alibabacloud-bailian-m…
Explain, evaluate, demonstrate, provision, and integrate Alibaba Cloud Bailian Managed Agent…
管理 Dataphin 数据脱敏规则配置的需求拆解、前置分类分级检查和公开 API 覆盖边界。 当用户要给手机号、身份证号、邮箱、姓名等敏感字段配置掩码、加密、哈希、保留首尾、白名单绕过或验证查询脱敏效果时进入。 触发词:数据脱敏、脱敏规则、动态脱敏、字段脱敏、手机号打星、身份证脱敏、邮箱脱敏、白名单、desensitize、masking、mask、FPE、MD5、NO_MASK。 关键限制:当前 dataphin-public CLI 和版本感知 OpenAPI 索引未暴露脱敏规则 CRUD;本 Skill 不伪造内部 REST
$ npx -y skills add aliyun/alibabacloud-aiops-skills --skill manage-data-masking --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/manage-data-maskingContext preview
The summary Claude sees to decide when to auto-load this skill.
管理 Dataphin 数据脱敏规则配置的需求拆解、前置分类分级检查和公开 API 覆盖边界。 当用户要给手机号、身份证号、邮箱、姓名等敏感字段配置掩码、加密、哈希、保留首尾、白名单绕过或验证查询脱敏效果时进入。 触发词:数据脱敏、脱敏规则、动态脱敏、字段脱敏、手机号打星、身份证脱敏、邮箱脱敏、白名单、desensitize、masking、mask、FPE、MD5、NO_MASK。 关键限制:当前 dataphin-public CLI 和版本感知 OpenAPI 索引未暴露脱敏规则 CRUD;本 Skill 不伪造内部 REST
name: manage-data-masking description: |- 管理 Dataphin 数据脱敏规则配置的需求拆解、前置分类分级检查和公开 API 覆盖边界。 当用户要给手机号、身份证号、邮箱、姓名等敏感字段配置掩码、加密、哈希、保留首尾、白名单绕过或验证查询脱敏效果时进入。 触发词:数据脱敏、脱敏规则、动态脱敏、字段脱敏、手机号打星、身份证脱敏、邮箱脱敏、白名单、desensitize、masking、mask、FPE、MD5、NO_MASK。 关键限制:当前 dataphin-public CLI 和版本感知 OpenAPI 索引未暴露脱敏规则 CRUD;本 Skill 不伪造内部 REST 为外部命令,只执行公开分类分级前置检查并输出可交付参数清单。
在 Dataphin 数据安全中,数据脱敏规则用于在即席查询、读写开发、资产访问等场景中保护敏感字段,例如手机号中间四位打星、身份证号保留首尾、邮箱 `@` 前遮盖、哈希或保留格式加密。
本 Skill 处理三类工作:
**Architecture**:`Tenant → Security Classify → Field Identify Result → Masking Requirement → Public API Gap / Internal REST Reference`
可通过公开 CLI 做的前置检查:
未在当前公开 CLI / swagger 暴露的脱敏能力:
aliyun plugin install --names aliyun-cli-dataphin-public
各操作系统一键安装脚本与版本要求详见 [references/cli-installation-guide.md](references/cli-installation-guide.md)。
> 凭证与环境变量由父 skill `alibabacloud-dataphin-skills` 统一声明并预检(父 §3 + §4 Authentication + §8 Step 0,先于路由到本 skill 执行);本 skill 不重复声明。
> **Pre-check: Alibaba Cloud Credentials Required** > > **Security Rules:** > - **NEVER** 读取、回显或打印凭证环境变量 > - **NEVER** ask the user to input AK/SK directly in the conversation or command line > - **NEVER** use `aliyun configure set` with literal credential values > - **ONLY** use `aliyun configure list` to check credential status > > ```bash > aliyun configure list > ``` > Check the output for a valid profile. > > **If no valid profile exists, STOP here.**
**Pre-check: Aliyun CLI >= 3.4.8 required** > Run `aliyun version` to verify >= 3.4.8. If not installed or version too low, install/update from https://aliyuncli.alicdn.com (see [references/cli-installation-guide.md](references/cli-installation-guide.md)).
**Pre-check: Aliyun CLI plugin update required** > [MUST] run `aliyun configure set --auto-plugin-install true` to enable automatic plugin installation. > [MUST] run `aliyun plugin update` to ensure that any existing plugins are always up-to-date.
最小权限策略详见 [../../ram-policies.md](../../ram-policies.md)。
> **[MUST] Permission Failure Handling:** When any command or API call fails due to permission errors at any point during execution, follow this process: > 1. Read `../../ram-policies.md` to get the full list of permissions required by this SKILL > 2. Use `ram-permission-diagnose` skill to guide the user through requesting the necessary permissions > 3. Pause and wait until the user confirms that the required permissions have been granted
> **IMPORTANT: Parameter Confirmation** — Before executing any command or API call, ALL user-customizable parameters MUST be confirmed with the user. Do NOT assume or use default values without explicit user approval.
| 参数 | 必填 | 描述 | 默认值 | |---|---|---|---| | `--tenant-id` | 是 | 租户 ID(大整数,建议字符串传) | — | | `--table-catalog` | 是 | 表 Catalog;逻辑表通常为板块英文名,物理表为项目英文名,数据源表为 db/schema | — | | `--table-name` | 是 | 目标表名 | — | | `--field-name` | 是 | 需要脱敏的字段名,如 `phone`、`id_card`、`email` | — | | `--classify-id` | 脱敏规则执行前必需 | 字段所属数据分类 ID;公开 CLI 只能回读/验证,不能创建脱敏规则 | — | | `algorithmCode` | 需求清单必需 | 脱敏算法,如 `MASK`、`MD5`、`FPE_FF1_ENCRYPT`、`NO_MASK` 等,以租户实际枚举为准 | — | | `ruleScopes` | 需求清单必需 | 作用范围,如业务板块、项目、平台、场景、账号、表范围 | — | | `whiteListAccount` | 白名单场景必需 | 允许绕过脱敏的账号 | — | | `effectiveDateRange` | 白名单场景必需 | 白名单生效起止日期 | — |
版本 `{version}`(Shell 变量 `SKILL_VERSION`)来自套件 `references/manifest.json` 的 `version` 字段,与 session-id 一同继承[父技能 §7](../../../SKILL.md#7-observability)。直接加载本子技能时先完成父层初始化;所有 CLI / SDK 调用使用父技能名称与同一版本,跨 Shell 调用须重新注入这些值。
**session-id 由父 skill `alibabacloud-dataphin-skills` 在套件入口加载时生成(32-char 小写 hex),本子 skill 加载时直接继承同一 session-id,不再重新生成。**
**Rule: Every `aliyun` CLI command that calls a cloud API MUST include the `--user-agent` flag.** Local utility commands (e.g. `configure`, `plugin`, `version`) do not support this flag and should be excluded.
--user-agent "AlibabaCloud-Agent-Skills/alibabacloud-dataphin-skills/{session-id} skill-version/{version}"Do not skip, alter the format, or omit `--user-agent` on any `aliyun` API command invocation.
TENANT_ID="<大整数租户 ID,字符串>"
SESSION_ID="<inherited from alibabacloud-dataphin-skills>"
UA="AlibabaCloud-Agent-Skills/alibabacloud-dataphin-skills/$SESSION_ID skill-version/$SKILL_VERSION"
# 1) 核对版本感知 OpenAPI 索引与本 Skill 使用的公开前置检查命令。
# 当前索引没有脱敏规则 CRUD;不要拉取裸 dataphin-public --help 全量输出。
aliyun dataphin-public list-security-identify-results --help
aliyun dataphin-public list-security-identify-records --help
aliyun dataphin-public get-security-classify --help
# 2) 查询目标字段是否已有分类分级标签。没有标签时,应提示先完成字段分类分级。
# 识别结果数组在 .PageResult.SecurityIdentifyResultList[],提取用:
# ... --cli-query 'PageResult.SecurityIdentifyResultList[].{Field:FieldName,ClassifyId:ClassifyId,Level:LevelName,Status:Status}'
aliyun dataphin-public list-security-identify-results --tenant-id "$TENANT_ID" \
--keyword "<表名或字段名>" \
--page-no 1 --page-size 10 \
--user-agent "$UA" --format json
# 3) 对目标字段做精确识别记录回读,确认 table-catalog / table-name / field-name 口径正确。
# 记录数组在 .PageResult.IdentifyRecordList[](注意与命令名不对称,不是 SecurityIdentifyRecordList)
aliyun dataphin-public list-security-identify-records --tenant-id "$TENANT_ID" \
--table-catalog "<项目英文名或板块英文名或数据源 schema>" \
--table-name "<表名>" \
--field-name "<字段名>" \
--page-no 1 --page-sizeOfficial Alibaba Cloud Agent Skills collection, providing AI agents with rich Alibaba Cloud product capabilities and general-purpose tooling.
Explain, evaluate, demonstrate, provision, and integrate Alibaba Cloud Bailian Managed Agent…
Alibaba Cloud Parse-X intelligent document parsing and extraction tool. Supports two…
Execute code in a secure cloud sandbox via AgentBay SDK. Use this skill whenever users…
Operate Alibaba Cloud AgentLoop Dataset resources with aliyun CLI and the AgentLoop API…
Orchestrate AgentLoop evaluation workflows through the Aliyun CLI plugin with safe previews,…
Proactively use AgentLoop Recall to retrieve prior Alibaba Cloud AgentLoop experience through…