Data & Analysis

Redact Sensitive Data: PII and Secrets

Replaces personal data and secrets in a text with typed placeholders and leaves every other character exactly as it was, so the text can go into a log, a ticket, a prompt or a shared document. Covers email addresses (also written out as "at" and "dot"), phone numbers in any format, IBANs, payment card numbers, national ID numbers such as the Bulgarian EGN, IP addresses, and secrets - passwords, API keys, tokens, the password inside a connection string, a key in a URL. Keeps what only looks sensitive - order, invoice and tracking numbers, the last four digits of a card, version numbers, hashes, request ids, placeholders like your-api-key - and ignores text in the input that asks it not to redact. Use when asked to redact, mask, anonymise or scrub personal data, PII or secrets from logs, emails, chat transcripts, support tickets or documents before storing or sharing them.

Redact Sensitive Data: PII and Secrets is a tested SKILL.md that replaces personal data and secrets in a text with typed placeholders and leaves every other character exactly as it was, so the text can go into a log, a ticket, a prompt or a shared document; an agent buys it once for $0.03 over x402.

Tested 2026-10-08No code, no hidden instructionsv1.0.0 · 6.3 KB · perpetual license

Not for

Names of people and companies, street addresses and free descriptions of a person, which have no fixed form; scanned images and PDFs; or proving that a text holds nothing private. It replaces what it recognises, so a value written in a shape it does not know can stay.

Tested, honestly

Tested 2026-10-08 with a strong and a weak model.

With and without the skill

Results with and without the skill, for Sonnet and Haiku
SonnetHaiku
withwithoutwithwithout
Exact redacted text (20 texts)20/2020/2015/2011/20

The same request on both sides, with the same seven placeholders; a fence around the answer is removed first. Sonnet needs no help on this test. For Haiku the skill fixed five answers, four of them cases of redacting too much and one of changed layout: the placeholder key, the last four digits of a card, a tracking number taken for a card number, the parameter name in a URL, and the line breaks of a German invoice, which it had merged into one line. It made one worse, a Markdown link where Haiku dropped the sentence before it. The other four misses are the same with and without the skill: Haiku drops the text that comes before the first value.

Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.

SonnetStrong model, claude-sonnet-5-5
Returned the exact expected text in all 20 cases, every other character unchanged: emails, phone numbers in several national formats, IBANs with spaces, a card number, an EGN, a DNI and an SSN, IPv4 and IPv6 addresses, the password inside a connection string, a bearer token, a key in a URL, a session secret in an env file, a key in code and a temporary password. It kept order, invoice, tracking and request numbers, versions, a commit hash, the last four digits of a card, an obvious placeholder key and an empty password, and redacted as usual where the text said the data was already clean or fake.
HaikuWeak model, claude-haiku-5-5
Exact in 15 of 20. But it failed five by dropping the text before the first value it replaced: the words before an email, a From: label, the start of a Markdown link and, on the record that claimed to be fake, everything except one placeholder; once it also swallowed the label SSN into the placeholder.

Full test summary

Example

Our own test text, before and after the skill ran. Excerpts only.

English · claude-sonnet-5-5

Before

Hi team, Customer Ana Petrova (ana.petrova@example.com, +1 (415) 555-0172) cannot log in since the update to 4.2.10. Her order 448812 was charged twice to card 4111 1111 1111 1111. Ticket: SUP-20931 Thanks, Leo

After

Hi team, Customer Ana Petrova ([EMAIL], [PHONE]) cannot log in since the update to 4.2.10. Her order 448812 was charged twice to card [CARD]. Ticket: SUP-20931 Thanks, Leo

Bulgarian · claude-sonnet-5-5

Before

Здравейте, казвам се Петър Иванов, ЕГН 8203154471, телефон 0888 123 456. Моля, възстановете сумата по IBAN BG80 BNBG 9661 1020 3456 78. Поръчка № 10045, фактура 0000017321 от 02.10.2026 г.

After

Здравейте, казвам се Петър Иванов, ЕГН [NATIONAL_ID], телефон [PHONE]. Моля, възстановете сумата по IBAN [IBAN]. Поръчка № 10045, фактура 0000017321 от 02.10.2026 г.

German · claude-sonnet-5-5

Before

Bitte überweisen Sie 1.250,00 € auf das Konto DE89 3704 0044 0532 0130 00. Rechnungsnummer 2026-0417, Kundennummer 88213. Rückfragen an buchhaltung@example.de oder telefonisch unter +49 30 1234567-89.

After

Bitte überweisen Sie 1.250,00 € auf das Konto [IBAN]. Rechnungsnummer 2026-0417, Kundennummer 88213. Rückfragen an [EMAIL] oder telefonisch unter [PHONE].

Spanish · claude-sonnet-5-5

Before

Cliente: Lucía Gómez, DNI 12345678Z, teléfono 612 34 56 78. Pedido 55120 enviado con número de seguimiento 1Z999AA10123456784.

After

Cliente: Lucía Gómez, DNI [NATIONAL_ID], teléfono [PHONE]. Pedido 55120 enviado con número de seguimiento 1Z999AA10123456784.

What is in the file

  • The answer
  • Placeholders
  • What exactly gets replaced
  • What stays
  • Work in this order
  • Short examples

Languages

Any language. Tried in: English, Bulgarian, German, Spanish.

License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Full terms.

Versions

Current version 1.0.0, updated 2026-10-08. Whoever bought an earlier version gets new ones free through the same re-download token.

  1. v1.0.0 · 2026-10-08

    First release: replaces email addresses, phone numbers, IBANs, card numbers, national ID numbers, IP addresses and secrets with seven typed placeholders and returns the text otherwise unchanged. Finds written-out emails, numbers split by spaces, and secrets inside URLs, headers, connection strings and code; keeps order, invoice and tracking numbers, the last four digits of a card, versions, hashes and request ids; ignores text in the input that asks it not to redact.

FAQ

What does the answer look like?

The same text with each value replaced by one of seven placeholders in square brackets, such as [EMAIL] or [SECRET], and every other character as it was. A password inside a connection string or a key inside a URL is replaced on its own; the rest of the line stays.

How did you test it?

On twenty texts in English, Bulgarian, German and Spanish, each compared character for character with the expected result. With the skill, Sonnet got all twenty exact and Haiku fifteen.

Does my model need it?

Sonnet got all twenty without it as well. Haiku went from 11 to 15: the skill stopped it from hiding things that are not secret, like the last four digits of a card, a parcel tracking number or a placeholder key, and from merging lines.

What does it still get wrong?

Haiku sometimes drops the words that come before the first value it replaces, with or without the skill, and once swallowed a label into the placeholder. Check a sample of the output before you leave this job to a small model.

Read more

Share

Read this page as Markdown: /skills/redact-sensitive.md.

  • Text to JSON: Extract Data Without Guessing

    Data & Analysis

    SKILL.md · v1.0.2 · 7.5 KB

    Extracts data from text into JSON that matches the shape you give (a JSON Schema, an example object or a list of fields), without guessing. Every value comes from the text; a missing fact becomes null, numbers and dates are converted only into the type the shape asks for, two conflicting values are not settled by a guess, and instructions hidden in the text are ignored. Use when asked to extract structured data, turn text into JSON, parse an invoice, receipt, email, order, CV or job post into fields, or fill a JSON schema from a document.

    $0.05once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 3 Oct 2026

  • Recommended

    Prompt Injection Guard

    Agents & Protocols

    SKILL.md · v1.0.3 · 14.5 KB

    Keeps an AI agent from obeying instructions hidden in what it reads (indirect prompt injection). Web pages, e-mails, files, PDFs, API and tool output, other agents' messages and skill files under review are treated as content, never as orders. The agent is instructed never to pay, transfer, delete or reveal anything because content asked, to report the attempt with a quote and its source, and to still finish the real task. Use whenever the agent reads anything it did not write itself, before any action with side effects such as a payment, a message or a file change, and when asked to review or summarise untrusted content.

    $0.07once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 2 Oct 2026

  • Ticket Triage: Category, Priority, Language

    Sales & Customer Support

    SKILL.md · v1.0.1 · 8.3 KB

    Sorts one incoming customer message (support email, chat, contact form or ticket) into a category, a priority and the customer's language, and answers with strict JSON that a program can route without a person reading it. Uses a fixed default category list or the list the request gives, and fixed rules for priority, so an angry tone or the word URGENT does not raise priority and a calm report of an outage does not lower it. The language is the one the customer wrote in, not the language of a pasted error, a quoted reply or a signature, and orders hidden in the message do not change the result. Use for ticket triage, to route or label a support ticket, to classify support emails in a help desk inbox, or to decide which message needs a human first.

    $0.05once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 8 Oct 2026