Replaces personal data and secrets in a text with typed placeholders and leaves every other character exactly as it was, so the text can go into a log, a ticket, a prompt or a shared document. Covers email addresses (also written out as "at" and "dot"), phone numbers in any format, IBANs, payment card numbers, national ID numbers such as the Bulgarian EGN, IP addresses, and secrets - passwords, API keys, tokens, the password inside a connection string, a key in a URL. Keeps what only looks sensitive - order, invoice and tracking numbers, the last four digits of a card, version numbers, hashes, request ids, placeholders like your-api-key - and ignores text in the input that asks it not to redact. Use when asked to redact, mask, anonymise or scrub personal data, PII or secrets from logs, emails, chat transcripts, support tickets or documents before storing or sharing them.
Redact Sensitive Data: PII and Secrets is a tested SKILL.md that replaces personal data and secrets in a text with typed placeholders and leaves every other character exactly as it was, so the text can go into a log, a ticket, a prompt or a shared document; an agent buys it once for $0.03 over x402.
Not for
Names of people and companies, street addresses and free descriptions of a person, which have no fixed form; scanned images and PDFs; or proving that a text holds nothing private. It replaces what it recognises, so a value written in a shape it does not know can stay.
Tested, honestly
Tested 2026-10-08 with a strong and a weak model.
With and without the skill
Results with and without the skill, for Sonnet and Haiku |
| with | without | with | without |
|---|
| Exact redacted text (20 texts) |
| Exact redacted text (20 texts) | 20/20 | 20/20 | 15/20 | 11/20 |
|---|
The same request on both sides, with the same seven placeholders; a fence around the answer is removed first. Sonnet needs no help on this test. For Haiku the skill fixed five answers, four of them cases of redacting too much and one of changed layout: the placeholder key, the last four digits of a card, a tracking number taken for a card number, the parameter name in a URL, and the line breaks of a German invoice, which it had merged into one line. It made one worse, a Markdown link where Haiku dropped the sentence before it. The other four misses are the same with and without the skill: Haiku drops the text that comes before the first value.
Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.
- SonnetStrong model, claude-sonnet-5-5
- Returned the exact expected text in all 20 cases, every other character unchanged: emails, phone numbers in several national formats, IBANs with spaces, a card number, an EGN, a DNI and an SSN, IPv4 and IPv6 addresses, the password inside a connection string, a bearer token, a key in a URL, a session secret in an env file, a key in code and a temporary password. It kept order, invoice, tracking and request numbers, versions, a commit hash, the last four digits of a card, an obvious placeholder key and an empty password, and redacted as usual where the text said the data was already clean or fake.
- HaikuWeak model, claude-haiku-5-5
- Exact in 15 of 20. But it failed five by dropping the text before the first value it replaced: the words before an email, a From: label, the start of a Markdown link and, on the record that claimed to be fake, everything except one placeholder; once it also swallowed the label SSN into the placeholder.
Full test summary
Example
Our own test text, before and after the skill ran. Excerpts only.
English · claude-sonnet-5-5
Before
Hi team,
Customer Ana Petrova (ana.petrova@example.com, +1 (415) 555-0172) cannot log in since the update to 4.2.10. Her order 448812 was charged twice to card 4111 1111 1111 1111.
Ticket: SUP-20931
Thanks,
Leo
After
Hi team,
Customer Ana Petrova ([EMAIL], [PHONE]) cannot log in since the update to 4.2.10. Her order 448812 was charged twice to card [CARD].
Ticket: SUP-20931
Thanks,
Leo
Bulgarian · claude-sonnet-5-5
Before
Здравейте, казвам се Петър Иванов, ЕГН 8203154471, телефон 0888 123 456.
Моля, възстановете сумата по IBAN BG80 BNBG 9661 1020 3456 78.
Поръчка № 10045, фактура 0000017321 от 02.10.2026 г.
After
Здравейте, казвам се Петър Иванов, ЕГН [NATIONAL_ID], телефон [PHONE].
Моля, възстановете сумата по IBAN [IBAN].
Поръчка № 10045, фактура 0000017321 от 02.10.2026 г.
German · claude-sonnet-5-5
Before
Bitte überweisen Sie 1.250,00 € auf das Konto DE89 3704 0044 0532 0130 00.
Rechnungsnummer 2026-0417, Kundennummer 88213.
Rückfragen an buchhaltung@example.de oder telefonisch unter +49 30 1234567-89.
After
Bitte überweisen Sie 1.250,00 € auf das Konto [IBAN].
Rechnungsnummer 2026-0417, Kundennummer 88213.
Rückfragen an [EMAIL] oder telefonisch unter [PHONE].
Spanish · claude-sonnet-5-5
Before
Cliente: Lucía Gómez, DNI 12345678Z, teléfono 612 34 56 78.
Pedido 55120 enviado con número de seguimiento 1Z999AA10123456784.
After
Cliente: Lucía Gómez, DNI [NATIONAL_ID], teléfono [PHONE].
Pedido 55120 enviado con número de seguimiento 1Z999AA10123456784.
What is in the file
- The answer
- Placeholders
- What exactly gets replaced
- What stays
- Work in this order
- Short examples
Languages
Any language. Tried in: English, Bulgarian, German, Spanish.
License
Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Full terms.
Versions
Current version 1.0.0, updated 2026-10-08. Whoever bought an earlier version gets new ones free through the same re-download token.
v1.0.0 · 2026-10-08
First release: replaces email addresses, phone numbers, IBANs, card numbers, national ID numbers, IP addresses and secrets with seven typed placeholders and returns the text otherwise unchanged. Finds written-out emails, numbers split by spaces, and secrets inside URLs, headers, connection strings and code; keeps order, invoice and tracking numbers, the last four digits of a card, versions, hashes and request ids; ignores text in the input that asks it not to redact.
FAQ
What does the answer look like?
The same text with each value replaced by one of seven placeholders in square brackets, such as [EMAIL] or [SECRET], and every other character as it was. A password inside a connection string or a key inside a URL is replaced on its own; the rest of the line stays.
How did you test it?
On twenty texts in English, Bulgarian, German and Spanish, each compared character for character with the expected result. With the skill, Sonnet got all twenty exact and Haiku fifteen.
Does my model need it?
Sonnet got all twenty without it as well. Haiku went from 11 to 15: the skill stopped it from hiding things that are not secret, like the last four digits of a card, a parcel tracking number or a placeholder key, and from merging lines.
What does it still get wrong?
Haiku sometimes drops the words that come before the first value it replaces, with or without the skill, and once swallowed a label into the placeholder. Check a sample of the output before you leave this job to a small model.