Atlas / Skills / jeremylongshore / Lindy Data Handling

Lindy Data HandlingCAUTION

skills/jeremylongshore/lindy-data-handling

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
1.20.0
Hosts
1 documented
License
MIT
Stars
2,824
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-09
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: lindy-data-handling
description: 'Data handling best practices for Lindy AI agents.

  Use when managing sensitive data in agent workflows,

  implementing data privacy controls, or ensuring compliance.

  Trigger with phrases like "lindy data", "lindy privacy",

  "lindy PII", "lindy data handling", "lindy GDPR", "lindy HIPAA".

  '
allowed-tools: Read, Write, Edit
version: 1.20.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags:
- saas
- lindy
- compliance
compatibility: Designed for Claude Code
---
# Lindy Data Handling

## Overview

Lindy agents process data through triggers, LLM calls, actions, knowledge bases,
and memory. Data flows through Lindy's managed infrastructure with AES-256
encryption at rest and in transit. This skill covers data classification, PII
handling, prompt-level data controls, and regulatory compliance.

## Prerequisites

- Understanding of data types processed by your agents
- Knowledge of applicable regulations (GDPR, CCPA, HIPAA)
- For HIPAA: Business Associate Agreement (BAA) with Lindy (Enterprise plan)

## Lindy Data Architecture

| Component | Data Storage | Retention |
|-----------|-------------|-----------|
| **Tasks** | Task inputs, outputs, step data | Visible in dashboard |
| **Memory** | Persistent snippets across tasks | Until manually deleted |
| **Context** | Per-task accumulated context | Task lifetime only |
| **Knowledge Base** | Uploaded files, crawled sites | Until manually removed |
| **Integrations** | OAuth tokens, connection data | Until disconnected |
| **Computer Use** | Browser session, screenshots | 30 days after last use |

## Instructions

### Step 1: Classify Data in Agent Workflows

Map what data each agent processes:

| Data Category | Examples | Handling |
|--------------|---------|----------|
| **Public** | Product info, FAQs, pricing | No restrictions |
| **Internal** | Sales reports, meeting notes | Limit to authorized agents |
| **Confidential** | Customer emails, CRM data | Access controls + audit |
| **Restricted** | PII, PHI, payment data | Minimize exposure + compliance |

### Step 2: PII Controls in Agent Prompts

Add data handling instructions directly to agent prompts:

```
## Data Handling Rules
- Never include full email addresses in summaries — use "[name]@[domain]"
- Redact phone numbers in logs — show only last 4 digits
- Do not forward customer personal information to Slack channels
- When storing to spreadsheet, omit columns: email, phone, address
- If asked to share customer data externally, decline and escalate
```

### Step 3: Knowledge Base Data Safety

Knowledge base files are searchable by the agent. Control what goes in:

**DO upload**:

- Product documentation
- FAQ articles
- Policy documents
- Public knowledge articles

**DO NOT upload**:

- Customer databases with PII
- Credentials or API keys
- Internal HR documents (unless agent specifically needs them)
- Financial records with account numbers

**Resync considerations**: KB auto-refreshes every 24 hours. If you upload
sensitive content by mistake, remove it AND trigger a manual Resync.

### Step 4: Secure Memory Usage

Agent memories persist across all future tasks. Be deliberate:

```
Safe memory: "Customer prefers email communication over phone"
Safe memory: "Billing questions should escalate to [email protected]"

Risky memory: "John Smith's SSN is 123-45-6789"  ← NEVER store PII in memory
Risky memory: "API key for Stripe: sk_live_xxxx"  ← NEVER store secrets
```

Add to agent prompt:

```
## Memory Rules
- Never store personally identifiable information (PII) in memory
- Never store credentials, API keys, or passwords in memory
- Memories should contain preferences, patterns, and procedures only
```

### Step 5: Computer Use Data Isolation

If using Computer Use (browser automation):

- Sessions persist for 30 days with saved credentials
- Enable **Incognito mode** for sessions handling sensitive data
- Use **dedicated** (not shared) computer assignments for sensitive agents
- Review screenshots captured during execution for data exposure

### Step 6: Integration Account Isolation

- Authorize dedicated service accounts per agent (not personal accounts)
- Use Gmail with a team alias, not an individual inbox
- Create read-only database credentials where possible
- Revoke access immediately when an agent is decommissioned

### Step 7: Regulatory Compliance

**GDPR (EU Data Protection)**:

- [ ] Document what personal data each agent processes
- [ ] Ensure agents only process data with valid legal basis
- [ ] Implement data subject access/deletion capabilities
- [ ] Agent prompt includes "do not retain personal data beyond task completion"
- [ ] Review Lindy's data processing agreement

**CCPA (California Consumer Privacy)**:

- [ ] Identify agents processing California resident data
- [ ] Ensure opt-out mechanisms exist for data processing
- [ ] Agent prompt prevents selling/sharing personal information

**HIPAA (Healthcare)**:

- [ ] Enterprise plan with BAA in place
- [ ] Agents only access minimum necessary PHI
- [ ] No PHI in agent memory or knowledge base
- [ ] Audit trail enabled for all PHI access
- [ ] Agent prompt includes PHI handling restrictions

### Step 8: Data Retention Management

```
Agent Prompt Addition:
## Data Retention
- Do not reference data from tasks older than 30 days
- Clear task context after each run (do not accumulate indefinitely)
- When updating memory, remove outdated entries
- Summarize customer interactions, do not store verbatim transcripts
```

## Data Handling Checklist

- [ ] Each agent's data classification documented
- [ ] PII handling rules in every agent prompt
- [ ] Knowledge base audited for sensitive content
- [ ] Memory creation restricted (no PII, no secrets)
- [ ] Integration accounts isolated per agent
- [ ] Computer Use sessions set to dedicated + incognito where needed
- [ ] Regulatory compliance requirements mapped
- [ ] BAA in place if handling healthcare d
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SKILL.md:131
- Create read-only database credentials where possible
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__lindy-data-handling.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-094f83675ca38aCAUTIONB89first audit
06

Questions

What does the Lindy Data Handling skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Lindy Data Handling safe to install?

With care. The audit graded it B (89/100) and found 1 thing worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Lindy Data Handling access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Lindy Data Handling work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement