Atlas / Skills / jeremylongshore / Mistral Data Handling

Mistral Data HandlingSAFE

skills/jeremylongshore/mistral-data-handling

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.14.0
Hosts
1 documented
License
MIT
Stars
2,824
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-09
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: mistral-data-handling
description: >-
  Govern Mistral prompts, outputs, embeddings, files, OCR, audio, batch, stateful resources, and deletion evidence. Use when sensitive or retained data is involved. Trigger with "Mistral data retention", "upload a file to Mistral", or "review Mistral privacy".
allowed-tools: Read,Glob,Grep,Write,Edit
argument-hint: "<workload> <data-class> <retention-policy>"
version: 1.14.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags: [saas, mistral, data-governance]
model: inherit
effort: high
compatibility: "Designed for Claude Code; live or external Mistral actions require network access and explicit approval"
---
# Mistral Data Lifecycle Governance

## Overview

Map every data class through provider transit, app storage, derived artifacts, state, retention, and deletion. Never infer privacy from one endpoint or account feature.

## Prerequisites

- A data inventory, lawful purpose, tenant boundary, retention requirements, and privacy owner.
- Current endpoint/account evidence including ZDR applicability.
- Deletion, subject-request, incident, and derived-data policies.

## Current Contract

ZDR covers supported stateless paid-plan calls but excludes stateful products/APIs including Agents, Batch processing files, Conversations, Libraries, and `/v1/files`. Each workload needs review.

## Authentication

Authorize data independently of the provider key. Never put credentials or customer content in logs, receipts, or diagnostics.

## Instructions

1. Classify prompts, outputs, embeddings, files, transcripts, OCR, batch artifacts, state IDs, and derived records.
2. Map endpoint, account controls, transit, provider state, app stores, logs, backups, and subprocessors.
3. Verify ZDR for the exact stateless operation; mark excluded/unknown stateful surfaces.
4. Minimize/redact, isolate tenants, bound purpose/retention, and authorize before transmission.
5. Track resource IDs and derived artifacts for cross-system deletion reconciliation.
6. Test access, expiry, deletion, restore/backups, subject requests, and incident evidence.

## Tool Discipline

Use Read, Glob, and Grep to inspect code, locks, configuration, tests, and evidence. Use Write and Edit only for approved repository changes. Invocation alone does not authorize network calls, paid usage, uploads, stateful resources, admin mutations, deployments, or deletion.

## Approval Boundaries

Sensitive data, uploads, batch/stateful use, retention, region changes, training/fine-tuning, and deletion require privacy/security approval. Deprecated fine-tuning docs do not establish a current supported workflow.

## Error Handling

- App deletion does not prove provider or index deletion.
- Embeddings, OCR, and transcripts remain sensitive derived data.
- Assuming ZDR for stateful APIs contradicts current exclusions.

## Output

Return the data and endpoint map, purpose, ZDR evidence, stores and retention, deletion ledger, owners, risks, and receipts. Label exclusions and unknown provider state.

## Examples

- Track document upload through OCR, index, backup, and deletion.
- Reject fine-tuning upload until a current supported contract and approval exist.

## Validation

Trace records end to end, test tenant denial, retention, deletion, and restore behavior, and verify every ZDR assertion. Fail the review when any derived artifact lacks an owner.

## Resources

- [Current first-party evidence map](references/official-docs.md) — recheck dated sources before relying on mutable endpoints, models, limits, prices, preview status, or retention.
- Record live account observations as environment-specific evidence, not universal Mistral guarantees.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__mistral-data-handling.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-094f83675ca38aSAFEB89first audit
06

Questions

What does the Mistral Data Handling skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Mistral Data Handling safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Mistral Data Handling access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Mistral Data Handling work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement