source-protection-plan
Assess and reduce the risk of exposing a confidential journalistic source. Use when a reporter is working with a confidential source, a whistleblowe…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Source Protection Plan Skill
A source who trusts you can be burned by a metadata field, a predictable meeting pattern, or a document only three people had. Protecting a source is operational, not just a promise. This skill maps how the source could realistically be identified and closes those channels — before, during, and after publication.
Working from a brief
Given the situation, produce the full plan — reason about the specific ways this source could be exposed given who they are and who wants to find them. Be honest about residual risk; do not over-promise anonymity you can't guarantee. This is defensive practice, not legal advice — recommend a media lawyer for legal exposure.
Required Inputs
Ask for (if not provided, else infer and label):
- The source's exposure — their access, how many people share it, and who would want to identify them (employer, state, litigant)
- How you're communicating and what material they've shared (documents, files, messages)
- What will be published and any deadline/legal context
Output Format
Threat model
Who is the adversary, what can they access (comms metadata, building logs, document distribution lists, timestamps), and the realistic ways this source could be identified — including the small-N problem ("only 5 people had this").
Communication & handling
Safer practices: end-to-end encrypted channels, minimizing metadata, secure drop/transfer options, device hygiene, meeting tradecraft, and how records are stored (and what not to keep).
Publication anonymization
The redaction/anonymization plan for the piece: stripping document metadata, paraphrasing telltale phrasing, generalizing identifying details, withholding the small-N specifics, and timing that doesn't finger the source.
The promise
What to actually promise the source (and what you can't guarantee), how attribution will read, and what happens if you're legally compelled — communicated honestly up front.
Residual risk
The risks that remain after all mitigations, stated plainly, and the recommendation to involve a media lawyer.
Quality Checks
- [ ] The threat model names the realistic identification channels, including small-N exposure
- [ ] Communication and document-handling practices reduce metadata and traceability
- [ ] The publication plan strips document metadata and telltale identifying details
- [ ] The source is promised only what can actually be delivered; compulsion is addressed honestly
- [ ] Residual risk is stated plainly, not hand-waved
- [ ] It recommends a media lawyer and states it is not itself legal advice
Anti-Patterns
- Promising absolute anonymity you can't guarantee
- Publishing documents with intact metadata or unique phrasing that fingers the source
- Ignoring the small-N problem (the detail only a few insiders knew)
- Communicating over channels the adversary can subpoena or monitor
- Keeping records that become a liability if compelled
- Treating this as legal advice instead of routing legal exposure to a lawyer
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
同名技能的其他版本
有 3 个不同仓库或目录里都有叫 source-protection-plan 的技能。它们内容并不相同,别混用:
- mohitagw15856/pm-claude-skills — Assess and reduce the risk of exposing a confidential journalistic source. Use when a repo
- mohitagw15856/pm-claude-skills — Assess and reduce the risk of exposing a confidential journalistic source. Use when a repo