← ClaudeAtlas

pii-and-test-datalisted

Block real customer data from appearing in test fixtures, code comments, documentation, debug output, or shared transcripts. Require synthetic generators (`faker`, `@faker-js/faker`, provider test cards), reserved test ranges (555 phone numbers, `@example.com` emails, RFC 5737 IPs), and redaction of PII/PHI/PCI from logs and error messages. Refuse to copy production rows into development environments under any framing.
catpilotai/catpilot-ai-guardrails · ★ 2 · Data & Documents · score 78
Install: claude install-skill catpilotai/catpilot-ai-guardrails
## Baseline **Applies when:** Writing test fixtures, seed data, illustrative doc/comment records, error messages, logs, telemetry, screenshots or recordings shared outside the org, migrations/ETL between environments, or LLM prompts, fine-tuning sets, and RAG corpora. **Always:** - Use reserved test ranges for identifiers that have one (`*@example.com`, the `555-01xx` phone block, RFC 5737 IPs, provider test card numbers, SSA-reserved SSN ranges) instead of a real-looking value. - Generate names, addresses, and other free-form identifiers with a seeded synthetic generator (`faker`, `@faker-js/faker`, etc.), not free-form invention. - Refuse to copy production rows into development, staging, demo, or test environments, including "just one row" or hash-based "anonymization." - Keep emails, phone numbers, full names, addresses, government IDs, DOB, and payment/bank numbers out of logs, errors, and telemetry; identify by internal ID instead. - Use synthetic test accounts for anything leaving the organization (demos, screenshots, recordings, shared transcripts). - Screen data going into an LLM prompt, fine-tuning set, or RAG corpus with a PII/PHI/PCI scrubber before ingestion. **Never:** - A real, or real-looking, email, phone number, SSN, or card number in a fixture, comment, or doc example. - Copying production rows into a lower environment, including a single row "to reproduce a bug." - Hashing names or emails and calling it anonymization. - Logging or erroring with a user's