Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    RedactFirst: Pre Publish IP Decoupling Guard

    1

    Anonymizes code, configs, and prompts to prevent IP leaks and NDA violations before public release.

    Free

    Security scanned
    RedactFirst: Pre Publish IP Decoupling Guard

    RedactFirst: Pre Publish IP Decoupling Guard

    Example session with this skill installed

    Sanitize this internal database config for a blog post:

    Acme Corp staging

    host: db.internal.acme.co
    user: dev_admin
    pass: sk_live_55a92b
    region: US-East-1 (Virginia)

    • Read your context and instructions
    • Compiled the redactfirst
    • Generated the document

    Scan complete. Status:

    BREACH. Several direct identifiers and live secrets were detected. You must rotate the API key at the provider before publishing this content.

    RedactFirst Sanitization Report

    CategoryFindingRiskAction
    Direct IdentifierAcme CorpHighReplaced with Client-A
    Internal Domaindb.internal.acme.coHighReplaced with db.vendor.example
    Secret Survivorsk_live_55a92bCriticalROTATE KEY IMMEDIATELY
    Indirect IdentifierUS-East-1 (Virginia)MediumReplaced with region-1

    Sanitized Artifact

    
    # Client-A staging
    host: db.vendor.example
    user: user_admin
    pass: "[REDACTED_SECRET_ROTATE_AT_SOURCE]"
    region: region-1
    

    Next steps
    1.

    Rotate Secrets: The detected key sk_live_55a92b is a live credential. Redacting it in the text does not invalidate the leak.
    2.

    Verify Placeholders: Ensure Client-A and region-1 are used consistently across all other files in this blog post.
    3.

    Check Logic: Confirm the sanitized YAML still accurately demonstrates the configuration logic intended for your readers.

    redactfirst-pre-publish-ip-decoupling-gu.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    Publishing proprietary code or client projects to public repositories often leads to accidental IP leaks, NDA violations, and credential exposure. This skill automates the decoupling of intellectual property from your codebase, ensuring that what you share is clean, anonymous, and safe for public consumption.

    What it does

    • Identifier Redaction scans for and replaces client names, internal domains, and personal data with consistent placeholders.
    • Secret Detection identifies API keys, tokens, and hashes that require rotation rather than simple redaction.
    • Structural Integrity preserves all code logic and flow while stripping only the identifying metadata and strings.
    • Indirect Mapping flags unique tech stacks or dated comments that could be used to re-identify the source through context.
    • Risk Scoring provides a categorical verdict (CLEAR, WARNING, BREACH) based on the remaining footprint.

    How it works

    1. Direct Scan lists all occurrences of company names, private URLs, and employee credentials.
    2. Neutral Mapping replaces those values with consistent, non-identifying strings like client-a or vendor.example.
    3. Indirect Flagging highlights project-specific naming conventions or regional references for manual review.
    4. Final Reporting emits a risk assessment report alongside a sanitized version of the artifact for diffing.

    Frameworks & tools

    Works with any text-based artifact including source code (Python, JS, Go, etc.), configuration files (YAML, JSON, ENV), and system prompts.

    Why this beats prompting it yourself

    Manual redaction is prone to oversight, especially with indirect identifiers that don't look like secrets. This skill enforces strict consistency across multiple files, preventing the common mistake of using different placeholders for the same client entity.

    Use cases

    • Preparing internal tools for open-source release on GitHub.
    • Sanitizing configuration logs for technical blog posts or tutorials.
    • Cleaning up portfolio projects for job applications or public gists.
    • Scrubbing client-specific identifiers from marketplace templates.

    Known limitations

    Does not perform automated secret rotation at the provider level. Limited to text-based artifacts; binary files or compiled assets are not supported.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean today

    • Free to download with an account

    Needs access to

    Acme Corp
    Vendor

    Listedtoday

    What's inside

    Frequently Asked Questions