Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Document Desensitization

ASecurity

法保文件脱敏技能 - 对用户上传的文档,完成文件脱敏,生成脱敏版文档。在用户需要对文件进行脱敏、去除隐私信息、加密用户信息时使用。

45 stars
0 votes
0 copies
0 views
Added 9/25/2026
developmentpythonshellapi

Works with

apimcp

Security Analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned 9/25/2026

$npx -y skills add ahang1598/doubao-workbuddy-qwenwork-skills --skill document-desensitization --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Document Desensitization?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Document Desensitization
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ahang1598-document-desensitization/badge)](https://www.skillsdirectory.com/skills/ahang1598-document-desensitization)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: document-desensitization
description: 法保文件脱敏技能 - 对用户上传的文档,完成文件脱敏,生成脱敏版文档。在用户需要对文件进行脱敏、去除隐私信息、加密用户信息时使用。
version: "1.0.0"
author: "法保网"
---

# 法保文件脱敏 Skill

## 可用工具

### file_desensitization - 文件脱敏

对给定 doc/docx 的文件URL实现一键脱敏,对敏感信息标星处理,返回脱敏后的文件下载链接。覆盖数值、日期、个人信息、企业信息、规格、源代码、系统名称、品牌名称等100余项敏感信息。

**参数说明:**

| 参数名 | 类型 | 必填 | 描述 |
| --- | --- | :---: | --- |
| file_url | string | 是 | 公网可访问的待脱敏文件URL,支持 .docx / .doc  格式。若未提供需反问获取 |
| file_name | string | 否 | 脱敏文件的真实名称(含扩展名,如"工会经费电话设计费.docx")。若从对话或上传流程中获知文件名请务必传入;未知时可省略 |

**返回字段:**

| 字段名 | 类型 | 描述 |
| --- | --- | --- |
| status_code | number | 状态码,200 成功,422 参数缺失,500 服务异常 |
| msg | string | 状态说明 |
| data | string | 脱敏后文档下载链接(成功,markdown格式)、空字符串(失败) |

### create_upload_ticket - 获取一次性上传凭证

当用户需要上传本地文件获取公网URL时调用(服务端代为鉴权,无需用户提供 API Key)。返回 upload_url(一次性上传URL,5分钟内有效)和 usage(本地执行命令)。

**返回字段:**

| 字段名 | 类型 | 描述 |
| --- | --- | --- |
| upload_url | string | 一次性上传URL(需附 filename 查询参数) |
| usage | string | 在用户本地执行的完整 curl 命令 |
| expires_in | number | 凭证有效期(秒) |

## 文件脱敏步骤

### 第一步:获取待脱敏的文件URL

需要待脱敏文件的**公网可访问URL**(支持 .docx / .doc  格式):
- 用户直接提供文件链接时,使用该链接
- **用户发送文件附件或提供本地文件路径时**(若附件本身提供可访问URL,直接使用该URL),按以下流程获取公网URL。禁止把本地路径直接作为 MCP 工具参数(工具在云端服务器执行,无法读取用户本地文件):

**本地文件上传指引(服务端代为鉴权,无需用户提供 API Key):**

1. **获取一次性上传凭证(首选)**:调用 `create_upload_ticket` 工具,返回 upload_url 与 usage 命令
2. **在用户本地执行上传**(优先脚本,本地无 Python 时执行 usage 中的 curl 命令)
   - 脚本:`python scripts/upload_ticket.py --url <upload_url> --file <本地文件路径>`(upload_url 原样传入即可,文件名自动URL编码)
   - 成功时输出一行公网URL,直接作为 file_url 使用
   - 失败时输出以「错误:」开头的提示,按提示处理后可重新调用 `create_upload_ticket` 获取新凭证;上传累计执行不超过 2 次,不得换参数反复重试
3. **无法在用户本地执行命令时**(无 shell 权限):将 usage 命令提供给用户自行执行,取其输出URL;或引导用户直接以文件链接形式提供

**注意**:文件URL必须是当前会话中用户提供的(附件或链接),请勿自行访问本地文件系统获取。若用户未提供待脱敏文件,请反问获取。

### 第二步:完成文件脱敏

告知用户文件正在脱敏处理中,请稍后... 然后调用 `file_desensitization` 工具,传入 file_url(以及 file_name,已知文件名时务必传入),返回脱敏后的文件下载链接。

## 返回格式

- **脱敏成功**:告知用户《脱敏版文件》生成成功,提供下载链接
- **脱敏失败**:提示用户文件脱敏失败,请稍后重试

## 终止性错误(收到即停,禁止绕过)

以下三类工具报错是面向用户的处理指令,不是可重试故障。工具返回后必须立即停止调用,不得自行处理:

- 「未检测到 API Key,请前往法保网 API 开放平台获取」
- 「API Key 无效或已过期,请前往法保网 API 开放平台确认账户状态」
- 「积分余额不足,请前往法保网 API 开放平台进行充值」

收到上述报错后禁止以下行为:

- 重试当前工具或修改参数后重试
- 调用其他工具复核该错误
- 绕过 MCP 工具调用,直接向服务端点发送底层 HTTP 请求

正确行为:将报错原文转告用户,等待用户在法保网 API 开放平台处理完毕后重新发起请求。

## 注意事项

- **信息收集优先**:必填参数缺失时必须反问获取,请勿直接调用工具。全部参数收集完成后再触发工具调用
- **禁止本地路径**:所有文件类参数必须是公网可访问的URL,严禁传入 `C:\`、`/home/` 等本地路径——服务端部署在云端,无法访问用户本地文件,传入本地路径必定失败
- **文件格式**:file_url 必须是公网可访问的URL,且文档必须是 .docx / .doc  格式。不支持 .pdf/.txt / .jpg 等其他格式
- **脱敏耗时**:文件脱敏需要几分钟,调用前需告知用户耐心等待
- **结果处理**:若返回 data 为下载链接(markdown格式 `[!请点击下载](url)`),提取URL告知用户点击下载;若 data 为空,提示用户稍后重试
- **鉴权说明**:本工具采用自填 API Key 模式,首次使用需在连接配置中填写法保网 API Key(在法保网 API 开放平台 https://lawyer.fabao.law/pc/#/mcp 获取)。若返回 msg 包含"积分余额不足",直接将 msg 内容展示给用户即可(msg 已附带法保网充值地址)。若提示 API Key 无效、已过期或未检测到,属于终止性错误——立即停止调用并将报错原文转告用户,禁止重试或绕过,规则见上方「终止性错误」段。

Attribution

ahang1598ahang1598
View sourceSee grades on GitHubMore from ahang1598 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Clean Code

Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments

304955 votes

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

286712 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Writing Plans

Use when you have a spec or requirements for a multi-step task, before touching code

2927051 votes
View all in development →