Explore

51

Browse the full catalog of community-built skills, connectors, plugins, and worlds.

Compliance & Regulatory
33
9
Aug 7, 2026
Moonshot-AI /

regulatory-audit-generator

Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like \"run a compliance check,\" \"GDPR/PIPL compliance,\" \"pre-launch review,\" \"privacy impact assessment (PIA/DPIA),\" or asking if a feature is compliant.

Compliance & Regulatory
60
15
Aug 7, 2026
Moonshot-AI /

legal-risk-assessment

Assess and classify legal risks using a severity-by-likelihood framework with escalation criteria. Use when evaluating contract risk, assessing deal exposure, classifying issues by severity, or determining whether a matter needs senior counsel or outside legal review.

Compliance & Regulatory
52
16
Jul 29, 2026
S. Chandler /

statute-briefer

Briefs statutes and legislative Acts using the MAPS + RULES framework: a system-level map of the whole Act (citation and text status, purpose, structure, scope, definitions) plus operational rule-modules for each operative provision (elements, legal effect, exceptions, procedure, consequences, forum, interaction rules). Works from statutory text supplied by the user and never invents statutory language. Use when briefing a statute, analyzing legislative text, mapping statutory architecture, extracting the elements of a provision, or applying a statute to facts. Triggers on "brief this statute", "analyze this Act", "map the statute", "apply [statute] to [scenario]", "what are the elements of [provision]", "statutory analysis", and on references to codified sections such as 42 U.S.C. or the Texas Health and Safety Code. Two modes: (A) text-only briefing for structural analysis, and (B) scenario-driven briefing that applies provisions to specific facts with verbatim quotation and pinpoint cites.

Compliance & Regulatory
29
2
Jul 26, 2026
H. Naik /

soc2

Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Covers gap analysis, policy writing, control documentation, audit evidence preparation, and vendor risk reviews for organizations at any maturity level — from first-time startups to seasoned compliance teams.

Compliance & Regulatory
23
5
Jul 26, 2026
H. Naik /

itar

Expert ITAR compliance advisor for US defense contractors, exporters, and manufacturers. Use this skill for any question about 22 CFR Parts 120-130, the United States Munitions List (USML), DDTC registration, export license applications (DSP-5/73/94), Technical Assistance Agreements (TAA), Manufacturing License Agreements (MLA), brokering regulations (Part 129), deemed export rules for foreign nationals, technology control plans, voluntary disclosures, violation mitigation, jurisdiction determination (ITAR vs EAR), or US Munitions List category scoping.

Compliance & Regulatory
43
7
Jul 26, 2026
H. Naik /

iso27001

Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or ISO/IEC 27001, including any of the following: gap analysis, auditing, compliance assessments, control checklists, policy writing, document generation, Statement of Applicability (SoA), risk assessment, risk registers, risk treatment plans, Annex A controls, ISMS implementation, clause requirements, certification readiness, transitioning from 2013 to 2022, control implementation guidance, incident response policies, access control policies, supplier security, or any information security management system (ISMS) topic.

Compliance & Regulatory
22
5
Jul 26, 2026
H. Naik /

ear

Export Administration Regulations (EAR, 15 CFR Parts 730-774) compliance advisor — ECCN classification across all 10 CCL categories and 5 product groups (A-E), EAR99 determination, jurisdiction analysis (EAR vs ITAR order of review), license requirement analysis via Country Chart, all license exceptions (LVS, GBS, CIV, TMP, RPL, GOV, TSU, ENC, TSR, APP, BAG, AVS, ACE), end-user/end-use controls (Entity List, Denied Persons List, Unverified List, MEU List), deemed export rules, Foreign Direct Product Rule (FDPR), de minimis thresholds, 10 General Prohibitions, SNAP-R license applications, voluntary self-disclosure, civil/criminal penalties, Export Compliance Program (ECP) design, and EAR vs ITAR jurisdiction determination. Use for any dual-use export control, CCL classification, or BIS compliance question.

Compliance & Regulatory
17
6
Jul 26, 2026
H. Naik /

cmmc

Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021.

Compliance & Regulatory
24
4
Jul 23, 2026
O. Laftouh /

morocco-ecommerce-compliance-audit

Performs a legal compliance audit for a Moroccan e-commerce website, focused on personal data protection (Law 09-08) and consumer contract disclosures/obligations (Law 31-08). Use this skill when a user asks to audit, check, or assess the legal compliance of an e-commerce website operating in Morocco — presence and validity of Terms & Conditions, privacy policy, CNDP declaration, mandatory disclosures, right of withdrawal, consent banner. Out of scope: compliance for other countries, Meta/Google advertising compliance (covered by another skill), definitive legal advice (results are a starting point for professional review, not legal advice).

Compliance & Regulatory
43
10
Jul 22, 2026
A. AI /

regulatory-threat-model

Runs a server-enforced STRIDE threat model and LINDDUN privacy threat model over a system described in prose, screens named dependencies against live CVE/KEV/EPSS data, and builds a cited screen of which EU security obligations (GDPR, NIS2, CRA, AI Act) may apply and which need determination - every regulatory statement fetched from officially published text through the Ansvar Gateway connector at answer time, with scope, role, and application-date limits stated. Never answered from model memory; never a compliance verdict.

Compliance & Regulatory
52
5
Jul 19, 2026
A. AI /

incident-reporting-navigator

One security incident can trigger several EU reporting regimes at once. This skill screens NIS2, GDPR, DORA, and the Cyber Resilience Act for each involved legal entity, applies the served trigger tests, checks each duty was actually in force for the incident, resolves the receiving authority per regime and member state from served national law (e.g. Dutch and German transpositions), and produces a deadline table in which every duty, authority, and deadline is quoted and cited from official publisher text. Requires the free Ansvar Gateway MCP connector; never answers from model memory - a connector failure is never converted into "no duty exists".

Compliance & Regulatory
44
7
Jul 19, 2026
A. AI /

cra-vulnerability-obligations

Cited EU Cyber Resilience Act assessment for a product with digital elements: scope, product classification, role-specific vulnerability-handling duties, and Article 14 reporting - joined with live CVE / CISA-KEV / EPSS vulnerability intelligence, and a NIS2 / GDPR / DORA entity-level screen. Requires the free Ansvar Gateway MCP connector; every legal claim is fetched from official publisher text at answer time and cited, never answered from model memory.

Compliance & Regulatory
20
1
Jul 17, 2026
A. Nikkola /

kilpailuoikeus

Suomen ja EU:n kilpailuoikeus: kielletyt kilpailunrajoitukset ja määräävän aseman väärinkäyttö (kilpailulaki 948/2011, SEUT 101 ja 102 artikla), yrityskauppavalvonta sekä kilpailu-compliance ja KKV:n tarkastuksiin varautuminen.

Compliance & Regulatory
44
7
Jul 17, 2026
Anthropic /

regulatory-legal

Watches regulatory feeds, diffs new rules against your policy library, tracks comment deadlines and open gaps, and writes the digest your team reads Monday morning.

Compliance & Regulatory
30
5
Jul 17, 2026
Anthropic /

product-legal

Reviews product launches against your risk calibration, answers 'is this a problem?' questions in minutes, checks marketing copy for claims that need substantiation, and flags upcoming launches that need legal eyes before anyone asks.

Compliance & Regulatory
71
14
Jul 16, 2026
Anthropic /

ai-governance-legal

Triages proposed AI use cases against your registry, runs impact assessments across the regimes in scope, reviews vendor AI terms for training-on-data and liability gaps, and keeps your AI policy current with practice.

Compliance & Regulatory
229
17
Jul 13, 2026
G. Skuza /

monitor-prawa-ue-i-polskiego

Wyszukiwanie, pobieranie i analiza aktów prawnych UE oraz polskich aktów i projektów wdrażających regulacje UE (np. PPWR, CBAM, EUDR, ESPR, CSRD, CSDDD, GPSR, AI Act, baterie, ekoprojekt). Używaj, gdy użytkownik potrzebuje statusu prawnego, dat stosowania, przepisów przejściowych, relacji aktów, obowiązków compliance i raportu z podstawami prawnymi oraz źródłami urzędowymi.

Compliance & Regulatory
91
14
Jul 5, 2026
O. Schmidt-Prietz /

eu-ai-act-transparency-assessor

Assesses which of the Art. 50(1)-(5) transparency obligations of the EU AI Act apply to a given AI system's provider or deployer, grounded in the final Code of Practice on Transparency of AI-Generated Content (June 2026) and the Commission's draft Art. 50 Guidelines. Covers AI-chatbot disclosure, deepfake and synthetic-content marking/watermarking, emotion-recognition and biometric-categorisation notices, the machine-readable marking duty, the obviousness exceptions, and the implementation timeline. Outputs a formal mini-report plus a per-obligation compliance checklist with gap flags. For breadth-first tier triage use the EU AI Act System Classifier; for raw Art. 50 text and Q&A use the EU AI Act Knowledge Base; for the full role x tier matrix use the EU AI Act Obligations Mapper.

Compliance & Regulatory
130
29
Jun 30, 2026
S. Boghossian /

privacy-policy

A zero-hallucination privacy-policy generator that takes anyone — non-lawyer founder to lawyer — from a guided intake to a publishable, jurisdiction-aware privacy policy. Jurisdiction-first: it detects which laws apply from where your users are, then drafts only the required clauses — GDPR/EU + UK, US (CCPA/CPRA, ~20 state laws, COPPA, sector overlays), and global/MENA (LGPD, Quebec Law 25, India DPDP, China PIPL, UAE/DIFC, Saudi PDPL), plus app-store, cookies, and AI/EU AI Act disclosures. Its rule: state only what you confirm; never invent a statute, citation, fine, or date — every claim is source-cited and QA-gated. Not legal advice.

Compliance & Regulatory
188
24
Jun 11, 2026
L. Meredith-Flister /

ai-audit-trail

This skill builds a structured audit trail of an AI-assisted task: what the tool was asked to do, what materials it was given, what it produced, how the output was verified, and what was ultimately relied upon. It documents the workflow for supervision and later review without ruling on privilege or disclosure, so the record stays accurate rather than self-serving.

Compliance & Regulatory
39
9
Jul 8, 2026
A. Fadavi /

enforcement-action-analysis

Analyze any OFAC or OFSI enforcement action — by URL, pasted text, or uploaded document — and produce a structured root cause analysis as a formatted Excel (.xlsx) spreadsheet. Use this skill whenever a user names, links to, pastes, or uploads an OFAC or OFSI enforcement action and asks for any of the following: root cause analysis, compliance gaps, what went wrong, lessons learned, organizational self-assessment, or remediation planning. Also trigger when a user asks "analyze this enforcement action", "what were the root causes", "turn this into a checklist", or "how do I make sure this doesn't happen to us". Outputs a single-sheet .xlsx table with six columns: Root Cause | What Went Wrong | How It Went Wrong | What Could Have Stopped It | Is my organization immune to this? (Yes/No/Partial) | Notes.

Compliance & Regulatory
96
30
Jun 9, 2026
O. Schmidt-Prietz /

eu-ai-act-knowledge-base

Authoritative regulatory Q&A grounded in 70 official EU source documents, including the 2026 Commission draft guidelines on Art. 6 high-risk classification. Answers any EU AI Act question with article-level citations from the full regulation text, Commission guidelines, EDPB/EDPS opinions, codes of practice, harmonised standards, FRIA guides, and sector-specific guidance — covering penalties, timelines, GPAI obligations, high-risk and prohibited practices, and the AI Act / GDPR interplay.

Compliance & Regulatory
79
20
Jun 9, 2026
O. Schmidt-Prietz /

eu-ai-act-high-risk-classifier

Depth assessment of whether an AI system is high-risk under Art. 6 of the EU AI Act, grounded in the Commission's draft Art. 6(5) classification guidelines (general principles + Annex I + Annex III). Covers the Annex I product-safety route, all eight Annex III areas with worked examples, the Art. 6(3) exception and its profiling re-exception, and the Art. 25 quasi-provider trap. Outputs a structured decision block, a practitioner memo, and a JSON interchange artefact.

Compliance & Regulatory
134
28
May 22, 2026
G. Saleh /

sanctions-and-export-analysis

Real-time individual screening across 30+ official lists (UN, EU, OFAC, OFSI, French DGT...), sectoral analysis, dual-use goods (EU Reg. 2021/821), US/China extraterritorial regimes (EAR, ITAR, FDPR, ECL), USD/SWIFT risk and jurisdictional mapping across 30+ countries.