Skip to content

sensitive-data-reviewer

Inspect a screenshot for sensitive data — emails, API keys/tokens, passwords, phone numbers, credit-card/SSN numbers, personal names, addresses, internal hostnames/IPs — and return each finding's bounding region plus a risk class (high/low) and recommended blur style. It marks; it does not blur (the redactor does). Read-only over the image.

At a glance

Model inherits the session's
Tools Read Grep Glob
Author navjyotnishant
Source agents/sensitive-data-reviewer.md

Returns content — does not write files

Like all but two of the agents, this one returns its output to the skill that spawned it, and the skill writes the file. It holds no write tools, so it cannot modify the repo even if asked to.

When it runs

A raw dashboard screenshot was captured and may contain customer PII.

check this screenshot for sensitive data before we use it

The capture-screenshots skill spawns this agent after capture; its marked regions feed the redactor.

What it returns

Return the findings list (regions + type + risk + style) and a one-line summary ("6 sensitive regions: 2 high, 4 low"). If the image is too low-res to locate a value confidently, say so and give your best bounding box marked low-confidence — the redactor's verify step will treat low-confidence coverage as a blocker.

Spawned by

Derived, not declared

No agent file records which skills call it — this list is recovered from the skill definitions at build time, so it cannot go stale.

See the /capture-screenshots pipeline for where this fits in the whole run.

Read agents/sensitive-data-reviewer.md →