---
name: source-protection-plan
description: "Assess and reduce the risk of exposing a confidential journalistic source. Use when a reporter is working with a confidential source, a whistleblower, or sensitive leaked material and needs to protect the source's identity. Produces a risk assessment (how the source could be identified — metadata, comms, patterns, documents), secure-communication and handling practices, a redaction/anonymization plan for what's published, and the promises to make (and not make) about protection. Guidance is defensive; it is not legal advice."
homepage: https://mohitagw15856.github.io/pm-claude-skills/skill/source-protection-plan.html
metadata:
  {
    "openclaw": { "emoji": "🧠" }
  }
---

# Source Protection Plan Skill

A source who trusts you can be burned by a metadata field, a predictable meeting pattern, or a document only three people had. Protecting a source is operational, not just a promise. This skill maps how the source could realistically be identified and closes those channels — before, during, and after publication.

## Working from a brief

Given the situation, **produce the full plan** — reason about the specific ways *this* source could be exposed given who they are and who wants to find them. Be honest about residual risk; do not over-promise anonymity you can't guarantee. This is defensive practice, not legal advice — recommend a media lawyer for legal exposure.

## Required Inputs

Ask for (if not provided, else infer and label):
- **The source's exposure** — their access, how many people share it, and who would want to identify them (employer, state, litigant)
- **How you're communicating** and what **material** they've shared (documents, files, messages)
- **What will be published** and any deadline/legal context

## Output Format

### Threat model
Who is the adversary, what can they access (comms metadata, building logs, document distribution lists, timestamps), and the realistic ways this source could be identified — including the small-N problem ("only 5 people had this").

### Communication & handling
Safer practices: end-to-end encrypted channels, minimizing metadata, secure drop/transfer options, device hygiene, meeting tradecraft, and how records are stored (and what *not* to keep).

### Publication anonymization
The redaction/anonymization plan for the piece: stripping document metadata, paraphrasing telltale phrasing, generalizing identifying details, withholding the small-N specifics, and timing that doesn't finger the source.

### The promise
What to actually promise the source (and what you can't guarantee), how attribution will read, and what happens if you're legally compelled — communicated honestly up front.

### Residual risk
The risks that remain after all mitigations, stated plainly, and the recommendation to involve a media lawyer.

## Quality Checks

- [ ] The threat model names the realistic identification channels, including small-N exposure
- [ ] Communication and document-handling practices reduce metadata and traceability
- [ ] The publication plan strips document metadata and telltale identifying details
- [ ] The source is promised only what can actually be delivered; compulsion is addressed honestly
- [ ] Residual risk is stated plainly, not hand-waved
- [ ] It recommends a media lawyer and states it is not itself legal advice

## Anti-Patterns

- Promising absolute anonymity you can't guarantee
- Publishing documents with intact metadata or unique phrasing that fingers the source
- Ignoring the small-N problem (the detail only a few insiders knew)
- Communicating over channels the adversary can subpoena or monitor
- Keeping records that become a liability if compelled
- Treating this as legal advice instead of routing legal exposure to a lawyer
