Agent Skillsmohitagw15856/pm-claude-skills › source-protection-plan

source-protection-plan

GitHub

用于评估和保护机密新闻来源身份的安全技能。生成威胁模型、安全通信与处理指南、发布匿名化方案及风险承诺,帮助记者降低来源被识别的风险。

plugins/pm-journalism/skills/source-protection-plan/SKILL.md mohitagw15856/pm-claude-skills

Trigger Scenarios

记者需要保护机密消息源 涉及举报人或敏感泄露材料 制定来源保护计划

Install

npx skills add mohitagw15856/pm-claude-skills --skill source-protection-plan -g -y
More Options

Non-standard path

npx skills add https://github.com/mohitagw15856/pm-claude-skills/tree/main/plugins/pm-journalism/skills/source-protection-plan -g -y

Use without installing

npx skills use mohitagw15856/pm-claude-skills@source-protection-plan

指定 Agent (Claude Code)

npx skills add mohitagw15856/pm-claude-skills --skill source-protection-plan -a claude-code -g -y

安装 repo 全部 skill

npx skills add mohitagw15856/pm-claude-skills --all -g -y

预览 repo 内 skill

npx skills add mohitagw15856/pm-claude-skills --list

SKILL.md

Frontmatter
{
    "name": "source-protection-plan",
    "description": "Assess and reduce the risk of exposing a confidential journalistic source. Use when a reporter is working with a confidential source, a whistleblower, or sensitive leaked material and needs to protect the source's identity. Produces a risk assessment (how the source could be identified — metadata, comms, patterns, documents), secure-communication and handling practices, a redaction\/anonymization plan for what's published, and the promises to make (and not make) about protection. Guidance is defensive; it is not legal advice."
}

Source Protection Plan Skill

A source who trusts you can be burned by a metadata field, a predictable meeting pattern, or a document only three people had. Protecting a source is operational, not just a promise. This skill maps how the source could realistically be identified and closes those channels — before, during, and after publication.

Working from a brief

Given the situation, produce the full plan — reason about the specific ways this source could be exposed given who they are and who wants to find them. Be honest about residual risk; do not over-promise anonymity you can't guarantee. This is defensive practice, not legal advice — recommend a media lawyer for legal exposure.

Required Inputs

Ask for (if not provided, else infer and label):

  • The source's exposure — their access, how many people share it, and who would want to identify them (employer, state, litigant)
  • How you're communicating and what material they've shared (documents, files, messages)
  • What will be published and any deadline/legal context

Output Format

Threat model

Who is the adversary, what can they access (comms metadata, building logs, document distribution lists, timestamps), and the realistic ways this source could be identified — including the small-N problem ("only 5 people had this").

Communication & handling

Safer practices: end-to-end encrypted channels, minimizing metadata, secure drop/transfer options, device hygiene, meeting tradecraft, and how records are stored (and what not to keep).

Publication anonymization

The redaction/anonymization plan for the piece: stripping document metadata, paraphrasing telltale phrasing, generalizing identifying details, withholding the small-N specifics, and timing that doesn't finger the source.

The promise

What to actually promise the source (and what you can't guarantee), how attribution will read, and what happens if you're legally compelled — communicated honestly up front.

Residual risk

The risks that remain after all mitigations, stated plainly, and the recommendation to involve a media lawyer.

Quality Checks

  • The threat model names the realistic identification channels, including small-N exposure
  • Communication and document-handling practices reduce metadata and traceability
  • The publication plan strips document metadata and telltale identifying details
  • The source is promised only what can actually be delivered; compulsion is addressed honestly
  • Residual risk is stated plainly, not hand-waved
  • It recommends a media lawyer and states it is not itself legal advice

Anti-Patterns

  • Promising absolute anonymity you can't guarantee
  • Publishing documents with intact metadata or unique phrasing that fingers the source
  • Ignoring the small-N problem (the detail only a few insiders knew)
  • Communicating over channels the adversary can subpoena or monitor
  • Keeping records that become a liability if compelled
  • Treating this as legal advice instead of routing legal exposure to a lawyer

Version History

  • e4def4c Current 2026-07-31 01:27

Same Skill Collection

exports/openclaw/360-feedback-template/SKILL.md
exports/openclaw/401k-plan-decoder/SKILL.md
exports/openclaw/ab-test-planner/SKILL.md
exports/openclaw/ab-test-readout/SKILL.md
exports/openclaw/accessibility-audit/SKILL.md
exports/openclaw/account-plan/SKILL.md
exports/openclaw/acquirer-red-team/SKILL.md
exports/openclaw/ad-copy/SKILL.md
exports/openclaw/aeo-optimizer/SKILL.md
exports/openclaw/agenda-or-cancel/SKILL.md
exports/openclaw/agent-design-review/SKILL.md
exports/openclaw/agent-hiring-panel/SKILL.md
exports/openclaw/agent-observability-spec/SKILL.md
exports/openclaw/agent-severance/SKILL.md
exports/openclaw/agent-spec/SKILL.md
exports/openclaw/agm-in-a-box/SKILL.md
exports/openclaw/ai-ethics-review/SKILL.md
exports/openclaw/ai-eval-plan/SKILL.md
exports/openclaw/ai-feature-prd/SKILL.md
exports/openclaw/ai-product-canvas/SKILL.md
exports/openclaw/air-quality/SKILL.md
exports/openclaw/altitude-shifter/SKILL.md
exports/openclaw/ambiguity-resolver/SKILL.md
exports/openclaw/analyst-relations-brief/SKILL.md
exports/openclaw/announcement-card/SKILL.md
exports/openclaw/api-docs-writer/SKILL.md
exports/openclaw/api-test-plan/SKILL.md
exports/openclaw/api-versioning-strategy/SKILL.md
exports/openclaw/apology-letter/SKILL.md
exports/openclaw/architecture-decision-record/SKILL.md
exports/openclaw/architecture-diagram/SKILL.md
exports/openclaw/archive-strategy/SKILL.md
exports/openclaw/assumption-bounty/SKILL.md
exports/openclaw/assumption-mapper/SKILL.md
exports/openclaw/async-update-format/SKILL.md
exports/openclaw/auto-repair-estimate-decoder/SKILL.md
exports/openclaw/autopilot-charter/SKILL.md
exports/openclaw/awkward-message-helper/SKILL.md
exports/openclaw/behavior-intervention-plan/SKILL.md
exports/openclaw/benefits-decoder/SKILL.md
exports/openclaw/bennett-time-audit/SKILL.md
exports/openclaw/bid-tender-review/SKILL.md
exports/openclaw/board-deck-narrative/SKILL.md
exports/openclaw/board-game-designer/SKILL.md
exports/openclaw/board-game-night-planner/SKILL.md
exports/openclaw/board-minutes/SKILL.md
exports/openclaw/board-pre-read/SKILL.md
exports/openclaw/body-double-session/SKILL.md
exports/openclaw/bom-cost-review/SKILL.md
exports/openclaw/bookkeeping-categorization/SKILL.md

Metadata

Files
0
Version
a462f61
Hash
fd139a17
Indexed
2026-07-31 01:27

ホーム - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-13 08:44
浙ICP备14020137号-1 $お客様$