Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Assess and reduce the risk of exposing a confidential journalistic source. Use when a reporter is working with a confidential source, a whistleblower, or sensitive leaked material and needs to protect the source's identity. Produces a risk assessment (how the source could be identified — metadata, comms, patterns, documents), secure-communication and handling practices, a redaction/anonymization plan for what's published, and the promises to make (and not make) about protection. Guidance is defe
.claude/skills/mohitagw15856-source-protection-plan/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-06 | ✗→✓ | ▲ Improved | 139% | 0% |
| case-11 | ✗→✓ | ▲ Improved | 56% | 0% |
| case-21 | ✗→✓ | ▲ Improved | 477% | 0% |
| case-17 | ✓→✗ | ▼ Worse | 35% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 55% | 0% |
A source who trusts you can be burned by a metadata field, a predictable meeting pattern, or a document only three people had. Protecting a source is operational, not just a promise. This skill maps how the source could realistically be identified and closes those channels — before, during, and after publication.
Given the situation, produce the full plan — reason about the specific ways this source could be exposed given who they are and who wants to find them. Be honest about residual risk; do not over-promise anonymity you can't guarantee. This is defensive practice, not legal advice — recommend a media lawyer for legal exposure.
Ask for (if not provided, else infer and label):
Who is the adversary, what can they access (comms metadata, building logs, document distribution lists, timestamps), and the realistic ways this source could be identified — including the small-N problem ("only 5 people had this").
Safer practices: end-to-end encrypted channels, minimizing metadata, secure drop/transfer options, device hygiene, meeting tradecraft, and how records are stored (and what not to keep).
The redaction/anonymization plan for the piece: stripping document metadata, paraphrasing telltale phrasing, generalizing identifying details, withholding the small-N specifics, and timing that doesn't finger the source.
What to actually promise the source (and what you can't guarantee), how attribution will read, and what happens if you're legally compelled — communicated honestly up front.
The risks that remain after all mitigations, stated plainly, and the recommendation to involve a media lawyer.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 29,236 | 32,385 | +11% | 1 | 1 | 0% | 3,226 | 4,563 | +41% | 0 | 0 | — |
case-02 | fail→fail | 28,138 | 36,128 | +28% | 1 | 1 | 0% | 3,555 | 5,271 | +48% | 0 | 0 | — |
case-03 | fail→fail | 29,382 | 31,431 | +7% | 1 | 1 | 0% | 3,566 | 4,994 | +40% | 0 | 0 | — |
case-04 | pass→pass | 22,621 | 28,260 | +25% | 1 | 1 | 0% | 2,505 | 3,887 | +55% | 0 | 0 | — |
case-05 | pass→pass | 16,770 | 26,754 | +60% | 1 | 1 | 0% | 2,511 | 3,932 | +57% | 0 | 0 | — |
case-06 | fail→pass | 27,775 | 31,985 | +15% | 1 | 1 | 0% | 1,946 | 4,659 | +139% | 0 | 0 | — |
case-07 | pass→pass | 17,968 | 23,649 | +32% | 1 | 1 | 0% | 2,086 | 3,414 | +64% | 0 | 0 | — |
case-08 | pass→pass | 23,963 | 23,781 | -1% | 1 | 1 | 0% | 2,679 | 4,102 | +53% | 0 | 0 | — |
case-09 | pass→pass | 20,572 | 25,863 | +26% | 1 | 1 | 0% | 1,924 | 3,670 | +91% | 0 | 0 | — |
case-10 | pass→pass | 20,784 | 26,451 | +27% | 1 | 1 | 0% | 2,405 | 3,976 | +65% | 0 | 0 | — |
case-11 | fail→pass | 22,290 | 22,267 | -0% | 1 | 1 | 0% | 2,475 | 3,868 | +56% | 0 | 0 | — |
case-12 | pass→pass | 22,543 | 38,836 | +72% | 1 | 1 | 0% | 2,641 | 4,757 | +80% | 0 | 0 | — |
case-13 | pass→pass | 16,102 | 27,304 | +70% | 1 | 1 | 0% | 1,957 | 3,827 | +96% | 0 | 0 | — |
case-14 | pass→pass | 14,282 | 18,921 | +32% | 1 | 1 | 0% | 2,168 | 3,379 | +56% | 0 | 0 | — |
case-15 | pass→pass | 11,710 | 22,045 | +88% | 1 | 1 | 0% | 1,514 | 3,064 | +102% | 0 | 0 | — |
case-16 | pass→pass | 19,228 | 22,436 | +17% | 1 | 1 | 0% | 2,146 | 3,688 | +72% | 0 | 0 | — |
case-17 | pass→fail | 20,174 | 22,736 | +13% | 1 | 1 | 0% | 2,842 | 3,837 | +35% | 0 | 0 | — |
case-18 | fail→fail | 23,999 | 25,782 | +7% | 1 | 1 | 0% | 2,899 | 4,298 | +48% | 0 | 0 | — |
case-19 | pass→pass | 17,449 | 30,161 | +73% | 1 | 1 | 0% | 2,682 | 4,400 | +64% | 0 | 0 | — |
case-20 | fail→fail | 17,063 | 38,274 | +124% | 1 | 1 | 0% | 2,769 | 5,209 | +88% | 0 | 0 | — |
case-21 | fail→pass | 6,697 | 26,117 | +290% | 1 | 1 | 0% | 761 | 4,388 | +477% | 0 | 0 | — |
case-22 | fail→fail | 7,082 | 7,692 | +9% | 1 | 1 | 0% | 565 | 1,420 | +151% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +9 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.