---
name: velin-security-scan-pii
description: Scan for PII leakage risks; review.security.
---
# PII Security Scan

## Purpose
Scans for PII exposure and common security mistakes.

## Domain
R · category `security`

## Capabilities
- `review.security`

## Permission
`review-only`

## Allowed actions
- READ
- ANALYZE

## Forbidden actions
- WRITE
- APPLY
- ROLLBACK
- ACCEPT
- DEFER
- NOTE
- ACKNOWLEDGE
- CATALOG
- MANIFEST
- CLASSIFY
- invent-target

## Stop conditions
- SR-11

## Agent role / risk
Security · risk `low`

## Workflow
1. ANALYZE/VALIDATE only (`permission: review-only`).
2. Apply checklist below.
3. Unclear → STOP (SR-11/SR-03 as listed on skill).
4. Never rewrite-Apply, invent targets, or skip reuse on build handoffs.

## Checklist
- [ ] PII patterns in samples
- [ ] Fail closed
- [ ] Not HTML sanitize skill
- [ ] No migration mapping

## Best practices
- BP-V01, BP-A01 (when a11y), BP-T02 (when theme)

## Anti-patterns
- Silent WRITE/APPLY
- Treating review success as license to auto-map Tailwind residuals

## Inputs / Outputs
- Inputs: html, docs
- Outputs: report
