Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add rico2035/security-skills --skill phi-pii-detectiongit clone --depth 1 https://github.com/rico2035/security-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/rico2035/security-skills/phi-pii-detection)<a href="https://agentmods.dev/skills/rico2035/security-skills/phi-pii-detection"><img src="https://agentmods.dev/badge/skills/rico2035/security-skills/phi-pii-detection/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/rico2035/security-skills/phi-pii-detection"><img src="https://agentmods.dev/badge/skills/rico2035/security-skills/phi-pii-detection.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00072 | $0.01051 |
| Opus 5 | $0.00036 | $0.00526 |
| Sonnet 5 | $0.00014 | $0.00210 |
| Haiku 4.5 | $0.00007 | $0.00105 |
Grade A, and why
phi-pii-detection scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 131 lines — stays where its author put it; the contents beside it link to each section on GitHub.
PHI/PII Leak Detection
Scan your codebase for Protected Health Information (PHI) and Personally Identifiable Information (PII) exposure, the #1 HIPAA violation vector.
When to Use
- Before any deployment to production
- After adding new logging, error handling, or API endpoints
- During HIPAA compliance reviews
- When onboarding new developers to verify secure coding practices
Sensitive Data Categories
Critical (block deploy if found)
- Social Security Numbers (SSN)
- Passwords, API keys, tokens
- Credit card / bank account numbers
- Full medical record numbers
High (fix within 7 days)
- Date of birth combined with patient name
- Diagnosis codes combined with patient identifiers
- Insurance member IDs with patient info
- Full addresses with health context
Medium (fix within 30 days)
- Email addresses in logs
- Phone numbers in error messages
- Partial identifiers without context
Search Patterns
Logging Statements
# JavaScript/TypeScript
console\.(log|warn|error|info|debug)\(.*\b(patient|ssn|dob|diagnosis|creditCard|bankAccount|socialSecurity|dateOfBirth|insuranceId|memberId)\b
logger\.(info|warn|error|debug)\(.*\b(patient|ssn|dob|diagnosis|creditCard|bankAccount)\b
# Python
logging\.(info|warning|error|debug|critical)\(.*\b(patient|ssn|dob|diagnosis|credit_card|bank_account)\b
print\(.*\b(patient|ssn|dob|diagnosis)\b
# Go
log\.(Print|Printf|Println|Fatal|Panic)\(.*\b(patient|ssn|dob|diagnosis)\b
# Java
(logger|LOG)\.(info|warn|error|debug)\(.*\b(patient|ssn|dob|diagnosis)\b
System\.out\.print.*\b(patient|ssn|dob|diagnosis)\b
Error Responses
# Sensitive data in thrown errors
throw new.*Error\(.*\b(patient|ssn|dob|diagnosis|insurance)\b
raise.*Exception\(.*\b(patient|ssn|dob|diagnosis)\b
# Sensitive data in API responses
res\.(json|send|status)\(.*\b(patientName|SSN|dateOfBirth)\b
return.*(Response|JsonResponse)\(.*\b(patient|ssn|dob)\b
Hardcoded Test Data (non-test files)
# SSN patterns outside test files
\b\d{3}-\d{2}-\d{4}\b
# Real-looking medical record numbers
\bMRN[:\s]*\d{6,10}\b
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 131 lines · 72 tokens per session scan A 9f25964eb7a8
phi-pii-detection is a skill published in the GitHub repository rico2035/security-skills (5 stars, last pushed 8d ago), licensed MIT. It adds 72 tokens to every session and 1,051 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…