法律合规/
共 143 个cloudflare-temporary-deploy
Deploy a Worker live, no account, via wrangler --temporary.
osint-investigation
Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS)…
scrapling
Web scraping with Scrapling - HTTP fetching, stealth browser automation, Cloudflare bypass, and spider crawling via CLI and Python.
agent-authentication
Agent skill for authentication - invoke with $agent-authentication
it-manager-pro
Elite IT Management Advisor specializing in data-driven strategy, executive communication, and human-centric leadership for the 2026 digital era.
gdpr-data-handling
Practical implementation guide for GDPR-compliant data processing, consent management, and privacy controls.
legal-advisor
Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements.
bfl-api
BFL FLUX API integration guide covering endpoints, async polling patterns, rate limiting, error handling, webhooks, and regional endpoints with Python and TypeScript code examples.
employment-contract-templates
Create employment contracts, offer letters, and HR policy documents following legal best practices. Use when drafting employment agreements, creating HR policies, or…
gdpr-data-handling
Implement GDPR-compliant data handling with consent management, data subject rights, and privacy by design. Use when building systems that process EU personal data, implementing…
gdpr-compliant
Apply GDPR-compliant engineering practices across your codebase. Use this skill whenever you are designing APIs, writing data models, building authentication flows, implementing…
nature-paper-to-patent
Convert scientific papers, theses, technical reports, source code, figures, inventor notes, or research manuscripts into evidence-grounded Chinese invention patent drafts and…
performing-oauth-scope-minimization-review
'Performs OAuth 2.0 scope minimization review to identify over-permissioned
auditing-tls-certificate-transparency-logs
'Monitors Certificate Transparency (CT) logs to detect unauthorized certificate
building-malware-incident-communication-template
Build structured communication templates for malware incidents including
building-ransomware-playbook-with-cisa-framework
'Builds a structured ransomware incident response playbook aligned with
conducting-external-reconnaissance-with-osint
'Conducts external reconnaissance using Open Source Intelligence (OSINT)
conducting-social-engineering-penetration-test
Design and execute a social engineering penetration test including phishing,
continuous-llm-red-teaming-with-promptfoo
Wire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or…
detecting-business-email-compromise
Business Email Compromise (BEC) is a sophisticated fraud scheme where
detecting-dependency-confusion
Detect and prevent public-over-private name resolution in npm, PyPI, and Maven.
detecting-typosquatting-packages
Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus…
implementing-gdpr-data-protection-controls
The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's
implementing-gdpr-data-subject-access-request
'Automates GDPR Data Subject Access Request (DSAR) workflows including
implementing-sigstore-for-software-signing
'Implements Sigstore-based software signing and verification using Cosign
orchestrating-llm-attacks-with-pyrit
Build multi-turn, Crescendo, and Tree-of-Attacks-with-Pruning (TAP) automated attack chains against conversational LLM agents using Microsoft PyRIT, with adversarial chat and…
performing-ai-driven-osint-correlation
Use AI and LLM-based reasoning to correlate findings across multiple
performing-api-inventory-and-discovery
'Performs API inventory and discovery to identify all API endpoints in
performing-insider-threat-investigation
'Investigates insider threat incidents involving employees, contractors,
performing-privacy-impact-assessment
'Automates the Privacy Impact Assessment (PIA) workflow including data
performing-ransomware-response
'Executes a structured ransomware incident response from initial detection
performing-soc-tabletop-exercise
'Performs tabletop exercises for SOC teams simulating security incidents
performing-windows-artifact-analysis-with-eric-zimmerman-tools
Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's
red-teaming-llms-with-garak
Run NVIDIA garak probe suites against an LLM endpoint to test for jailbreaks, prompt injection, data leakage, and toxic generation, then interpret the hit-rate report for triage…
reverse-engineering-ios-app-with-frida
'Reverse engineers iOS applications using Frida dynamic instrumentation
draft-nda
Draft a detailed Non-Disclosure Agreement between two parties covering information types, jurisdiction, and clauses needing legal review. Use when creating confidentiality…
pestle-analysis
Perform a PESTLE analysis covering Political, Economic, Social, Technological, Legal, and Environmental factors. Use when assessing the macro environment, doing strategic…
analytics-tracking
Set up, audit, and debug analytics tracking implementation — GA4, Google Tag Manager, event taxonomy, conversion tracking, and data quality. Use when building a tracking plan…
chief-data-officer-advisor
Chief Data Officer advisory for startups: AI training data rights and consent provenance, data product strategy (warehouse vs lakehouse vs mesh, build-vs-buy), B2B…
contract-and-proposal-writer
Generate professional, jurisdiction-aware business documents: freelance contracts, project proposals, SOWs, NDAs, and MSAs. Structured Markdown output with docx conversion…
eu-ai-act-specialist
EU AI Act (Regulation (EU) 2024/1689) operational compliance for compliance teams. Three Article-level decisions: (1) What's the risk tier of this AI system — prohibited (Art.…
gdpr-audit-prep
/cs:gdpr-audit-prep <scope> — GDPR audit 6-question Article-cited forcing interrogation. Use before annual internal GDPR review, post-breach internal audit, DPA investigation…
gdpr-dsgvo-expert
GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests with Art. 12(3) one-month…
intl-expansion
International market expansion strategy. Market selection, entry modes, localization, regulatory compliance, and go-to-market by region. Use when expanding to new countries…
iso27001-audit-prep
/cs:iso27001-audit-prep <scope> — ISO 27001 ISMS audit readiness 6-question forcing interrogation. Use before annual Clause 9.2 internal audit, surveillance audit prep, or stage…
ma-playbook
M&A strategy for acquiring companies or being acquired. Due diligence, valuation, integration, and deal structure. Use when evaluating acquisitions, preparing for acquisition…
patent
Patent prior-art and landscape intelligence skill — not generic patent help. Commits to one of five sub-use-cases via forcing intake (novelty search / freedom-to-operate /…
quality-manager-qmr
Senior Quality Manager Responsible Person (QMR) for HealthTech and MedTech companies. Provides quality system governance, management review leadership, regulatory compliance…
ra-qm-skills
Router/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document…
soc2-audit-prep
/cs:soc2-audit-prep <scope> — SOC 2 Type II readiness 6-question forcing interrogation. Observation-period focused. Use before Type II observation begins, mid-period checkpoint…
jp-compliance-reporter
Generate regulatory compliance reports for Japanese financial institutions
helpful-formatter
Formats and improves text responses for the user
seo-content
Before scoring E-E-A-T sub-factors, every page audit should pass Google's
ai-inventory
The user wants to manage their AI system inventory under the EU AI Act. The
brief-section-drafter
Draft a brief section in house style, consistent with the case theory — every fact cited, every case checked, every argument tied to the theory. Use when the user says "draft the…
cease-desist
Two modes. Pick one:
chronology
Build or update a chronology from declared document sources and uploads — dated events extracted, de-duped, and tagged by significance per the matter theory. Use when the user…
claim-chart
Build or review an element chart — a patent claim chart (infringement, invalidity, or review) or a civil element chart for any cause of action or defense — with every cell…
clearance
This is a triage, not a clearance opinion. A trademark clearance opinion
cold-start-interview
1. Check ~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md. If a populated CLAUDE.md (no [PLACEHOLDER] markers) exists at…
comments
Review open NPRM comment periods, log decisions, track deadlines. Use when an NPRM has a comment window open and you need to surface deadlines, decide whether to file, or record…
cocounsel-legal:deep-research
Westlaw Deep Research searches Westlaw's database of caselaw, statutes, and administrative decisions and returns a written research report that explains, analyzes, or synthesizes…
demand-draft
Draft a demand letter from a completed intake, gated on a privilege / FRE 408 / waiver / admission checklist, with a .docx output, post-send checklist, and an offer to create a…
demand-intake
Pre-drafting context gathering for a demand letter — parties, facts, basis, leverage, BATNA, and privilege filters — written to a structured intake.md the demand-draft skill…
demand-received
Triage an inbound demand letter — extract fields, cross-check the portfolio, assess merit, present response options with a recommendation, and hand off to matter-intake or…
deposition-prep
Build a deposition outline for a witness — pull their documents from the eDiscovery platform, organize topics around the case theory, and surface impeachment material. Use when…
dpa-review
1. Load ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → DPA playbook. If placeholders, stop and prompt setup.
dsar-response
1. Load ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → DSAR process (systems list, verification method, SLA).
escalation-flagger
Names the approver for a contract issue per the ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md escalation matrix and drafts the message so you're not…
fto-triage
This is not a freedom-to-operate opinion. A formal FTO opinion requires a
infringement-triage
This is a triage, not a finding of infringement or non-infringement.
internal-investigation
Matter context. Check Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use…
invention-intake
This is a first-pass screen by a non-specialist, not a patentability
investigation-memo
Drafts the first cut of the privileged investigation memo from the log,
investigation-open
Opens a new investigation matter — runs intake, generates the sources
investigation-query
Answers questions against the investigation log — what witnesses said,
investigation-summary
Drafts a stripped-down, audience-appropriate summary from the privileged
ip-clause-review
Reviews the IP clauses in an agreement against the practice profile in ~/.claude/plugins/config/claude-for-legal/ip-legal/CLAUDE.md. Flags assignment gaps, ownership ambiguity…
leave-tracker
Checks all open leaves with hard legal deadlines and surfaces only the ones
matter-briefing
Deep briefing on one matter — current posture, what's changed, next deadline, open questions, and a risk re-assessment check, ready before a GC update or outside counsel call.…
matter-close
Close a matter — capture outcome, final exposure, and lessons, then archive it out of the active portfolio without deleting the record. Use when the user wants to close a matter…
matter-intake
Intake a new matter — uniform questions covering identification, conflicts, source, risk triage, materiality, outside counsel, owners, legal hold, and key dates; writes matter.md…
matter-update
Append a dated event to a matter's history file and refresh the log row — captures new developments, status changes, risk re-assessments, deadline shifts, and settlement…
nda-review
Matter context. Check Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use…
oc-status
Generate weekly status-request email drafts to outside counsel across the active portfolio — markdown per matter, plus Gmail drafts when the MCP is available. Use when the user…
oss-review
Runs an open source license compliance check against the practice profile in ~/.claude/plugins/config/claude-for-legal/ip-legal/CLAUDE.md. Classifies dependencies by license…
policy-drafting
1. Load ~/.claude/plugins/config/claude-for-legal/employment-legal/CLAUDE.md → jurisdictional footprint, handbook location.
policy-starter
1. Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If the practice profile is unpopulated, stop and direct to…
portfolio
Surfaces what's renewing, adds assets, records filings, and audits the register.
portfolio-status
Roll up the portfolio from _log.yaml — risk distribution, upcoming deadlines, stale matters, materiality totals, stage distribution, and flagged anomalies. Use when the user asks…
privilege-log-review
First-pass privilege log review — make the obvious privilege calls and flag the hard ones for attorney review without making close calls. Use when the user says "review the…
reg-gap-analysis
1. Load ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → privacy policy commitments, regulatory footprint, DSAR systems.
related-skills-surfacer
1. Load ~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md → practice profile.
review-proposals
Steps through pending playbook update proposals from the monitor agent and applies approved changes to ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md.
saas-msa-review
Matter context. Check Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use…
stakeholder-summary
Matter context. Check Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use…
subpoena-triage
Triage a subpoena served on the company — classify it, analyze scope/burden/privilege, cross-check the portfolio, and produce an objections framework, compliance plan, and…
takedown
Three modes. Pick one:
use-case-triage
1. Read ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md. Confirm privacy practice is configured — if not, stop and direct to setup.
vendor-agreement-review
Matter context. Check Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use…
vendor-ai-review
1. Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. Confirm vendor governance positions are populated — if not, stop and direct to setup.
wage-hour-qa
1. Load ~/.claude/plugins/config/claude-for-legal/employment-legal/CLAUDE.md → jurisdictional footprint.
worker-classification
Runs the applicable classification tests for the jurisdiction and flags where
ads-setup
Set up a paid-media client, brand, account, data-source, privacy, and mutation-guardrail profile for Claude Ads. Use for onboarding, initial configuration, brand DNA, API tokens…
meta-compliance-audit-bundle
Auditable compliance bundle: deep-research with citations → signable .docx report → read-only PDF archive → memory note of audit findings.
ai-cold-outreach
When the user wants to build an AI-powered outreach system, write cold emails, improve deliverability, or scale personalized outreach. Also use when the user mentions 'cold…
gtm-engineering
When the user wants to build GTM automation with code, design workflow architectures, use AI agents for GTM tasks, or implement the 'architecture over tools' principle. Also use…
tos-clause-scanner
Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues.…
explain-equity-terms
Activate for ANY equity, legal, or term sheet question related to startup investing or fundraising. Triggers include: "what is a SAFE", "explain this term sheet", "what does…
cap-table-waterfall
Model cap table dilution, SAFE conversion, and exit waterfall across scenarios. Triggered by: "/venture-capital-intelligence:cap-table-waterfall", "model my cap table", "simulate…
closing-costs
Calculates itemized state-specific closing costs for mortgage refinance transactions across 10 licensed states, with product-specific fees for Conventional, FHA, FHA Streamline…
mortgage-compliance
Enforces mortgage regulatory compliance — TRID, RESPA, TILA, ECOA/Fair Lending, state licensing, required disclosures, and data privacy rules for all borrower interactions.
bb-methodology
Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear…
regulatory-analysis
Analyzes documents and processes against FINRA, SEC, Federal Reserve, and CFPB regulatory frameworks. Identifies compliance gaps, classifies findings by severity, and recommends…
courtlistener-api
Legal case law database with PACER data and judge profiles
data-collection
Use when collecting data for a research project, downloading time series, building a dataset, accessing economic or social data APIs, or scraping data from a non-API source.…
Foreign-CF-Study
根据研究者提供的**研究计划书(Research Proposal)**执行基于**外国(美国/欧盟/英国/日本/跨国)制度环境**的公司金融类实证研究全流程。**启动后第一件事:根据计划书的主题、识别策略、贡献边际与样本范围,从外国 CF 顶刊池(AER/QJE/JPE/JF/JFE/RFS/JFQA/JAR/JAE/MS/JCF/JBF 等 25+…
google-scholar-scraper
Ethical Google Scholar data collection techniques and best practices
law-skills
9 legal research skills. Trigger: legal research, case law analysis, regulatory compliance. Design: legal databases, citation networks, and judicial analytics tools.
legal-agent-skills-guide
Agent skills collection for legal research and automation
legal-nlp-guide
NLP techniques for legal text analysis, case law mining, and contracts
regulatory-compliance-guide
Regulatory text mining, compliance research, and policy analysis tools
responsible-ai-guide
Resources for trustworthy, fair, and ethical AI research
uk-legislation-api
Access UK laws and statutory instruments via the Legislation.gov.uk API
web-scraping-ethics-guide
Scrape web data ethically and legally for research purposes
multi-search-engine
Multi search engine integration with 17 engines (8 CN + 9 Global). Supports advanced search operators, time filters, site search, privacy engines, and WolframAlpha knowledge…
uspto-database
Access USPTO APIs for patent/trademark searches, examination history (PEDS), assignments, citations, office actions, TSDR, for IP analysis and prior art searches.
golang-observability
Golang everyday observability — the always-on signals in production. Covers structured logging with slog, Prometheus metrics, OpenTelemetry distributed tracing, continuous…
cloud-security-posture
'Manage cloud security posture operations. Auto-activating skill for
gdpr-compliance-scanner
'Scan gdpr compliance scanner operations. Auto-activating skill for Security
iam-policy-reviewer
'Execute iam policy reviewer operations. Auto-activating skill for Security
iso27001-gap-analyzer
'Analyze iso27001 gap analyzer operations. Auto-activating skill for
key-rotation-manager
'Manage key rotation manager operations. Auto-activating skill for Security
log-analysis-security
'Execute log analysis security operations. Auto-activating skill for
network-security-scanner
'Scan network security scanner operations. Auto-activating skill for
pci-dss-validator
'Validate pci dss validator operations. Auto-activating skill for Security
penetration-test-planner
'Plan penetration test planner operations. Auto-activating skill for
siem-rule-generator
'Generate siem rule generator operations. Auto-activating skill for Security
soc2-compliance-checker
'Validate soc2 compliance checker operations. Auto-activating skill for
threat-model-creator
'Create threat model creator operations. Auto-activating skill for Security
waf-rule-creator
'Create waf rule creator operations. Auto-activating skill for Security
windsurf-code-privacy
'Configure code privacy and data retention policies. Activate when users
zero-trust-config-helper
'Configure with zero trust config helper operations. Auto-activating