Groq data handling
425 plugins, 2,810 skills, 200 agents for Claude Code. Open-source marketplace at tonsofskills.com with the ccpi CLI package manager.
npx -y skills add jeremylongshore/claude-code-plugins-plus-skills --skill groq-data-handlingAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
What its author says it does
Copied from the file, not written here
Use when you need to keep PII out of Groq API calls, filter model responses, audit-log conversations, or track token cost and usage for a Groq integration. Implements prompt sanitization, PII redaction, response filtering, and usage tracking. Trigger with phrases like "groq data", "groq PII", "groq GDPR", "groq data retention", "groq privacy", "groq compliance".
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
5.0 KB, as published. Nobody here has run it
Groq Data Handling
Overview
Manage data flowing through Groq's inference API. This skill wires a privacy pipeline around the Groq SDK: sanitize prompts before they are sent, filter responses after they return, redact PII, hash-log an audit trail, and track token usage and cost. Key fact: Groq does not use API data for model training (Groq Privacy Policy).
Prerequisites
- Node.js project with the
groq-sdkpackage installed (npm i groq-sdk). - A Groq API key exported as
GROQ_API_KEY. The SDK reads it automatically from the environment —new Groq()needs no explicit argument. Never hardcode the key; keep it in an untracked.envor your secret manager. - Node's built-in
cryptomodule (for the audit hash) — no install needed.
Instructions
The pipeline layers in four stages; drop simple add-ons (moderation, cost reporting) on top. Each snippet below is the skeleton — the full, copy-ready code for every stage is in references/implementation.md.
-
Sanitize input — run a PII rule table over every message before it leaves your process, flagging which categories were caught:
function sanitizeMessages(messages: any[]): { messages: any[]; hadPII: boolean } { // apply PII_RULES to each message's content; return redacted copy + flag } -
Wrap the completion call — call
safeCompletion(...)instead of the rawgroq.chat.completions.create, so input and response both pass the sanitizer. -
Track usage —
trackUsage(model, completion.usage, sessionId)records token counts and estimated cost per call using a per-model price table. -
Audit —
auditedCompletion(...)ties it together and logs a SHA-256 hash of the prompt (never the prompt text) so the audit trail carries no sensitive content.
For content moderation via Llama Guard and a daily cost report, see references/examples.md.
Groq data policy
- Groq does not train on API request/response data.
- Prompts and completions are processed and discarded.
- Groq may temporarily log requests for abuse prevention.
- For enterprise: contact Groq for DPA and SOC 2 compliance details.
Output
- Sanitized messages/responses — text with
[EMAIL],[PHONE],[SSN],[CARD],[IP]placeholders swapped in for detected PII, plus ahadPIIboolean and a list of redacted categories. - Usage records — one JSON line per call (
type: "groq_usage") with model, token counts, andestimatedCostUsd. - Audit entries — one JSON line per call (
type: "groq_audit") carrying a prompt hash,piiDetected,responseFiltered, and the usage record. - Cost report — an aggregated object with
totalCost,totalTokens,totalCalls, and a per-model breakdown (see the sample in references/examples.md).
Error Handling
| Issue | Cause | Solution |
|---|---|---|
| PII leaks in response | Model echoes sensitive input | Apply response filtering on all completions |
| Cost spike | 70B model for all requests | Route simple tasks to 8B |
| Missing usage data | Streaming mode | Use non-streaming for tracked requests, or estimate |
| Audit gaps | Not all code paths use wrapper | Lint rule: ban direct groq.chat.completions.create |
GROQ_API_KEY not set | Key missing from environment | Export the key before running; the SDK throws on an unauthenticated call |
Examples
- Full four-stage pipeline (sanitizer, safe wrapper, usage tracker, audited completion) — references/implementation.md.
- Content safety check with Llama Guard and a daily cost report — references/examples.md.
Minimal end-to-end use once the helpers are in place:
const { content, audit } = await auditedCompletion(sessionId, messages);
// content is PII-filtered; audit is a hash-only record safe to persist
Resources
For enterprise access controls, see the groq-enterprise-rbac skill.