SkillAgentSearch skills...

anth-data-handling

'Implement data privacy, PII handling, and compliance patterns for Claude

Install / Use

npx skills add jeremylongshore/tons-of-skills-marketplace --skill anth-data-handling

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

88/100

Category

Legal

Supported Platforms

Claude Code

Our assessment of anth-data-handling

anth-data-handling scores 88/100 on our quality scale, 62nd of 163 Legal skills we index (top 39%).

Its SKILL.md is 6.6 KB long, well organised into 15 sections with 2 code examples: a thorough specification that gives an agent plenty to work with.

With 2,785 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
29/30
Structure
18/20
Description
12/15
Adoption
15/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 6 days ago, so anth-data-handling is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

anth-data-handling compared with similar skills

All 4 of these similar skills score higher than anth-data-handling; compare them before choosing.

SkillScoreStarsUpdatedFormat
anth-data-handling (this skill)by jeremylongshore882.8k6d agoSKILL.md
Agent-Reachby Panniantong10086.3k14d agoCLAUDE.md
headroomby headroomlabs-ai10074.1ktodayCLAUDE.md
Scraplingby D4Vinci10084.6ktodayMCP Server
crawl4aiby unclecode10084.5k5d agoMCP Server

Frequently asked questions

How do I install anth-data-handling?
Run npx skills add jeremylongshore/tons-of-skills-marketplace --skill anth-data-handling. The install tabs above show the steps for each supported agent.
Which AI agents does anth-data-handling work with?
It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
Is anth-data-handling safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is anth-data-handling still maintained?
The repository was last updated 6 days ago, so anth-data-handling is actively maintained.

name: anth-data-handling description: 'Implement data privacy, PII handling, and compliance patterns for Claude API.

Use when handling sensitive data, implementing PII redaction,

or configuring data retention for GDPR/CCPA compliance with Claude.

Trigger with phrases like "anthropic data privacy", "claude PII",

"anthropic gdpr", "claude data handling", "redact data claude".

' allowed-tools: Read, Write, Edit, Grep version: 1.7.0 license: MIT author: Jeremy Longshore jeremy@intentsolutions.io tags:

  • saas
  • ai
  • anthropic compatibility: Designed for Claude Code

Anthropic Data Handling

Overview

Anthropic's data policies: API inputs/outputs are NOT used for model training (commercial API). Zero-day retention is available. This skill covers PII redaction before sending to Claude and compliance patterns.

Anthropic Data Policies

| Policy | Details | |--------|---------| | Training data | API data is NOT used for training (commercial API) | | Data retention | 30-day default; 0-day available via agreement | | Encryption | TLS 1.2+ in transit, AES-256 at rest | | SOC 2 Type II | Certified | | HIPAA BAA | Available for eligible customers |

PII Redaction Before API Calls

import re
import anthropic

def redact_pii(text: str) -> tuple[str, dict]:
    """Redact PII before sending to Claude, return redaction map for restoration."""
    redaction_map = {}
    patterns = [
        (r'\b\d{3}-\d{2}-\d{4}\b', 'SSN', '[SSN-REDACTED-{}]'),
        (r'\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b', 'EMAIL', '[EMAIL-REDACTED-{}]'),
        (r'\b\d{3}[-.]?\d{3}[-.]?\d{4}\b', 'PHONE', '[PHONE-REDACTED-{}]'),
        (r'\b\d{4}[- ]?\d{4}[- ]?\d{4}[- ]?\d{4}\b', 'CARD', '[CARD-REDACTED-{}]'),
    ]

    counter = 0
    for pattern, label, replacement in patterns:
        for match in re.finditer(pattern, text):
            counter += 1
            placeholder = replacement.format(counter)
            redaction_map[placeholder] = match.group()
            text = text.replace(match.group(), placeholder, 1)

    return text, redaction_map

def restore_pii(text: str, redaction_map: dict) -> str:
    """Restore redacted PII in Claude's response."""
    for placeholder, original in redaction_map.items():
        text = text.replace(placeholder, original)
    return text

# Usage
user_input = "Contact John at john@example.com or 555-123-4567"
safe_input, redactions = redact_pii(user_input)
# safe_input: "Contact John at [EMAIL-REDACTED-1] or [PHONE-REDACTED-2]"

client = anthropic.Anthropic()
msg = client.messages.create(
    model="claude-sonnet-4-20250514",
    max_tokens=256,
    messages=[{"role": "user", "content": safe_input}]
)
final_output = restore_pii(msg.content[0].text, redactions)

Audit Logging

import json
import logging
from datetime import datetime, timezone

audit_logger = logging.getLogger("claude.audit")

def audited_request(client, user_id: str, purpose: str, **kwargs):
    """Wrap Claude API calls with audit logging."""
    # Log request metadata (never log content)
    audit_logger.info(json.dumps({
        "event": "claude.request",
        "timestamp": datetime.now(timezone.utc).isoformat(),
        "user_id": user_id,
        "purpose": purpose,
        "model": kwargs.get("model"),
        "max_tokens": kwargs.get("max_tokens"),
    }))

    response = client.messages.create(**kwargs)

    audit_logger.info(json.dumps({
        "event": "claude.response",
        "request_id": response._request_id,
        "input_tokens": resp…[redacted],
        "output_tokens": resp…[redacted],
        "stop_reason": response.stop_reason,
    }))

    return response

Data Handling Checklist

  • [ ] PII redacted before sending to Claude API
  • [ ] Audit logs capture who accessed what and when
  • [ ] Logs never contain message content or PII
  • [ ] Data retention policy matches your compliance needs
  • [ ] Zero-day retention enabled if required (contact Anthropic)
  • [ ] HIPAA BAA in place if handling PHI
  • [ ] User consent obtained for AI processing
  • [ ] Data deletion procedures documented

Error Handling

| Risk | Mitigation | |------|------------| | PII in prompts | Pre-call redaction pipeline | | PII in responses | Post-call output scanning | | Audit log gaps | Centralized logging with alerting | | Data subject access request | Searchable audit trail by user_id |

Prerequisites

  • Define the data classification, processing purpose, legal basis or user consent, and retention owner before sending anything to the API.
  • Provide an approved redaction policy, a secret-manager-backed API credential, and an allowlisted Anthropic workspace or service boundary.
  • Prepare synthetic fixtures that exercise each PII class and a deletion test; do not use real customer records while validating the pipeline.

Instructions

  1. Classify the input and reject fields outside the approved purpose or destination. Apply deterministic redaction before constructing the request; keep any restoration map encrypted, access-controlled, and short-lived.
  2. Run the redaction, prompt, and response scanners against synthetic fixtures. A failed scan, missing consent, or unexpected content block is a hard stop; do not retry with the original data.
  3. Call the Messages API with the least-privileged credential and only the approved model, workspace, and retention configuration. Do not place prompts, responses, redaction maps, or secrets in logs, traces, metrics, or exception text.
  4. Scan the response before restoration or release. Record only aggregate counts, policy decisions, request identifier, and token metadata, then enforce the documented retention and deletion procedure.
  5. Verify deletion in the sandbox and retain a redacted audit receipt for the owner and compliance reviewer.

Output

Produce a redacted data-handling receipt containing the purpose, policy version, environment, workspace class, redaction and response-scan outcomes, request identifier, token counts, retention deadline, deletion result, and reviewer. Exclude names, contact details, prompt/response text, raw identifiers, redaction maps, and credentials.

Examples

For a synthetic fixture such as customer_id=fixture-017; email=test@example.invalid; purpose=classification, redact the email, call a sandbox workspace, assert raw_pii_sent=0 and sensitive_content_logged=0, and emit redaction=pass; output_scan=pass; retention=24h; deletion=verified. Never substitute a real person or production record in this example.

Resources

Next Steps

For enterprise access control, see anth-enterprise-rbac.

Related Skills

View on GitHub
GitHub Stars2.8k
CategoryLegal
Updated6d ago
Forks404

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions