Groq Data HandlingSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: groq-data-handling description: | Use when you need to keep PII out of Groq API calls, filter model responses, audit-log conversations, or track token cost and usage for a Groq integration. Implements prompt sanitization, PII redaction, response filtering, and usage tracking. Trigger with phrases like "groq data", "groq PII", "groq GDPR", "groq data retention", "groq privacy", "groq compliance". allowed-tools: Read, Write, Edit version: 1.11.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - groq - compliance compatibility: Designed for Claude Code --- # Groq Data Handling ## Overview Manage data flowing through Groq's inference API. This skill wires a privacy pipeline around the Groq SDK: sanitize prompts before they are sent, filter responses after they return, redact PII, hash-log an audit trail, and track token usage and cost. Key fact: Groq does not use API data for model training ([Groq Privacy Policy](https://groq.com/privacy-policy/)). ## Prerequisites - Node.js project with the `groq-sdk` package installed (`npm i groq-sdk`). - A Groq API key exported as `GROQ_API_KEY`. The SDK reads it automatically from the environment — `new Groq()` needs no explicit argument. Never hardcode the key; keep it in an untracked `.env` or your secret manager. - Node's built-in `crypto` module (for the audit hash) — no install needed. ## Instructions The pipeline layers in four stages; drop simple add-ons (moderation, cost reporting) on top. Each snippet below is the skeleton — the full, copy-ready code for every stage is in [references/implementation.md](references/implementation.md). 1. **Sanitize input** — run a PII rule table over every message before it leaves your process, flagging which categories were caught: ```typescript function sanitizeMessages(messages: any[]): { messages: any[]; hadPII: boolean } { // apply PII_RULES to each message's content; return redacted copy + flag } ``` 2. **Wrap the completion call** — call `safeCompletion(...)` instead of the raw `groq.chat.completions.create`, so input and response both pass the sanitizer. 3. **Track usage** — `trackUsage(model, completion.usage, sessionId)` records token counts and estimated cost per call using a per-model price table. 4. **Audit** — `auditedCompletion(...)` ties it together and logs a SHA-256 hash of the prompt (never the prompt text) so the audit trail carries no sensitive content. For content moderation via Llama Guard and a daily cost report, see [references/examples.md](references/examples.md). ### Groq data policy - Groq does **not** train on API request/response data. - Prompts and completions are processed and discarded. - Groq may temporarily log requests for abuse prevention. - For enterprise: contact Groq for DPA and SOC 2 compliance details. ## Output - **Sanitized messages/responses** — text with `[EMAIL]`, `[PHONE]`, `[SSN]`, `[CARD]`, `[IP]` placeholders swapped in for detected PII, plus a `hadPII` boolean and a list of redacted categories. - **Usage records** — one JSON line per call (`type: "groq_usage"`) with model, token counts, and `estimatedCostUsd`. - **Audit entries** — one JSON line per call (`type: "groq_audit"`) carrying a prompt hash, `piiDetected`, `responseFiltered`, and the usage record. - **Cost report** — an aggregated object with `totalCost`, `totalTokens`, `totalCalls`, and a per-model breakdown (see the sample in [references/examples.md](references/examples.md)). ## Error Handling | Issue | Cause | Solution | |-------|-------|----------| | PII leaks in response | Model echoes sensitive input | Apply response filtering on all completions | | Cost spike | 70B model for all requests | Route simple tasks to 8B | | Missing usage data | Streaming mode | Use non-streaming for tracked requests, or estimate | | Audit gaps | Not all code paths use wrapper | Lint rule: ban direct `groq.chat.completions.create` | | `GROQ_API_KEY` not set | Key missing from environment | Export the key before running; the SDK throws on an unauthenticated call | ## Examples - **Full four-stage pipeline** (sanitizer, safe wrapper, usage tracker, audited completion) — [references/implementation.md](references/implementation.md). - **Content safety check** with Llama Guard and a **daily cost report** — [references/examples.md](references/examples.md). Minimal end-to-end use once the helpers are in place: ```typescript const { content, audit } = await auditedCompletion(sessionId, messages); // content is PII-filtered; audit is a hash-only record safe to persist ``` ## Resources - [Groq Privacy Policy](https://groq.com/privacy-policy/) - [Groq Pricing](https://groq.com/pricing) - [Llama Guard (content moderation)](https://console.groq.com/docs/model/meta-llama/llama-guard-4-12b) - [Full implementation](references/implementation.md) · [Examples](references/examples.md) For enterprise access controls, see the `groq-enterprise-rbac` skill.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__groq-data-handling.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Groq Data Handling skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Groq Data Handling safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Groq Data Handling access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Groq Data Handling work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.