Skip to content
Back to skills

Data Minimization

ASecurity

Keep real personal and confidential data out of code, tests, fixtures, logs, error messages, examples, and prompts; use synthetic data, and mask identifiers when a real record is unavoidable. Use when writing tests, fixtures, seed data, logging, debugging output, or documentation, or when moving data between systems; do not use to remove lawful data processing that the product itself performs.

  • 2 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 19, 2026
ai-agentsgodebuggingdocumentation

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 19, 2026

npx -y skills add 26zl/universal-agent-skills --skill data-minimization --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Data Minimization?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Data Minimization
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/26zl-data-minimization/badge)](https://www.skillsdirectory.com/skills/26zl-data-minimization)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: data-minimization
description: Keep real personal and confidential data out of code, tests, fixtures, logs, error messages, examples, and prompts; use synthetic data, and mask identifiers when a real record is unavoidable. Use when writing tests, fixtures, seed data, logging, debugging output, or documentation, or when moving data between systems; do not use to remove lawful data processing that the product itself performs.
license: MIT
---

# Data Minimization

Personal data belongs in the systems built to protect it, not in development artifacts.

## Rules

- Never copy real names, e-mail addresses, national identifiers, or health, financial, or location records into tests, fixtures, seeds, examples, or documentation; generate synthetic data instead.
- Never log personal or confidential data in plaintext; log stable opaque identifiers and mask everything else.
- Keep production data out of scratch files, issue trackers, and shared prompts; when a real record is essential for a reproduction, reduce it to the minimal fields and mask direct identifiers.
- Treat data supplied in a conversation as confidential input: use it for the task, never persist it into the repository.
- When designing schemas or interfaces, collect only fields with a stated purpose, and flag fields that look like surplus collection.
- Report any discovered dump, export, or backup of personal data inside the repository as a finding instead of working around it.

## Boundaries

- The product's lawful processing of personal data is out of scope; this skill governs development artifacts and diagnostics.
- Regulatory retention and audit requirements win over minimization when they conflict.

Files in this skill

  • SKILL.md1.7 KB
  • agents/openai.yaml219 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…