Juicebox Data HandlingSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-09Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: juicebox-data-handling description: 'Juicebox data privacy and GDPR. Trigger: "juicebox data privacy", "juicebox gdpr". ' allowed-tools: Read, Write, Edit, Grep version: 1.16.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - recruiting - juicebox compatibility: Designed for Claude Code --- # Juicebox Data Handling ## Overview Juicebox AI processes people datasets for talent intelligence and analysis workflows. Data types include people search results, enriched profile records (employment history, skills, social links), analysis exports, and outreach logs. Profile data often contains personal information governed by GDPR, CCPA, and recruitment privacy regulations. All enrichment results must be handled with consent tracking, purpose limitation, and right-to-deletion support. Contact data requires field-level encryption and strict access controls to prevent unauthorized disclosure. ## Data Classification | Data Type | Sensitivity | Retention | Encryption | |-----------|-------------|-----------|------------| | Search results | Low | Session only (ephemeral) | TLS in transit | | Enriched profiles | High (PII) | Per data policy, max 1 year | AES-256 at rest | | Contact data (email/phone) | High (PII) | Until candidate objects or deletion | Field-level encryption | | Analysis exports | Medium | 90 days | AES-256 at rest | | Outreach logs | Medium | 6 months | AES-256 at rest | ## Data Import ```typescript interface JuiceboxProfile { id: string; name: string; email?: string; phone?: string; company: string; title: string; skills: string[]; source: string; enrichedAt: string; } async function importPeopleDataset(query: string, maxResults = 100): Promise<JuiceboxProfile[]> { const profiles: JuiceboxProfile[] = []; let offset = 0; do { const res = await fetch(`https://api.juicebox.ai/v1/search`, { method: 'POST', headers: { Authorization: `Bearer ${process.env.JUICEBOX_API_KEY}`, 'Content-Type': 'application/json' }, body: JSON.stringify({ query, limit: 50, offset }), }); const data = await res.json(); if (!data.results?.length) break; for (const p of data.results) { if (!p.id || !p.name) throw new Error(`Invalid profile: missing required fields`); profiles.push(p); } offset += 50; } while (profiles.length < maxResults); return profiles; } ``` ## Data Export ```typescript async function exportAnalysisResults(profiles: JuiceboxProfile[], format: 'csv' | 'json') { // Strip direct contact info from exports unless explicitly authorized const sanitized = profiles.map(({ email, phone, ...rest }) => ({ ...rest, email: email ? '[CONSENT_REQUIRED]' : undefined, phone: phone ? '[CONSENT_REQUIRED]' : undefined, })); if (format === 'csv') { const header = Object.keys(sanitized[0]).join(','); const rows = sanitized.map(r => Object.values(r).join(',')); return [header, ...rows].join('\n'); } return JSON.stringify(sanitized, null, 2); } ``` ## Data Validation ```typescript function validateProfile(p: JuiceboxProfile): string[] { const errors: string[] = []; if (!p.id) errors.push('Missing profile ID'); if (!p.name || p.name.length > 200) errors.push('Invalid or missing name'); if (p.email && !/^[\w.+-]+@[\w-]+\.[\w.]+$/.test(p.email)) errors.push('Invalid email format'); if (p.phone && !/^\+?[\d\s()-]{7,20}$/.test(p.phone)) errors.push('Invalid phone format'); if (!p.source) errors.push('Missing data source attribution'); if (p.enrichedAt && isNaN(Date.parse(p.enrichedAt))) errors.push('Invalid enrichment timestamp'); return errors; } ``` ## Compliance - [ ] GDPR consent tracked per profile: lawful basis recorded (consent, legitimate interest) - [ ] Right-to-deletion: purge profile, enrichment data, and outreach logs within 30 days of request - [ ] GDPR data subject access: export all stored data for a candidate on request - [ ] CCPA opt-out: honor Do Not Sell signals for California residents - [ ] Purpose limitation: enrichment data used only for stated recruitment/analysis purpose - [ ] Contact data encrypted at field level with per-tenant keys - [ ] Audit log for all profile access, export, and deletion events - [ ] Data minimization: auto-purge enriched profiles older than retention window ## Error Handling | Issue | Cause | Fix | |-------|-------|-----| | API 401 unauthorized | Expired or revoked API key | Rotate key in secret manager, update env | | Duplicate profiles in import | Same person from multiple sources | Deduplicate by email hash before storage | | GDPR deletion incomplete | Outreach logs not purged alongside profile | Cascade delete across all related tables | | Export contains raw PII | Consent flag not checked before export | Add consent gate in `exportAnalysisResults` | | Enrichment timeout | Upstream data provider slow | Implement 10s timeout with retry, fallback to cached | ## Prerequisites - A documented source authority and lawful-use basis, data owner, classification/retention policy, suppression list, approved destination, and synthetic fixture. ## Instructions 1. Inventory fields, source terms, and intended destination before ingestion; quarantine unknown authority, classification, or suppression state. 2. Run schema, minimization, and suppression validation on bounded synthetic batches, logging only opaque IDs and aggregate counts. 3. Compare intended source/destination scope with policy before any enrichment or export, defaulting uncertainty to deny. 4. Submit idempotent staged work only to approved destinations, retain a redacted manifest, and verify deletion at the stated retention boundary. 5. Stop and escalate rather than weakening suppression, authority, or data-minimization rules. ## Output Return a handling receipt with source authority, classification, destination, policy revision, input/accepted/quarantined counts, suppression result, retention/deletion state, and rollback referen
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__juicebox-data-handling.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Juicebox Data Handling skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Juicebox Data Handling safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Juicebox Data Handling access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Juicebox Data Handling work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.