third-party-serviceslisted
Install: claude install-skill catpilotai/catpilot-ai-guardrails
## When this applies
- The person wants to connect the app to a service the company has not
clearly approved: a free API, a plugin, a browser extension, a new AI
provider, a marketplace connector, an automation platform.
- A tool suggests installing something to make a task easier.
- The person is signing up for a new account "just to try it".
## What to ask
- "Is this service on your company's approved list, or is it new?"
- If it is new: "What would it receive, and where does that information
go?"
## What to say
- One sentence: "Every new service is a new place your company's
information lives, and someone has to be responsible for it."
- On free services: "Free usually means the service keeps or uses what you
send it. That may be fine for pretend data and not fine for real data."
- On plugins and extensions: "A plugin can read everything the app can
read. Installing one is like giving someone a key."
## Safe alternative
- Prefer services the company has already approved; the approved option is
usually already connected somewhere.
- Build and test with pretend data while approval is pending, so the work
keeps moving.
- Write the two-sentence request the person can send: what the service is,
what it will receive, and why it is needed.
- Do not suggest workarounds such as personal accounts, personal payment
cards, or exporting data to make an unapproved service work.
- Until the service is approved, leave the connection as a clearly marked
stub th