lineage-pii-and-governance

lineage-pii-and-governance is a skill for Claude Code, Codex from vaquarkhan/data-engineering-agent-skills. It costs 41 tokens per session (485 once invoked), scanned A, original, MIT.

A guide to managing ownership, data lineage, access, and sensitive-data controls for published datasets, models, streams, and business metrics. Data lineage records where data comes from and how it changes.

In plain words
What is it for?
Use it when publishing or changing data products, handling regulated information, updating access rules, or documenting upstream and downstream relationships.
Why use it?
It helps prevent unclear responsibility, undocumented dependencies, and unsafe access when shared data changes.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it when publishing or changing data products, handling regulated information, updating access rules, or documenting upstream and downstream relationships.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/vaquarkhan/data-engineering-agent-skills/lineage-pii-and-governance
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add vaquarkhan/data-engineering-agent-skills --skill lineage-pii-and-governance
Clone the repo
git clone --depth 1 https://github.com/vaquarkhan/data-engineering-agent-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for lineage-pii-and-governance

README.md
[![agentmods](https://agentmods.dev/badge/skills/vaquarkhan/data-engineering-agent-skills/lineage-pii-and-governance/github.svg)](https://agentmods.dev/skills/vaquarkhan/data-engineering-agent-skills/lineage-pii-and-governance)
Your own site
<a href="https://agentmods.dev/skills/vaquarkhan/data-engineering-agent-skills/lineage-pii-and-governance"><img src="https://agentmods.dev/badge/skills/vaquarkhan/data-engineering-agent-skills/lineage-pii-and-governance/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for lineage-pii-and-governance

Your own site · 80×15
<a href="https://agentmods.dev/skills/vaquarkhan/data-engineering-agent-skills/lineage-pii-and-governance"><img src="https://agentmods.dev/badge/skills/vaquarkhan/data-engineering-agent-skills/lineage-pii-and-governance.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 41 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 485 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00041 $0.00485
Opus 5 $0.00020 $0.00243
Sonnet 5 $0.00008 $0.00097
Haiku 4.5 $0.00004 $0.00049

Measured 9d ago against content hash f20850d53d84, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

lineage-pii-and-governance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

The scan reads SKILL.md. This mod also ships 3 executable files (anti-patterns/pii_in_plain_text.py, checks/pii_scan.py, checks/retention_coverage.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/lineage-pii-and-governance/SKILL.md · 72 lines

How it starts

The opening of the file, as written. The whole thing — 72 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Lineage, PII, And Governance

Overview

Governance is an engineering concern, not a cleanup exercise. This skill ensures that every meaningful data change accounts for ownership, lineage, access, and sensitive-data handling before release.

When to Use

  • publishing a new table, model, or stream
  • changing business-critical metrics
  • handling personal, financial, health, or otherwise sensitive data
  • modifying access controls or data-sharing patterns
  • changing upstream or downstream lineage

Workflow

  1. Identify ownership and consumers. Every published dataset should have:

    • an owner
    • intended consumers
    • known downstream dependencies
  2. Classify the data. Determine whether fields are:

    • public
    • internal
    • confidential
    • regulated or sensitive
  3. Define required controls. Controls may include:

    • masking
    • tokenization
    • row-level restrictions
    • column-level restrictions
    • encryption requirements
    • retention or deletion rules
  4. Update lineage and documentation. Record how the data flows from source to publish layer, including major transformations.

  5. Verify policy enforcement in implementation. Do not stop at documentation. Check that access and masking rules are actually reflected in code or platform configuration.

Common Rationalizations

Rationalization Reality
"It is only internal data." Internal datasets still create exposure, misuse, and compliance risk.
"We will document lineage later." Lineage that is not updated during change work becomes stale immediately.
"Security will handle masking downstream." Sensitive data should be controlled as close to production as possible.

Red Flags

  • published data has no named owner
  • sensitive fields are copied without classification
  • lineage updates are missing for a shared metric
  • access rules are assumed but not enforced

Verification

  • Dataset ownership and consumers are identified
  • Sensitive fields are classified
  • Required controls are implemented or explicitly planned
  • Lineage and documentation reflect the change
  • Governance checks are based on real enforcement, not comments alone

Read the full file on GitHub · 72 lines

Files

What ships with it

3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 72 lines · 41 tokens per session scan A f20850d53d84

Subscribe to this mod's changes

lineage-pii-and-governance is a skill published in the GitHub repository vaquarkhan/data-engineering-agent-skills (45 stars, last pushed 3mo ago), licensed MIT. It adds 41 tokens to every session and 485 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

kafka-shadowtraffic

Generate a ShadowTraffic configuration to populate a Kafka topic with realistic synthetic data. Discovers the target topic, its key and value schemas, and the correct serializers from the live cluster via any attached Kafka MCP server, then writes a ready-to-run shadowtraffic-config.json and Docker command. Use when…

lensesio/agentic-engineering-for-apache-kafka · 134 tokens

spark-training-gotchas

Preflight and diagnose the ten known failure modes for ML training on NVIDIA DGX Spark. Use when a training run on DGX Spark fails to start, OOMs below the 128GB limit, slows down mid-run, or before any multi-hour training job on GB10.

wshobson/agents · 63 tokens

9router

Entry point for 9Router — local/remote AI gateway with OpenAI-compatible REST for chat, image, TTS, embeddings, web search, web fetch. Use when the user mentions 9Router, NINEROUTERURL, or wants AI without writing provider boilerplate. This skill covers setup + indexes capability skills; fetch the relevant capability…

decolua/9router · 84 tokens

aeon

This skill should be used for time series machine learning tasks including classification, regression, clustering, forecasting, anomaly detection, segmentation, and similarity search. Use when working with temporal data, sequential patterns, or time-indexed observations requiring specialized algorithms beyond standard…

synthetic-sciences/openscience · 74 tokens

lookml_ingest

Map a LookML view/model/explore into ktx semantic layer sources. Covers the LookML to ktx primitive table, provenance tagging, and three worked examples (overlay, standalone from derivedtable, standalone with sqlalwayswhere). Load when the turn contains .lkml content.

Kaelio/ktx · 63 tokens

markitdown

Convert files and office documents to Markdown. Supports PDF, DOCX, PPTX, XLSX, images (with OCR), audio (with transcription), HTML, CSV, JSON, XML, ZIP, YouTube URLs, EPubs and more.

synthetic-sciences/openscience · 53 tokens