Generating Synthetic Surrogates
maziyarpanahi/openmed
Replace detected PHI with realistic, type-matched fake values in OpenMed so clinical notes stay readable and parseable instead of full of [REDACTED] markers.
Assessment of pseudonymization techniques and re-identification risk.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill pseudonymization-risk -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills pseudonymization-risk --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/pseudonymization-risk .claude/skills/pseudonymization-risk && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pseudonymization-risk" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/pseudonymization-risk into .claude/skills/pseudonymization-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymization-risk", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/pseudonymization-riskType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill pseudonymization-risk -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills pseudonymization-risk --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/pseudonymization-risk .agents/skills/pseudonymization-risk && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pseudonymization-risk" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/pseudonymization-risk into .agents/skills/pseudonymization-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymization-risk", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill pseudonymization-risk -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills pseudonymization-risk --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/pseudonymization-risk .cursor/skills/pseudonymization-risk && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pseudonymization-risk" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/pseudonymization-risk into .cursor/skills/pseudonymization-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymization-risk", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/pseudonymization-risk--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill pseudonymization-risk -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills pseudonymization-risk --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/pseudonymization-risk .gemini/skills/pseudonymization-risk && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pseudonymization-risk" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/pseudonymization-risk into .gemini/skills/pseudonymization-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymization-risk", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills pseudonymization-riskInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill pseudonymization-risk -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/pseudonymization-risk .github/skills/pseudonymization-risk && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pseudonymization-risk" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/pseudonymization-risk into .github/skills/pseudonymization-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymization-risk", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill pseudonymization-risk -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills pseudonymization-risk --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/pseudonymization-risk .opencode/skills/pseudonymization-risk && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pseudonymization-risk" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/pseudonymization-risk into .opencode/skills/pseudonymization-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymization-risk", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pseudonymization-riskAssessment of pseudonymization techniques and re-identification risk.
Pseudonymization Risk is an agent skill from mukul975/Privacy-Data-Protection-Skills. Assessment of pseudonymization techniques and re-identification risk. Covers tokenization, hashing, encryption-based pseudonymization, and hybrid approaches. Includes re-identification risk scoring using the motivated intruder test, quantitative metrics (marketer, journalist, prosecutor models), and linkage attack resilience evaluation. References ENISA 2019 pseudonymization report.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Cryptography, Natural language processing and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pseudonymization Risk loads about 3.2k tokens when it runs, and up to ~7.3k if it reads all its reference files. Until then it costs about 102 tokens; SKILL.md has 1,418 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,418 words, ~3,240 tokens.
.claude/skills/pseudonymization-risk/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Pseudonymization (GDPR Article 4(5)) means processing personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure non-attribution. Unlike anonymization (Recital 26), pseudonymized data remains personal data — but it significantly reduces risk and is explicitly recognized as an appropriate safeguard under Articles 25, 32, and 89.
The ENISA report "Pseudonymisation Techniques and Best Practices" (November 2019) provides a comprehensive taxonomy of pseudonymization techniques and their properties. This skill implements a structured assessment framework for selecting appropriate techniques and quantifying residual re-identification risk.
| Property | Value |
|---|---|
| Mechanism | Sequential or random counter assigned to each identifier |
| Reversibility | Reversible via lookup table |
| Collision resistance | Guaranteed (bijective mapping) |
| Performance | O(1) lookup |
| Storage overhead | Mapping table size proportional to identifier count |
| Key management | Protect the mapping table as additional information |
Prism Data Systems AG Implementation: Customer IDs are replaced with UUIDv4 pseudonyms at the analytics ingestion boundary. The mapping table is stored in a separate HSM-backed database accessible only to the DPO and the identity resolution service (which requires dual-approval access).
| Property | Value |
|---|---|
| Mechanism | HMAC-SHA256 with secret key applied to identifier |
| Reversibility | Not directly reversible; vulnerable to brute-force on low-entropy inputs |
| Collision resistance | Negligible collision probability (256-bit output) |
| Performance | O(1) computation |
| Storage overhead | Fixed 32-byte output per identifier |
| Key management | HMAC key must be protected as additional information |
Risk: Plain SHA-256 hashing (without key) is vulnerable to rainbow table attacks on low-entropy identifiers like email addresses. HMAC with a secret key mitigates this but the key becomes the single point of re-identification.
Prism Data Systems AG Implementation: HMAC-SHA256 with a 256-bit key rotated quarterly is used for pseudonymizing user identifiers in the analytics pipeline. The HMAC key is stored in AWS KMS with access restricted to the pseudonymization service account. Key rotation triggers re-pseudonymization of the active analytics dataset.
| Property | Value |
|---|---|
| Mechanism | AES-256-GCM or format-preserving encryption (FF1/FF3-1) |
| Reversibility | Fully reversible with decryption key |
| Collision resistance | Guaranteed (bijective for same key) |
| Performance | O(1) computation; FPE slower than standard AES |
| Storage overhead | Ciphertext size ≈ plaintext + 16-byte tag (GCM) |
| Key management | Encryption key is the additional information per Art. 4(5) |
Format-Preserving Encryption preserves the format of the original identifier (e.g., encrypting a 10-digit phone number produces another 10-digit number), enabling pseudonymization without schema changes.
Prism Data Systems AG Implementation: FPE (FF3-1 mode) is used for pseudonymizing phone numbers and IBAN fields in the support ticket system. This allows Tier 1 support agents to see structurally valid but pseudonymized identifiers, reducing accidental exposure while maintaining workflow compatibility.
| Property | Value |
|---|---|
| Mechanism | Random token generated and stored in a secure vault; no mathematical relationship to original |
| Reversibility | Reversible only via vault lookup |
| Collision resistance | Guaranteed by vault uniqueness constraint |
| Performance | O(1) vault lookup; network latency for centralized vault |
| Storage overhead | Vault stores original-to-token mapping |
| Key management | Vault access controls replace key management |
Prism Data Systems AG Implementation: Payment card data is tokenized using a PCI DSS-compliant token vault. The vault is operated by the payment processor and is logically separated from Prism's infrastructure. Detokenization requires a PCI-scoped service account with transaction-level authorization.
| Property | Value |
|---|---|
| Mechanism | Replace real identifiers with structurally similar but fictional values |
| Reversibility | Not reversible (one-way replacement) |
| Collision resistance | Depends on generation method; risk of accidental collision with real data |
| Performance | O(1) generation |
| Storage overhead | No mapping table needed (irreversible) |
| Key management | Not applicable |
Use case: Test environments where referential integrity must be maintained but no re-identification path is acceptable.
| Criterion | Counter | HMAC | Encryption | Tokenization | Synthetic |
|---|---|---|---|---|---|
| Reversibility | Lookup table | Brute-force only | Decryption key | Vault lookup | Irreversible |
| Deterministic | Configurable | Yes (same key) | Yes (same key+IV) | Configurable | No |
| Format preserving | No | No | FPE only | Configurable | Yes |
| Linkability (same dataset) | Yes | Yes | Yes | Configurable | No |
| Linkability (cross-dataset) | No | Same key: Yes | Same key: Yes | No | No |
| Brute-force resistance | N/A | Key-dependent | Key-dependent | N/A | N/A |
| Suited for analytics | Yes | Yes | Limited | Yes | Limited |
| Suited for testing | No | No | No | Yes | Yes |
| ENISA recommendation level | Basic | Intermediate | Advanced | Advanced | Specialized |
The UK Information Commissioner's Office (ICO) Anonymisation Code of Practice defines the motivated intruder test: would a reasonably competent, motivated person with access to resources such as the internet, public libraries, and public records be able to identify an individual from the pseudonymized data?
Assessment Factors:
| Factor | Low Risk (1) | Medium Risk (3) | High Risk (5) |
|---|---|---|---|
| Population uniqueness | Common attributes, large equivalence classes | Moderate uniqueness, some rare combinations | Highly unique attribute combinations |
| Auxiliary information availability | No public datasets linkable | Some public records overlap | Rich public profiles (social media, registers) |
| Identifier entropy | High entropy (e.g., UUID) | Medium entropy (e.g., hashed email) | Low entropy (e.g., hashed phone number) |
| Dataset richness | Few quasi-identifiers | Moderate quasi-identifiers (5-10) | Many quasi-identifiers (>10) |
| Temporal precision | Yearly or coarser | Monthly | Daily or finer |
| Geographic precision | Country level | Region/city level | Postcode or finer |
| Domain sensitivity | Low sensitivity domain | Moderate sensitivity | Health, financial, political data |
The attacker knows a specific individual is in the dataset and attempts to find their record. Risk = 1 / k, where k is the size of the equivalence class containing the target record.
The attacker does not know if the target is in the dataset but attempts to re-identify any individual for a story. Risk = max(1/k) across all equivalence classes (the smallest group is most vulnerable).
The attacker attempts to re-identify as many individuals as possible. Risk = (1/n) * Σ(1/k_i) — the average re-identification probability across all records.
| Attack Type | Description | Mitigation |
|---|---|---|
| Record linkage | Matching pseudonymized records with identified records in external datasets using quasi-identifiers | Generalize quasi-identifiers, enforce k-anonymity |
| Attribute linkage | Inferring sensitive attributes from group characteristics even without identifying the individual | Enforce l-diversity on sensitive attributes |
| Table linkage | Determining that an individual is present in a sensitive dataset (membership inference) | Apply differential privacy, enforce t-closeness |
| Composition attack | Combining multiple independent pseudonymized releases to narrow equivalence classes | Track cumulative privacy budget, limit releases |
| Temporal linkage | Linking records across time periods using behavioral patterns or trajectory data | Apply temporal generalization, add noise to timestamps |
Score the pseudonymization technique on five properties:
| Property | Weight | Score Range |
|---|---|---|
| Key/mapping security | 30% | 0-100 based on key management maturity |
| Brute-force resistance | 25% | 0-100 based on input entropy and computational cost |
| Cross-dataset unlinkability | 20% | 0-100 based on determinism and key reuse |
| Implementation maturity | 15% | 0-100 based on library validation and audit history |
| Operational resilience | 10% | 0-100 based on key rotation, backup, disaster recovery |
Score the data environment on re-identification risk factors:
| Factor | Weight | Score Range |
|---|---|---|
| Population uniqueness | 25% | 0-100 (higher = more unique = higher risk) |
| Auxiliary data availability | 25% | 0-100 (higher = more auxiliary data = higher risk) |
| Quasi-identifier count | 20% | 0-100 based on number and granularity |
| Dataset size | 15% | 0-100 (smaller datasets = higher risk per record) |
| Release frequency | 15% | 0-100 (more frequent releases = higher composition risk) |
Residual Risk = Data Environment Risk × (1 - Technique Score / 100)| Residual Risk Range | Classification | Action Required |
|---|---|---|
| 0-15 | Low | Acceptable. Document and monitor |
| 16-35 | Moderate | Additional controls recommended |
| 36-60 | High | Technique upgrade or data reduction required |
| 61-100 | Very High | Processing should not proceed without anonymization |
| Data Flow | Technique | Technique Score | Environment Risk | Residual Risk | Classification |
|---|---|---|---|---|---|
| Analytics pipeline | HMAC-SHA256 (keyed) | 78 | 42 | 9.2 | Low |
| Support dashboard | FPE (FF3-1) | 82 | 35 | 6.3 | Low |
| Payment processing | Tokenization (vault) | 91 | 55 | 5.0 | Low |
| Test environments | Synthetic replacement | 95 | 20 | 1.0 | Low |
| Research exports | Counter + k-anonymity | 72 | 58 | 16.2 | Moderate |
| ML training data | HMAC + differential privacy | 85 | 48 | 7.2 | Low |
The research exports flow received a "Moderate" classification due to the combination of rich quasi-identifiers in the exported dataset and the counter-based technique's susceptibility to record linkage. Remediation: apply l-diversity (l≥3) on sensitive attributes and generalize quasi-identifiers to achieve k≥11 before export.
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/pseudonymization-risk of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Pseudonymization Risk next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pseudonymization Risk this skillmukul975/Privacy-Data-Protection-Skills | 295 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Generating Synthetic Surrogatesmaziyarpanahi/openmed | 5.5k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Data Protection And Encryptioncbrock84/headcount | 2k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Clade Security Basicsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.1k | Automated safety check: Notes | MIT | |
| Stellar DevVelaPayments/vela-payments | 131 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Security Compliancesangrokjung/claude-forge | 850 | 2 repos | ~7.2k | Automated safety check: Pass | MIT |
maziyarpanahi/openmed
Replace detected PHI with realistic, type-matched fake values in OpenMed so clinical notes stay readable and parseable instead of full of [REDACTED] markers.
cbrock84/headcount
Protects data itself rather than the systems around it — classifying what you hold, encrypting in transit and at rest and understanding what each actually defends against, managing keys and their…
jeremylongshore/tons-of-skills-marketplace
Secure your Anthropic integration — API key management, input validation, Use when working with security-basics patterns.
VelaPayments/vela-payments
End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments.
sangrokjung/claude-forge
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…
davila7/claude-code-templates
A skill your agent uses when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU…
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
mukul975/Privacy-Data-Protection-Skills
Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.
Assessment of pseudonymization techniques and re-identification risk. Pseudonymization Risk is an agent skill from mukul975/Privacy-Data-Protection-Skills. Assessment of pseudonymization techniques and re-identification risk.
Pseudonymization Risk fits situations like: tasks that involve Cryptography; tasks that involve Natural language processing; tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill pseudonymization-risk -a claude-code`. Or copy the skill folder (skills/privacy/pseudonymization-risk in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/pseudonymization-risk in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill pseudonymization-risk -a codex`. Or copy the skill folder (skills/privacy/pseudonymization-risk in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/pseudonymization-risk in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill pseudonymization-risk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pseudonymization-risk, .gemini/skills/pseudonymization-risk, .github/skills/pseudonymization-risk and .opencode/skills/pseudonymization-risk in your project.
Going by SKILL.md and its folder, Pseudonymization Risk needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Pseudonymization Risk is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Pseudonymization Risk: Generating Synthetic Surrogates (maziyarpanahi/openmed, 5.5k stars), Data Protection And Encryption (cbrock84/headcount, 2k stars), Clade Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Stellar Dev (VelaPayments/vela-payments, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.