security-check

Evaluate input data sensitivity against organizational AI usage policies.

2|Updated May 24, 2026
One-click install
npx skills add https://github.com/CivicActions/ai-runbook-jh --skill security-check-civicactions
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-check
Source: https://github.com/CivicActions/ai-runbook-jh/tree/main/skills/security-check
Command: npx skills add https://github.com/CivicActions/ai-runbook-jh --skill security-check-civicactions

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill prevents the accidental exposure of sensitive information, PII, or confidential project data by providing a standardized pre-flight checklist before any content is shared with an AI tool.

Core Features & Use Cases

  • Risk Classification: Systematically categorizes content against PII, PHI, CUI, and client proprietary standards.
  • Environment Validation: Ensures AI usage aligns with project-specific environment restrictions and sanctioned tool lists.
  • Attribution Enforcement: Standardizes the application of AI-assisted disclosure markers to ensure compliance with organizational policy.

Quick Start

Run the security-check skill to evaluate the safety of the support ticket content before pasting it into the AI chat.

Frequently Asked Questions about security-check

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prevent PII exposure when sharing support tickets with an AI chat?

To prevent PII exposure, you can run a pre-flight security check that systematically categorizes content against PII, PHI, and CUI standards before pasting it into an AI chat. This ensures compliance with defined redaction protocols.

What is AI data redaction and how does it align with NIST AI risk management frameworks?

AI data redaction is a pre-flight process that evaluates input data sensitivity against organizational AI usage policies. It enforces adherence to sanctioned tool lists and redaction protocols to ensure compliance with NIST AI risk management frameworks.

Can I use an automated privacy gate for external user data and production logs?

Yes, a privacy gate applies to all sessions involving external user data, production logs, or restricted environment artifacts. It validates the environment against project-specific security contracts before sharing content.

How do I classify sensitive content against client proprietary standards before AI processing?

You classify sensitive content by running a risk classification check that categorizes inputs against client proprietary standards and organizational policies. This process ensures proper attribution enforcement before AI processing.

Do I need a pre-flight checklist to enforce AI-assisted disclosure markers?

Yes, using a pre-flight checklist standardizes the application of AI-assisted disclosure markers. This attribution enforcement ensures your content sharing aligns with organizational policy and project-specific environment restrictions.

When should I not use an automated security compliance check for AI inputs?

You should not skip a security compliance check when handling external user data or restricted environment artifacts. It is a required gate to prevent accidental exposure of confidential project data and maintain NIST compliance.