regulatory-threat-model
Runs a server-enforced STRIDE threat model and LINDDUN privacy threat model over a system described in prose, screens named dependencies against live CVE/KEV/EPSS data, and builds a cited screen of which EU security obligations (GDPR, NIS2, CRA, AI Act) may apply and which need determination - every regulatory statement fetched from officially published text through the Ansvar Gateway connector at answer time, with scope, role, and application-date limits stated. Never answered from model memory; never a compliance verdict.
incident-reporting-navigator
One security incident can trigger several EU reporting regimes at once. This skill screens NIS2, GDPR, DORA, and the Cyber Resilience Act for each involved legal entity, applies the served trigger tests, checks each duty was actually in force for the incident, resolves the receiving authority per regime and member state from served national law (e.g. Dutch and German transpositions), and produces a deadline table in which every duty, authority, and deadline is quoted and cited from official publisher text. Requires the free Ansvar Gateway MCP connector; never answers from model memory - a connector failure is never converted into "no duty exists".
cra-vulnerability-obligations
Cited EU Cyber Resilience Act assessment for a product with digital elements: scope, product classification, role-specific vulnerability-handling duties, and Article 14 reporting - joined with live CVE / CISA-KEV / EPSS vulnerability intelligence, and a NIS2 / GDPR / DORA entity-level screen. Requires the free Ansvar Gateway MCP connector; every legal claim is fetched from official publisher text at answer time and cited, never answered from model memory.
