Data privacy engineering
Skill sairam0424/MindForge/.mindforge/skills/data-privacy-engineering
MindForge: The Enterprise Agentic Framework for Claude Code & Antigravity. High-performance autonomous execution, wave-parallelism, and multi-tier governance for production-grade AI engineering.From the repository description
npx -y skills add sairam0424/MindForge --skill data-privacy-engineeringAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
3.8 KB, 620 tokens by cl100k_base, as published. Nobody here has run it
Skill — Data Privacy Engineering
When this skill activates
This skill activates when implementing privacy-preserving data systems, building consent management infrastructure, or applying anonymization techniques. Use when handling sensitive data requires technical controls beyond access restrictions.
Mandatory actions when this skill is active
Before writing any code
- Conduct privacy impact assessment: identify PII/sensitive data, data flows, retention requirements, third-party sharing, and regulatory obligations (GDPR, CCPA, HIPAA)
- Define privacy requirements: anonymization level (k-anonymity, l-diversity, differential privacy), consent granularity, right-to-erasure scope, and data minimization principles
- Select appropriate privacy techniques: tokenization (reversible), hashing (one-way), encryption (protected), differential privacy (statistical), synthetic data (replacement)
- Establish privacy testing framework: re-identification risk assessment, privacy budget tracking, consent enforcement verification, and breach simulation
During implementation
- Implement automated PII detection pipeline: regex patterns, ML models, NER for unstructured text scanning code, logs, databases, and data lakes
- Build tokenization service with: format-preserving encryption for display, secure token vault, key rotation, and performance caching for high-throughput
- Create differential privacy mechanisms: Laplace/Gaussian noise addition calibrated to epsilon budget, query result perturbation, and privacy budget accounting across queries
- Design consent management system: granular opt-in/opt-out, purpose-specific consent, consent version tracking, and propagation to downstream systems
- Implement data minimization controls: retention policies with automated deletion, purpose limitation enforcement, and necessity justification for data collection
- Build privacy-preserving analytics: federated learning for ML without centralized data, secure aggregation for metrics, and homomorphic encryption for computation on encrypted data
- Create data subject rights workflows: search across systems, export in portable format, deletion with verification, and rectification propagation
After implementation
- Generate privacy compliance reports: PII inventory, consent coverage, retention policy enforcement, third-party data sharing audit, and rights request fulfillment SLA
- Build privacy monitoring dashboards: PII exposure incidents, consent withdrawal rates, privacy budget consumption, and anonymization quality metrics
- Create breach response procedures: detection, containment, notification timelines, affected user identification, and remediation workflows
- Document privacy controls: anonymization methods, re-identification risk levels, consent mechanisms, and data retention justifications for audit purposes
Self-check before task completion
- PII detection covers all data stores with automated scanning and alerting on new sensitive data discoveries
- Anonymization techniques applied with documented re-identification risk assessment (k-anonymity ≥10 or equivalent)
- Consent management enforces purpose limitation with propagation to all downstream processing systems
- Differential privacy implementation maintains epsilon budget <1.0 for sensitive aggregations with privacy accounting
- Data subject rights workflows tested for completeness across all systems within regulatory SLA (30 days GDPR)
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.