Atlas / Skills / jeremylongshore / Groq Data Handling

Groq Data HandlingSAFE

skills/jeremylongshore/groq-data-handling

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.11.0
Hosts
1 documented
License
MIT
Stars
2,823
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: groq-data-handling
description: |
  Use when you need to keep PII out of Groq API calls, filter model responses,
  audit-log conversations, or track token cost and usage for a Groq integration.
  Implements prompt sanitization, PII redaction, response filtering, and usage
  tracking. Trigger with phrases like "groq data", "groq PII", "groq GDPR",
  "groq data retention", "groq privacy", "groq compliance".
allowed-tools: Read, Write, Edit
version: 1.11.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags:
- saas
- groq
- compliance
compatibility: Designed for Claude Code
---
# Groq Data Handling

## Overview

Manage data flowing through Groq's inference API. This skill wires a privacy
pipeline around the Groq SDK: sanitize prompts before they are sent, filter
responses after they return, redact PII, hash-log an audit trail, and track
token usage and cost. Key fact: Groq does not use API data for model training
([Groq Privacy Policy](https://groq.com/privacy-policy/)).

## Prerequisites

- Node.js project with the `groq-sdk` package installed (`npm i groq-sdk`).
- A Groq API key exported as `GROQ_API_KEY`. The SDK reads it automatically
  from the environment — `new Groq()` needs no explicit argument. Never hardcode
  the key; keep it in an untracked `.env` or your secret manager.
- Node's built-in `crypto` module (for the audit hash) — no install needed.

## Instructions

The pipeline layers in four stages; drop simple add-ons (moderation, cost
reporting) on top. Each snippet below is the skeleton — the full, copy-ready
code for every stage is in [references/implementation.md](references/implementation.md).

1. **Sanitize input** — run a PII rule table over every message before it
   leaves your process, flagging which categories were caught:

   ```typescript
   function sanitizeMessages(messages: any[]): { messages: any[]; hadPII: boolean } {
     // apply PII_RULES to each message's content; return redacted copy + flag
   }
   ```

2. **Wrap the completion call** — call `safeCompletion(...)` instead of the raw
   `groq.chat.completions.create`, so input and response both pass the sanitizer.

3. **Track usage** — `trackUsage(model, completion.usage, sessionId)` records
   token counts and estimated cost per call using a per-model price table.

4. **Audit** — `auditedCompletion(...)` ties it together and logs a SHA-256
   hash of the prompt (never the prompt text) so the audit trail carries no
   sensitive content.

For content moderation via Llama Guard and a daily cost report, see
[references/examples.md](references/examples.md).

### Groq data policy

- Groq does **not** train on API request/response data.
- Prompts and completions are processed and discarded.
- Groq may temporarily log requests for abuse prevention.
- For enterprise: contact Groq for DPA and SOC 2 compliance details.

## Output

- **Sanitized messages/responses** — text with `[EMAIL]`, `[PHONE]`, `[SSN]`,
  `[CARD]`, `[IP]` placeholders swapped in for detected PII, plus a `hadPII`
  boolean and a list of redacted categories.
- **Usage records** — one JSON line per call (`type: "groq_usage"`) with model,
  token counts, and `estimatedCostUsd`.
- **Audit entries** — one JSON line per call (`type: "groq_audit"`) carrying a
  prompt hash, `piiDetected`, `responseFiltered`, and the usage record.
- **Cost report** — an aggregated object with `totalCost`, `totalTokens`,
  `totalCalls`, and a per-model breakdown (see the sample in
  [references/examples.md](references/examples.md)).

## Error Handling

| Issue | Cause | Solution |
|-------|-------|----------|
| PII leaks in response | Model echoes sensitive input | Apply response filtering on all completions |
| Cost spike | 70B model for all requests | Route simple tasks to 8B |
| Missing usage data | Streaming mode | Use non-streaming for tracked requests, or estimate |
| Audit gaps | Not all code paths use wrapper | Lint rule: ban direct `groq.chat.completions.create` |
| `GROQ_API_KEY` not set | Key missing from environment | Export the key before running; the SDK throws on an unauthenticated call |

## Examples

- **Full four-stage pipeline** (sanitizer, safe wrapper, usage tracker,
  audited completion) — [references/implementation.md](references/implementation.md).
- **Content safety check** with Llama Guard and a **daily cost report** —
  [references/examples.md](references/examples.md).

Minimal end-to-end use once the helpers are in place:

```typescript
const { content, audit } = await auditedCompletion(sessionId, messages);
// content is PII-filtered; audit is a hash-only record safe to persist
```

## Resources

- [Groq Privacy Policy](https://groq.com/privacy-policy/)
- [Groq Pricing](https://groq.com/pricing)
- [Llama Guard (content moderation)](https://console.groq.com/docs/model/meta-llama/llama-guard-4-12b)
- [Full implementation](references/implementation.md) · [Examples](references/examples.md)

For enterprise access controls, see the `groq-enterprise-rbac` skill.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__groq-data-handling.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aSAFEB89first audit
06

Questions

What does the Groq Data Handling skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Groq Data Handling safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Groq Data Handling access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Groq Data Handling work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement