaks.
Any service that queries the blockchain for an address is not a concern — the query is mandatory for the system to function and the data is not linked to any other identifiable information. This applies to all coin modules. Examples:
api.kaspa.orgapi.trongrid.io)Prioritize these, but do not exclude others:
Treat any of these as high-risk when found in added lines:
location.pathname, window.location.hash, address, walletAccountId, txId, publicKey, signature, rawData, payinAddress, fromAccountAddress, toAccountAddress, binaryPayload
Run git diff develop...HEAD. This is the primary source — start here, not from grep.
In added lines, identify:
track(), trackPage(), logger.*(), captureException()In removed lines, identify:
confidentialityFilter, scrubbing calls, PII-stripping wrappers — flag each removal as a potential leak enabler.For each high-risk variable in added lines, trace its lineage:
For each new sink call in the diff:
track()), read its implementation — do not assume from the nameUse the grep commands below only to trace a pattern already found in the diff. Never run them independently to source findings.
Score each finding 1–10. Report only those scoring 7 or higher with a concrete fix.
location.pathname flowing into track() — pathname often assigned before the call:
find apps \( -name "*.ts" -o -name "*.tsx" \) | grep -vE "\.test\.|/__tests__/|/tests/" | \
xargs perl -0777 -ne 'BEGIN { exit unless @ARGV } print "$ARGV\n" if /track(?:Page)?\([\s\S]{0,500}?location\.pathname/'window.location.hash in analytics:
grep -rn "window\.location\.hash" apps/ --include="*.ts" --include="*.tsx"Address interpolated into new Error(...) in coin modules:
find libs \( -name "*.ts" -o -name "*.tsx" \) | grep -vE "live-e2e-shared|coin-tester-modules|__tests__|tests|\.test\." | \
xargs perl -0777 -ne 'BEGIN { exit unless @ARGV } print "$ARGV\n" if /new Error\(`[\s\S]{0,300}?\$\{[^}]*(address|sender|hash|walletAccountId|txId|publicKey)[^}]*\}/i'Signed tx payload on broadcast failure:
grep -rn -E "broadcast_failure|broadcastLogger" apps/ --include="*.ts" | grep -v "\.test\."Full transaction object spread into analytics:
grep -rn -E "value:[[:space:]]*(params|transaction)\b" apps/ --include="*.ts" --include="*.tsx" \
| grep -v "\.test\." \
| grep -vE "value:[[:space:]]*(params|transaction)\."Signed payload fields in track():
grep -rn -E "binaryPayload|payinAddress|fromAccountAddress|toAccountAddress" libs/ apps/ --include="*.ts" --include="*.tsx" \
| grep -vE "\.test\.|/__tests__/|/tests/"Props filter registration (the shared pipeline applies it to both track() and trackPage()):
grep -rn "setPropsFilter(" apps/ --include="*.ts" --include="*.tsx" | grep -v testDesktop registers confidentialityFilter; check whether any other app that sends analytics needs a filter.
🔴 Critical (10/10) — apps/.../useActivityIndicator.ts:39
track("SyncErrorList", { page: location.pathname, ... });
Fix: remove `page` from the payload or replace with a static route label stripped of account IDs.
🟡 Suggestion (8/10) — apps/.../someFile.ts:12
track("Event", { hash: window.location.hash });
Fix: pass only the route segment before the `#`, not the full hash..agents/skills/client-ids/SKILL.md
© LedgerHQ, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/detect-data-leaks of LedgerHQ/ledger-live.
Open the folder on GitHubat commit 30d7883
Detect Data Leaks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Detect Data Leaks this skillLedgerHQ/ledger-live | 622 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Pii Detectruvnet/ruflo | 74k | 1 repos | ~350 | Automated safety check: Notes | MIT | |
| Detecting Memory Leaksjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~934 | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 296k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Threat Detectionalirezarezvani/claude-skills | 28k | — | ~3.5k | Automated safety check: Pass | MIT | |
| Branchesredis/RedisInsight | 8.9k | — | ~409 | Automated safety check: Pass | Custom licence |
ruvnet/ruflo
Detect and flag personally identifiable information (PII) in text, code, and configurations.
jeremylongshore/tons-of-skills-marketplace
Detect potential memory leaks and analyze memory usage patterns in code.
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
alirezarezvani/claude-skills
A skill your agent uses when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.
redis/RedisInsight
Create and name git branches following project conventions. An agent skill from redis/RedisInsight.
github/awesome-copilot
Create Git branches following the Conventional Branch specification (feature/, bugfix/, hotfix/, release/, chore/).
LedgerHQ/ledger-live
Find which open PRs are impacted by a migration/sunset/refactor and notify their authors — blocking review when the old path is already gone from develop, heads-up comment when it is only deprecated…
LedgerHQ/ledger-live
Write, review or debug a cloudSyncModule.ts — a CloudSyncDataManager that syncs one slice of user data through Ledger Sync (Cloud Sync).
LedgerHQ/ledger-live
Maintain CODEOWNERS file and team directories. An agent skill from LedgerHQ/ledger-live.
LedgerHQ/ledger-live
Coin-specific families logic must live in families/. An agent skill from LedgerHQ/ledger-live.
LedgerHQ/ledger-live
Structure a Ledger Wallet data layer where one API response serves several entities.
LedgerHQ/ledger-live
Investigate native React Native crashes (Fabric/Hermes/iOS) in ledger-live-mobile when JS error logs are missing or unhelpful.
Detect new PII leaks introduced by the current branch. An agent skill from LedgerHQ/ledger-live. Detect Data Leaks is an agent skill from LedgerHQ/ledger-live. Detect new PII leaks introduced by the current branch.
Detect Data Leaks fits situations like: asked to check for potential data leaks for the current changes.
Run `npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a claude-code`. Or copy the skill folder (.agents/skills/detect-data-leaks in LedgerHQ/ledger-live) into .claude/skills/detect-data-leaks in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a codex`. Or copy the skill folder (.agents/skills/detect-data-leaks in LedgerHQ/ledger-live) into .agents/skills/detect-data-leaks in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LedgerHQ/ledger-live --skill detect-data-leaks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detect-data-leaks, .gemini/skills/detect-data-leaks, .github/skills/detect-data-leaks and .opencode/skills/detect-data-leaks in your project.
Going by SKILL.md and its folder, Detect Data Leaks needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Detect Data Leaks is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Detect Data Leaks: Pii Detect (ruvnet/ruflo, 74k stars), Detecting Memory Leaks (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Finishing a Development Branch (obra/superpowers, 296k stars) and Threat Detection (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LedgerHQ (a GitHub organization) maintains it in LedgerHQ/ledger-live, which has 622 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 8, 2026.
Source: LedgerHQ/ledger-live on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.