Personally identifiable information (PII) leak prevention for EverClaw.

MITAuto-check passedDevelopment

Install Pii Guard

skills CLI
$ npx skills add profbernardoj/everclaw-community-branches --skill pii-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install profbernardoj/everclaw-community-branches pii-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/profbernardoj/everclaw-community-branches.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pii-guard .claude/skills/pii-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pii-guard
GitHub stars
112
Token cost
~921 tokens
SKILL.md length
341 words
Files
5
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Personally identifiable information (PII) leak prevention for EverClaw.

  • Works in 5 steps: Pattern File → Scanning → Behavior: HARD BLOCK → …
  • Checking content for PII before external actions
  • SKILL.md covers Purpose, When This Fires, How It Works and Adding New Patterns, plus 1 more section
  • Runs Shell scripts from its folder; calls git

What it does

Pii Guard is an agent skill from profbernardoj/everclaw-community-branches. Personally identifiable information (PII) leak prevention for EverClaw. Scans outbound content against configurable PII patterns before git push, email, social media, ClawHub publishing, GitHub interactions, or any external data transmission. Provides git pre-push hooks, CLI scanning tools, and hard-block enforcement with user override capability. Use when checking content for PII before external actions, adding new protected patterns, configuring git pre-push hooks, or auditing data leak prevention.

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `pii-patterns.template.json`, `pii-scan.sh` and `setup.sh`).

It sits in Development, covering Git workflow and Vulnerability scanning. It works with Git and GitHub. The repository describes itself as: Decentralized AI inference for OpenClaw agents. Powered by Morpheus AI. Stake MOR, access Kimi K2.5 + 10 models, never run out of inference. The licence is MIT.

When your agent uses it

  • Checking content for PII before external actions
  • Adding new protected patterns
  • Configuring git pre-push hooks
  • Auditing data leak prevention

Example prompts

  • “/pii-guard”

Requirements

  • A Bash shell

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Pattern File
  2. Scanning
  3. Behavior: HARD BLOCK
  4. Git Pre-Push Hook
  5. Agent Integration

What it can do on your machine

Read from SKILL.md and the folder at commit 0b30b36. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pii Guard loads about 921 tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 341 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~921

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from profbernardoj/everclaw-community-branches at commit 0b30b36, republished under its MIT licence (© profbernardoj). 341 words, ~921 tokens.

Download SKILL.mdSave it as .claude/skills/pii-guard/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
pii-guard
description
Personally identifiable information (PII) leak prevention for EverClaw. Scans outbound content against configurable PII patterns before git push, email, social media, ClawHub publishing, GitHub interactions, or any external data transmission. Provides git pre-push hooks, CLI scanning tools, and hard-block enforcement with user override capability. Use when checking content for PII before external actions, adding new protected patterns, configuring git pre-push hooks, or auditing data leak prevention.

PII Guard — Personal Data Leak Prevention

Purpose

Prevents personal identifiable information (PII) from being sent to external services. This skill MUST be checked before any outbound action that transmits data externally.

When This Fires

Mandatory check before:

  • git push (any repo)
  • Sending emails
  • Posting to social media (X/Twitter, Moltbook, etc.)
  • Publishing to ClawHub
  • Creating/updating GitHub issues, PRs, discussions, or comments
  • Any message action to external channels with file attachments
  • Any web_fetch POST or form submission
  • Any exec command that sends data externally (curl POST, scp, rsync, etc.)

How It Works

1. Pattern File

All protected patterns live in the workspace:

~/.openclaw/workspace/.pii-patterns.json

This file is NEVER committed — it contains the very data it protects.

2. Scanning

The scanner checks content against all patterns in these categories:

  • names — Protected personal names
  • emails — Protected email addresses
  • phones — Protected phone numbers (all formats)
  • wallets — Protected blockchain addresses
  • organizations — Protected org/church/school names
  • people — Protected associate/contact names
  • websites — Protected personal domains
  • keywords — Any other protected strings
3. Behavior: HARD BLOCK

When PII is detected:

  1. STOP — Do not proceed with the external action
  2. REPORT — Tell the user exactly what was found and where
  3. WAIT — Only proceed if the user explicitly confirms after reviewing

Error format:

🚫 PII GUARD: Blocked — personal data detected

Found in: <filename or content description>
Match: "<the matched pattern>"
Category: <names|emails|phones|etc>

Action blocked: <what was about to happen>
To proceed: Remove the PII or explicitly confirm override.
4. Git Pre-Push Hook

A global git hook is installed at:

~/.openclaw/workspace/scripts/git-hooks/pre-push

Configured via: git config --global core.hooksPath ~/.openclaw/workspace/scripts/git-hooks

This runs automatically on every git push across ALL repos on this machine.

  • Scans the diff being pushed (not just HEAD)
  • Blocks push if PII detected
  • Can be bypassed with git push --no-verify (use with extreme caution)
5. Agent Integration

The agent should call pii_scan before external actions:

bash
# Scan a file
~/.openclaw/workspace/scripts/pii-scan.sh <file_or_directory>

# Scan stdin
echo "some content" | ~/.openclaw/workspace/scripts/pii-scan.sh -

# Scan a string
~/.openclaw/workspace/scripts/pii-scan.sh --text "check this string"

Exit codes:

  • 0 — Clean, no PII found
  • 1 — PII detected (blocked)
  • 2 — Error (patterns file missing, etc.)

Adding New Patterns

Edit ~/.openclaw/workspace/.pii-patterns.json and add entries to the appropriate category array. Changes take effect immediately — no restart needed.

Security Notes

  • .pii-patterns.json must NEVER be committed to any repo
  • The patterns file itself contains PII — treat it as sensitive
  • The hook and scan scripts are safe to publish (they contain no PII)
  • When in doubt, scan first

© profbernardoj, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in skills/pii-guard of profbernardoj/everclaw-community-branches.

  • SKILL.md
  • pii-patterns.template.json
  • pii-scan.sh
  • pre-push
  • setup.sh

Open the folder on GitHubat commit 0b30b36

Compare with similar skills

Pii Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pii Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pii Guard this skillprofbernardoj/everclaw-community-branches112—~921Automated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Release Bumpjamiepine/voicebox57k—~1.1kAutomated safety check: PassMIT
Creating Description For Gh PRredis/jedis12k—~838Automated safety check: PassMIT
Create Pull Request with Work Item IDmakeplane/plane61k—~824Automated safety check: PassAGPL-3.0

Similar skills

  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Release Bump

    jamiepine/voicebox

    Ends a release cycle by moving the Unreleased changelog notes under a dated version heading, bumping version files with bumpversion and tagging the commit.

    57k GitHub stars~1.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Official

    Generate a clear, concise GitHub PR title and description from the diff between two local git branches, and save it to prDescription.md in the repo root.

    12k GitHub stars~838 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Opens a pull request for the current branch using the repo's template, a work item ID in the title and a description filled in from the actual diff.

    61k GitHub stars~824 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • React Router Pull Request Creator

    remix-run/react-router

    Packages finished React Router work into a draft pull request: branch, commit, push, a written PR body and the right GitHub labels.

    57k GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from profbernardoj/everclaw-community-branches

All 12 skills in this repo
  • Memory Upgrade

    profbernardoj/everclaw-community-branches

    Diagnose and fix broken memory search in OpenClaw. An agent skill from profbernardoj/everclaw-community-branches.

    112 GitHub stars~574 tokensUpdated 1 mo ago
    Auto-check passed
  • Relationships

    profbernardoj/everclaw-community-branches

    Relationship CRM for tracking people, connections, and context.

    112 GitHub stars~765 tokensUpdated 1 mo ago
    Auto-check passed
  • Agent Chat

    profbernardoj/everclaw-community-branches

    XMTP real-time agent-to-agent and user-to-agent encrypted messaging daemon for EverClaw.

    112 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Bagman

    profbernardoj/everclaw-community-branches

    Secure key management for AI agents. An agent skill from profbernardoj/everclaw-community-branches.

    112 GitHub stars~4.4k tokensUpdated 1 mo ago
    Auto-check: warnings
  • Night Shift

    profbernardoj/everclaw-community-branches

    Automated overnight task planning and execution engine for EverClaw.

    112 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Xmtp Comms Guard

    profbernardoj/everclaw-community-branches

    Security middleware for all XMTP communications in EverClaw.

    112 GitHub stars~523 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Pii Guard

What does Pii Guard do?

Personally identifiable information (PII) leak prevention for EverClaw. Pii Guard is an agent skill from profbernardoj/everclaw-community-branches. Personally identifiable information (PII) leak prevention for EverClaw.

When should I use Pii Guard?

Pii Guard fits situations like: checking content for PII before external actions; adding new protected patterns; configuring git pre-push hooks; auditing data leak prevention.

How do I install Pii Guard in Claude Code?

Run `npx skills add profbernardoj/everclaw-community-branches --skill pii-guard -a claude-code`. Or copy the skill folder (skills/pii-guard in profbernardoj/everclaw-community-branches) into .claude/skills/pii-guard in your project. Claude Code loads it when a task matches its description.

How do I install Pii Guard in Codex?

Run `npx skills add profbernardoj/everclaw-community-branches --skill pii-guard -a codex`. Or copy the skill folder (skills/pii-guard in profbernardoj/everclaw-community-branches) into .agents/skills/pii-guard in your project. Codex loads it when a task matches its description.

Can I use Pii Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add profbernardoj/everclaw-community-branches --skill pii-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pii-guard, .gemini/skills/pii-guard, .github/skills/pii-guard and .opencode/skills/pii-guard in your project.

What does Pii Guard need to run?

Going by SKILL.md and its folder, Pii Guard needs a shell for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: A Bash shell.

Does Pii Guard access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Pii Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pii Guard use?

Pii Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pii Guard use?

About 921 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pii Guard?

Skills that share tags, products or a category with Pii Guard: Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Create Pull Request (cline/cline, 70k stars), Release Bump (jamiepine/voicebox, 57k stars) and Creating Description For Gh PR (redis/jedis, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pii Guard?

profbernardoj (a GitHub user) maintains it in profbernardoj/everclaw-community-branches, which has 112 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on September 2, 2026.

Source: profbernardoj/everclaw-community-branches on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.