Skip to content

P3: CLAUDE.md PII pre-commit scanner #39

@ramdhanyk

Description

@ramdhanyk

Source: 2026-04-20 multi-expert AADM audit. Security auditor.

Problem

Nothing prevents an engineer pasting a PHI sample, secret, or customer record into CLAUDE.md's "Client-specific context" section. That content then enters every Claude session transcript.

Fix

Pre-commit hook scanning CLAUDE.md and sprints/**/*.md for:

Block commit on hit; require explicit override + suppression entry.

Acceptance

A planted email in CLAUDE.md fails commit. An explicit override path with audit trail exists.

Depends on

Metadata

Metadata

Assignees

No one assigned

    Labels

    P3Lower-stakes fillsaudit-followupFrom the 2026-04-20 multi-expert AADM audit

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions