mistral-data-handling
Defines patterns for PII redaction and data compliance when interacting with Mistral AI APIs.
Install
mkdir -p .claude/skills/mistral-data-handling && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/8843" && unzip -o skill.zip -d .claude/skills/mistral-data-handling && rm skill.zipInstalls to .claude/skills/mistral-data-handling
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Implement Mistral AI PII handling, data retention, and GDPR/CCPA complianceKey capabilities
- →Redact PII from text prompts
- →Sanitize fine-tuning datasets
- →Implement conversation TTL and message limits
- →Perform GDPR-compliant user data erasure
- →Log audit metadata without storing message content
How it works
The skill uses regex-based patterns to identify and replace sensitive data like emails and SSNs, and provides a store class to manage conversation retention and erasure.
Inputs & outputs
When to use mistral-data-handling
- →Redact PII from prompts
- →Implement data retention policies
- →Ensure GDPR compliance
- →Audit sensitive data flows
About this skill
Mistral Data Lifecycle Governance
Overview
Map every data class through provider transit, app storage, derived artifacts, state, retention, and deletion. Never infer privacy from one endpoint or account feature.
Prerequisites
- A data inventory, lawful purpose, tenant boundary, retention requirements, and privacy owner.
- Current endpoint/account evidence including ZDR applicability.
- Deletion, subject-request, incident, and derived-data policies.
Current Contract
ZDR covers supported stateless paid-plan calls but excludes stateful products/APIs including Agents, Batch processing files, Conversations, Libraries, and /v1/files. Each workload needs review.
Authentication
Authorize data independently of the provider key. Never put credentials or customer content in logs, receipts, or diagnostics.
Instructions
- Classify prompts, outputs, embeddings, files, transcripts, OCR, batch artifacts, state IDs, and derived records.
- Map endpoint, account controls, transit, provider state, app stores, logs, backups, and subprocessors.
- Verify ZDR for the exact stateless operation; mark excluded/unknown stateful surfaces.
- Minimize/redact, isolate tenants, bound purpose/retention, and authorize before transmission.
- Track resource IDs and derived artifacts for cross-system deletion reconciliation.
- Test access, expiry, deletion, restore/backups, subject requests, and incident evidence.
Tool Discipline
Use Read, Glob, and Grep to inspect code, locks, configuration, tests, and evidence. Use Write and Edit only for approved repository changes. Invocation alone does not authorize network calls, paid usage, uploads, stateful resources, admin mutations, deployments, or deletion.
Approval Boundaries
Sensitive data, uploads, batch/stateful use, retention, region changes, training/fine-tuning, and deletion require privacy/security approval. Deprecated fine-tuning docs do not establish a current supported workflow.
Error Handling
- App deletion does not prove provider or index deletion.
- Embeddings, OCR, and transcripts remain sensitive derived data.
- Assuming ZDR for stateful APIs contradicts current exclusions.
Output
Return the data and endpoint map, purpose, ZDR evidence, stores and retention, deletion ledger, owners, risks, and receipts. Label exclusions and unknown provider state.
Examples
- Track document upload through OCR, index, backup, and deletion.
- Reject fine-tuning upload until a current supported contract and approval exist.
Validation
Trace records end to end, test tenant denial, retention, deletion, and restore behavior, and verify every ZDR assertion. Fail the review when any derived artifact lacks an owner.
Resources
- Current first-party evidence map — recheck dated sources before relying on mutable endpoints, models, limits, prices, preview status, or retention.
- Record live account observations as environment-specific evidence, not universal Mistral guarantees.
When not to use it
- →When domain-specific PII rules are not defined
- →When logging of raw message content is required for debugging
Prerequisites
Limitations
- →Regex-based redaction may miss domain-specific PII
- →Audit logging intentionally excludes message content
How it compares
It automates the sanitization of training data and conversation history, which is typically a manual and error-prone process.
Compared to similar skills
mistral-data-handling side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| mistral-data-handling (this skill) | 0 | 2mo | Review | Intermediate |
| firebase | 20 | 8mo | No flags | Intermediate |
| blockchain-developer | 6 | 5mo | No flags | Advanced |
| file-uploads | 4 | 8mo | No flags | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
firebase
davila7
Firebase gives you a complete backend in minutes - auth, database, storage, functions, hosting. But the ease of setup hides real complexity. Security rules are your last line of defense, and they're often wrong. Firestore queries are limited, and you learn this after you've designed your data model. This skill covers Firebase Authentication, Firestore, Realtime Database, Cloud Functions, Cloud Storage, and Firebase Hosting. Key insight: Firebase is optimized for read-heavy, denormalized data. I
blockchain-developer
sickn33
Build production-ready Web3 applications, smart contracts, and decentralized systems. Implements DeFi protocols, NFT platforms, DAOs, and enterprise blockchain integrations. Use PROACTIVELY for smart contracts, Web3 apps, DeFi protocols, or blockchain infrastructure.
file-uploads
davila7
Expert at handling file uploads and cloud storage. Covers S3, Cloudflare R2, presigned URLs, multipart uploads, and image optimization. Knows how to handle large files without blocking. Use when: file upload, S3, R2, presigned URL, multipart.
graphql
davila7
GraphQL gives clients exactly the data they need - no more, no less. One endpoint, typed schema, introspection. But the flexibility that makes it powerful also makes it dangerous. Without proper controls, clients can craft queries that bring down your server. This skill covers schema design, resolvers, DataLoader for N+1 prevention, federation for microservices, and client integration with Apollo/urql. Key insight: GraphQL is a contract. The schema is the API documentation. Design it carefully.
fullstack-guardian
Jeffallan
Use when implementing features across frontend and backend, building APIs with UI, or creating end-to-end data flows. Invoke for feature implementation, API development, UI building, cross-stack work.
backend-dev
marmelab
Coding practices for backend development in Atomic CRM. Use when deciding whether backend logic is needed, or when creating/modifying database migrations, views, triggers, RLS policies, edge functions, or custom dataProvider methods that call Supabase APIs.