orca-data-exposure

Discover and prioritize sensitive data exposure across environments.

47|7|Updated May 3, 2026
One-click install
npx skills add https://github.com/orcasecurity/orca-skills --skill orca-data-exposure
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: orca-data-exposure
Source: https://github.com/orcasecurity/orca-skills/tree/main/skills/orca-data-exposure
Command: npx skills add https://github.com/orcasecurity/orca-skills --skill orca-data-exposure

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This DSPM-oriented skill identifies where sensitive data resides and is at risk across environments, including exposed secrets, PII, credentials, and data-store security posture, enabling prioritized remediation.

Core Features & Use Cases

  • Discover sensitive data across clouds and on-premises, surface unprotected stores, and rank risks by exposure level.
  • Provide a DSPM-style view to answer "where's our sensitive data?", "what's at risk?", and "how do we fix it?".
  • Generate a remediation plan with phased actions aligned to compliance considerations and data protection best practices.

Quick Start

Ask for a DSPM view to see exposed data and begin remediation.

Frequently Asked Questions about orca-data-exposure

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I discover where sensitive data and PII are exposed across my cloud environments?

To discover sensitive data exposure, you can run a DSPM-style scan that identifies unprotected stores, exposed secrets, and PII across your accounts. It surfaces where sensitive data resides and ranks risks by exposure level.

What is DSPM and how does it help secure exposed credentials and API keys?

DSPM, or data security posture management, is the process of discovering and prioritizing sensitive data risk across environments. It helps secure exposed credentials and API keys by mapping data exposure and generating prioritized remediation plans.

Can I scope sensitive data discovery scans to specific asset types like unencrypted stores?

Yes, you can scope sensitive data discovery by specific data types such as secrets, PII, credentials, and API keys, or by account and asset. This targets unencrypted stores, public data stores, and internet-facing assets for remediation.

How do I generate a remediation plan for internet-facing assets and certificate exposure?

You generate a remediation plan for internet-facing assets and certificate exposure by running six parallel discovery searches. The scan enriches findings with compliance context to produce phased remediation actions for data protection.

What is the best way to prioritize data risk across on-premises and cloud data stores?

The best way to prioritize data risk is to use a DSPM view that ranks unprotected stores by exposure level. It evaluates public data stores, unencrypted stores, and internet-facing assets to deliver a phased remediation plan.

Does data exposure scanning provide compliance context for sensitive data protection?

Yes, data exposure scanning provides compliance context by enriching discovery results with data protection best practices. It aligns remediation guidance with compliance considerations to help secure sensitive data across systems.