Data Leakage Prevention in Skills
Overview
Safeguard against accidental personal data leakage when authoring Hermes skills. Ensures no PII (personally identifiable information), secrets, credentials, or sensitive data is embedded in SKILL.md content, template files, references, or script examples.
When to Use
- Before creating any new skill
- When reviewing/editing existing skills for privacy compliance
- When a skill will process user data
- When writing example templates that might contain sample data
The Risk: How Skills Leak Data
Skills can leak data through multiple vectors:
- Example content: Templates with hardcoded names, emails, addresses, phone numbers
- Configuration files: Scripts with embedded API keys, passwords, file paths
- Reference files: Documents containing sample client data, screenshots with PII
- Code examples: Python/bash scripts with hardcoded credentials or personal paths
- Frontmatter: Description or metadata containing project names tied to personal identity
- Linked files: Templates, scripts, or assets that contain real data instead of placeholders
The Pre-Write Privacy Gate
Always run through this checklist before writing ANY skill content:
Step 1: Identify Data Categories
For every field, variable, or example value, ask:
- Could this identify a real person or entity?
| Data Category |
Examples in Skills |
Safe Alternative |
| Full names |
"John Smith's API key" |
"YOUR_API_KEY" or "example@example.com" |
| Email addresses |
"john@company.com" in templates |
"user@example.com" or "{{email}}" |
| Phone numbers |
"(555) 123-4567" |
"555-0100" or "+0-000-000-0000" |
| Physical addresses |
"123 Main St, Anytown" |
"123 Example St" or "[FULL_ADDRESS]" |
| Company names (personal context) |
"John's Startup Inc." |
"ACME Corp" or "Example Company" |
| API keys/tokens |
Hardcoded keys in scripts |
Environment variables or placeholders |
| File paths (personal) |
"C:\Users\john\MyProject" |
"$PROJECT_DIR" or relative paths |
| Database names |
"john_customer_db" |
"app_database" or "{{DB_NAME}}" |
Step 2: Safe Placeholder Standards
Always use placeholders that are unmistakably generic:
# BAD (contains PII-like patterns):
sample_api_key: "sk-live-abc123-john-smith-key"
client_email: "john.doe@company.com"
user_name: "John Smith"
# GOOD (generic placeholders):
api_key: "{{API_KEY}}"
email: "user@example.com"
name: "[FULL_NAME]"
Step 3: Secret Management in Scripts
Never hardcode secrets in skill scripts. Always use:
# BAD:
api_key = "sk-12345abcdef-John-Smith-key"
password = "mypassword123"
# GOOD:
import os
api_key = os.environ.get("API_KEY")
password = os.environ.get("PASSWORD")
# Or: raise ValueError("Set API_KEY environment variable")
Step 4: Generic Example Data Templates
For templates, scripts, and reference files:
- Names: Use "Alice", "Bob", "Charlie" (common test names) or "User One"
- Emails: Use example.com, test.com, or company.example.com
- Addresses: Use "123 Example Street" with "Springfield" as city placeholder
- Phone: "+1-555-010-0000" pattern
- Companies: "ACME Corp", "Example Inc", "Globex Corporation"
Privacy Review Process
Before Skill Publication
- Scan entire SKILL.md for PII patterns (use pii-detection-and-remediation skill)
- Scan all linked files (references/, scripts/, templates/, assets/)
- Check all example values, variable names, default configs
- Verify no real API keys, tokens, or credentials are included
- Ensure all placeholder patterns are generic and reusable
For Data-Processing Skills
When a skill will handle actual user data:
- Document what data the skill collects (explicit
## Privacy Impact section)
- Document what data the skill stores (none / temporary / persistent)
- Document what data the skill transmits (external APIs, logging, etc.)
- Include a
## Data Handling Notice in the skill body
Common Pitfalls
- Example credentials that look real — "user@company.com" might be a real person's email
- Hardcoded file paths — "C:\Users\John\Documents\ClientProject" reveals identity
- Test data from real life — Using your own or clients' real data as examples
- "Realistic" placeholder patterns — Fake names that happen to match real people
- Reference files with real data — Screenshots, CSVs with real names/emails
- Embedding secrets in script examples — "for demo purposes" keys that still work
Verification Checklist
1---2name: data-leakage-prevention-in-skills3description: Use when creating skills. Prevent data leakage.4license: MIT5---67# Data Leakage Prevention in Skills89## Overview10Safeguard against accidental personal data leakage when authoring Hermes skills. Ensures no PII (personally identifiable information), secrets, credentials, or sensitive data is embedded in SKILL.md content, template files, references, or script examples.1112## When to Use13- Before creating any new skill14- When reviewing/editing existing skills for privacy compliance15- When a skill will process user data16- When writing example templates that might contain sample data1718## The Risk: How Skills Leak Data1920Skills can leak data through multiple vectors:211. **Example content**: Templates with hardcoded names, emails, addresses, phone numbers222. **Configuration files**: Scripts with embedded API keys, passwords, file paths233. **Reference files**: Documents containing sample client data, screenshots with PII244. **Code examples**: Python/bash scripts with hardcoded credentials or personal paths255. **Frontmatter**: Description or metadata containing project names tied to personal identity266. **Linked files**: Templates, scripts, or assets that contain real data instead of placeholders2728## The Pre-Write Privacy Gate2930**Always run through this checklist before writing ANY skill content:**3132### Step 1: Identify Data Categories33For every field, variable, or example value, ask:34- Could this identify a real person or entity?3536| Data Category | Examples in Skills | Safe Alternative |37|--------------|--------------------|------------------|38| Full names | "John Smith's API key" | "YOUR_API_KEY" or "example@example.com" |39| Email addresses | "john@company.com" in templates | "user@example.com" or "{{email}}" |40| Phone numbers | "(555) 123-4567" | "555-0100" or "+0-000-000-0000" |41| Physical addresses | "123 Main St, Anytown" | "123 Example St" or "[FULL_ADDRESS]" |42| Company names (personal context) | "John's Startup Inc." | "ACME Corp" or "Example Company" |43| API keys/tokens | Hardcoded keys in scripts | Environment variables or placeholders |44| File paths (personal) | "C:\Users\john\MyProject" | "$PROJECT_DIR" or relative paths |45| Database names | "john_customer_db" | "app_database" or "{{DB_NAME}}" |4647### Step 2: Safe Placeholder Standards48Always use placeholders that are unmistakably generic:4950```yaml51# BAD (contains PII-like patterns):52sample_api_key: "sk-live-abc123-john-smith-key"53client_email: "john.doe@company.com"54user_name: "John Smith"5556# GOOD (generic placeholders):57api_key: "{{API_KEY}}"58email: "user@example.com"59name: "[FULL_NAME]"60```6162### Step 3: Secret Management in Scripts63Never hardcode secrets in skill scripts. Always use:64```python65# BAD:66api_key = "sk-12345abcdef-John-Smith-key"67password = "mypassword123"6869# GOOD:70import os71api_key = os.environ.get("API_KEY")72password = os.environ.get("PASSWORD")73# Or: raise ValueError("Set API_KEY environment variable")74```7576### Step 4: Generic Example Data Templates77For templates, scripts, and reference files:78- Names: Use "Alice", "Bob", "Charlie" (common test names) or "User One"79- Emails: Use example.com, test.com, or company.example.com80- Addresses: Use "123 Example Street" with "Springfield" as city placeholder81- Phone: "+1-555-010-0000" pattern82- Companies: "ACME Corp", "Example Inc", "Globex Corporation"8384## Privacy Review Process8586### Before Skill Publication871. Scan entire SKILL.md for PII patterns (use pii-detection-and-remediation skill)882. Scan all linked files (references/, scripts/, templates/, assets/)893. Check all example values, variable names, default configs904. Verify no real API keys, tokens, or credentials are included915. Ensure all placeholder patterns are generic and reusable9293### For Data-Processing Skills94When a skill will handle actual user data:951. Document what data the skill collects (explicit `## Privacy Impact` section)962. Document what data the skill stores (none / temporary / persistent)973. Document what data the skill transmits (external APIs, logging, etc.)984. Include a `## Data Handling Notice` in the skill body99100## Common Pitfalls1011. **Example credentials that look real** — "user@company.com" might be a real person's email1022. **Hardcoded file paths** — "C:\\Users\\John\\Documents\\ClientProject" reveals identity1033. **Test data from real life** — Using your own or clients' real data as examples1044. **"Realistic" placeholder patterns** — Fake names that happen to match real people1055. **Reference files with real data** — Screenshots, CSVs with real names/emails1066. **Embedding secrets in script examples** — "for demo purposes" keys that still work107108## Verification Checklist109- [ ] No full names, emails, phones, addresses in any skill content110- [ ] All API keys/passwords replaced with `{{ENV_VAR}}` or `YOUR_KEY_HERE`111- [ ] File paths use env vars (`$PROJECT_DIR`) or relative paths112- [ ] All example data uses generic placeholders (example.com, Alice/Bob, etc.)113- [ ] Reference files scanned for hidden PII114- [ ] Scripts use `os.environ.get()` for secrets, never hardcoded115- [ ] Data-handling skills include Privacy Impact and Data Handling Notice sections