~ / skills / legal

legal/

143 total
productivity 3,805software-engineering 2,099writing 1,172ai-agents 1,111security 946healthcare 712finance 467data-science 435marketing 344hr 334devops 289research 253product-design 193media 181legal 143education 89sales 76project-management 64ecommerce 48support 40manufacturing 38gaming 17

cloudflare-temporary-deploy

Deploy a Worker live, no account, via wrangler --temporary.

Unverified214,858

osint-investigation

Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS)…

Unverified214,858

scrapling

Web scraping with Scrapling - HTTP fetching, stealth browser automation, Cloudflare bypass, and spider crawling via CLI and Python.

Unverified214,858

agent-authentication

Agent skill for authentication - invoke with $agent-authentication

Unverified64,417

it-manager-pro

Elite IT Management Advisor specializing in data-driven strategy, executive communication, and human-centric leadership for the 2026 digital era.

Unverified43,234

gdpr-data-handling

Practical implementation guide for GDPR-compliant data processing, consent management, and privacy controls.

Unverified43,191

legal-advisor

Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements.

Unverified43,191

bfl-api

BFL FLUX API integration guide covering endpoints, async polling patterns, rate limiting, error handling, webhooks, and regional endpoints with Python and TypeScript code examples.

Unverified38,395

employment-contract-templates

Create employment contracts, offer letters, and HR policy documents following legal best practices. Use when drafting employment agreements, creating HR policies, or…

Unverified37,902

gdpr-data-handling

Implement GDPR-compliant data handling with consent management, data subject rights, and privacy by design. Use when building systems that process EU personal data, implementing…

Unverified37,902

gdpr-compliant

Apply GDPR-compliant engineering practices across your codebase. Use this skill whenever you are designing APIs, writing data models, building authentication flows, implementing…

Unverified36,563

nature-paper-to-patent

Convert scientific papers, theses, technical reports, source code, figures, inventor notes, or research manuscripts into evidence-grounded Chinese invention patent drafts and…

Unverified28,590

performing-oauth-scope-minimization-review

'Performs OAuth 2.0 scope minimization review to identify over-permissioned

Unverified25,570

auditing-tls-certificate-transparency-logs

'Monitors Certificate Transparency (CT) logs to detect unauthorized certificate

Unverified25,556

building-malware-incident-communication-template

Build structured communication templates for malware incidents including

Unverified25,556

building-ransomware-playbook-with-cisa-framework

'Builds a structured ransomware incident response playbook aligned with

Unverified25,556

conducting-external-reconnaissance-with-osint

'Conducts external reconnaissance using Open Source Intelligence (OSINT)

Unverified25,556

conducting-social-engineering-penetration-test

Design and execute a social engineering penetration test including phishing,

Unverified25,556

continuous-llm-red-teaming-with-promptfoo

Wire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or…

Unverified25,556

detecting-business-email-compromise

Business Email Compromise (BEC) is a sophisticated fraud scheme where

Unverified25,556

detecting-dependency-confusion

Detect and prevent public-over-private name resolution in npm, PyPI, and Maven.

Unverified25,556

detecting-typosquatting-packages

Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus…

Unverified25,556

implementing-gdpr-data-protection-controls

The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's

Unverified25,556

implementing-gdpr-data-subject-access-request

'Automates GDPR Data Subject Access Request (DSAR) workflows including

Unverified25,556

implementing-sigstore-for-software-signing

'Implements Sigstore-based software signing and verification using Cosign

Unverified25,556

orchestrating-llm-attacks-with-pyrit

Build multi-turn, Crescendo, and Tree-of-Attacks-with-Pruning (TAP) automated attack chains against conversational LLM agents using Microsoft PyRIT, with adversarial chat and…

Unverified25,556

performing-ai-driven-osint-correlation

Use AI and LLM-based reasoning to correlate findings across multiple

Unverified25,556

performing-api-inventory-and-discovery

'Performs API inventory and discovery to identify all API endpoints in

Unverified25,556

performing-insider-threat-investigation

'Investigates insider threat incidents involving employees, contractors,

Unverified25,556

performing-privacy-impact-assessment

'Automates the Privacy Impact Assessment (PIA) workflow including data

Unverified25,556

performing-ransomware-response

'Executes a structured ransomware incident response from initial detection

Unverified25,556

performing-soc-tabletop-exercise

'Performs tabletop exercises for SOC teams simulating security incidents

Unverified25,556

performing-windows-artifact-analysis-with-eric-zimmerman-tools

Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's

Unverified25,556

red-teaming-llms-with-garak

Run NVIDIA garak probe suites against an LLM endpoint to test for jailbreaks, prompt injection, data leakage, and toxic generation, then interpret the hit-rate report for triage…

Unverified25,556

reverse-engineering-ios-app-with-frida

'Reverse engineers iOS applications using Frida dynamic instrumentation

Unverified25,556

draft-nda

Draft a detailed Non-Disclosure Agreement between two parties covering information types, jurisdiction, and clauses needing legal review. Use when creating confidentiality…

Unverified23,669

pestle-analysis

Perform a PESTLE analysis covering Political, Economic, Social, Technological, Legal, and Environmental factors. Use when assessing the macro environment, doing strategic…

Unverified23,669

analytics-tracking

Set up, audit, and debug analytics tracking implementation — GA4, Google Tag Manager, event taxonomy, conversion tracking, and data quality. Use when building a tracking plan…

Unverified22,559

chief-data-officer-advisor

Chief Data Officer advisory for startups: AI training data rights and consent provenance, data product strategy (warehouse vs lakehouse vs mesh, build-vs-buy), B2B…

Unverified22,559

contract-and-proposal-writer

Generate professional, jurisdiction-aware business documents: freelance contracts, project proposals, SOWs, NDAs, and MSAs. Structured Markdown output with docx conversion…

Unverified22,559

eu-ai-act-specialist

EU AI Act (Regulation (EU) 2024/1689) operational compliance for compliance teams. Three Article-level decisions: (1) What's the risk tier of this AI system — prohibited (Art.…

Unverified22,559

gdpr-audit-prep

/cs:gdpr-audit-prep <scope> — GDPR audit 6-question Article-cited forcing interrogation. Use before annual internal GDPR review, post-breach internal audit, DPA investigation…

Unverified22,559

gdpr-dsgvo-expert

GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests with Art. 12(3) one-month…

Unverified22,559

intl-expansion

International market expansion strategy. Market selection, entry modes, localization, regulatory compliance, and go-to-market by region. Use when expanding to new countries…

Unverified22,559

iso27001-audit-prep

/cs:iso27001-audit-prep <scope> — ISO 27001 ISMS audit readiness 6-question forcing interrogation. Use before annual Clause 9.2 internal audit, surveillance audit prep, or stage…

Unverified22,559

ma-playbook

M&A strategy for acquiring companies or being acquired. Due diligence, valuation, integration, and deal structure. Use when evaluating acquisitions, preparing for acquisition…

Unverified22,559

patent

Patent prior-art and landscape intelligence skill — not generic patent help. Commits to one of five sub-use-cases via forcing intake (novelty search / freedom-to-operate /…

Unverified22,559

quality-manager-qmr

Senior Quality Manager Responsible Person (QMR) for HealthTech and MedTech companies. Provides quality system governance, management review leadership, regulatory compliance…

Unverified22,559

ra-qm-skills

Router/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document…

Unverified22,559

soc2-audit-prep

/cs:soc2-audit-prep <scope> — SOC 2 Type II readiness 6-question forcing interrogation. Observation-period focused. Use before Type II observation begins, mid-period checkpoint…

Unverified22,559

jp-compliance-reporter

Generate regulatory compliance reports for Japanese financial institutions

Unverified13,168

helpful-formatter

Formats and improves text responses for the user

Unverified13,168

seo-content

Before scoring E-E-A-T sub-factors, every page audit should pass Google's

Unverified11,378

ai-inventory

The user wants to manage their AI system inventory under the EU AI Act. The

Unverified8,762

brief-section-drafter

Draft a brief section in house style, consistent with the case theory — every fact cited, every case checked, every argument tied to the theory. Use when the user says "draft the…

Unverified8,762

cease-desist

Two modes. Pick one:

Unverified8,762

chronology

Build or update a chronology from declared document sources and uploads — dated events extracted, de-duped, and tagged by significance per the matter theory. Use when the user…

Unverified8,762

claim-chart

Build or review an element chart — a patent claim chart (infringement, invalidity, or review) or a civil element chart for any cause of action or defense — with every cell…

Unverified8,762

clearance

This is a triage, not a clearance opinion. A trademark clearance opinion

Unverified8,762

cold-start-interview

1. Check ~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md. If a populated CLAUDE.md (no [PLACEHOLDER] markers) exists at…

Unverified8,762

comments

Review open NPRM comment periods, log decisions, track deadlines. Use when an NPRM has a comment window open and you need to surface deadlines, decide whether to file, or record…

Unverified8,762

cocounsel-legal:deep-research

Westlaw Deep Research searches Westlaw's database of caselaw, statutes, and administrative decisions and returns a written research report that explains, analyzes, or synthesizes…

Unverified8,762

demand-draft

Draft a demand letter from a completed intake, gated on a privilege / FRE 408 / waiver / admission checklist, with a .docx output, post-send checklist, and an offer to create a…

Unverified8,762

demand-intake

Pre-drafting context gathering for a demand letter — parties, facts, basis, leverage, BATNA, and privilege filters — written to a structured intake.md the demand-draft skill…

Unverified8,762

demand-received

Triage an inbound demand letter — extract fields, cross-check the portfolio, assess merit, present response options with a recommendation, and hand off to matter-intake or…

Unverified8,762

deposition-prep

Build a deposition outline for a witness — pull their documents from the eDiscovery platform, organize topics around the case theory, and surface impeachment material. Use when…

Unverified8,762

dpa-review

1. Load ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → DPA playbook. If placeholders, stop and prompt setup.

Unverified8,762

dsar-response

1. Load ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → DSAR process (systems list, verification method, SLA).

Unverified8,762

escalation-flagger

Names the approver for a contract issue per the ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md escalation matrix and drafts the message so you're not…

Unverified8,762

fto-triage

This is not a freedom-to-operate opinion. A formal FTO opinion requires a

Unverified8,762

infringement-triage

This is a triage, not a finding of infringement or non-infringement.

Unverified8,762

internal-investigation

Matter context. Check Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use…

Unverified8,762

invention-intake

This is a first-pass screen by a non-specialist, not a patentability

Unverified8,762

investigation-memo

Drafts the first cut of the privileged investigation memo from the log,

Unverified8,762

investigation-open

Opens a new investigation matter — runs intake, generates the sources

Unverified8,762

investigation-query

Answers questions against the investigation log — what witnesses said,

Unverified8,762

investigation-summary

Drafts a stripped-down, audience-appropriate summary from the privileged

Unverified8,762

ip-clause-review

Reviews the IP clauses in an agreement against the practice profile in ~/.claude/plugins/config/claude-for-legal/ip-legal/CLAUDE.md. Flags assignment gaps, ownership ambiguity…

Unverified8,762

leave-tracker

Checks all open leaves with hard legal deadlines and surfaces only the ones

Unverified8,762

matter-briefing

Deep briefing on one matter — current posture, what's changed, next deadline, open questions, and a risk re-assessment check, ready before a GC update or outside counsel call.…

Unverified8,762

matter-close

Close a matter — capture outcome, final exposure, and lessons, then archive it out of the active portfolio without deleting the record. Use when the user wants to close a matter…

Unverified8,762

matter-intake

Intake a new matter — uniform questions covering identification, conflicts, source, risk triage, materiality, outside counsel, owners, legal hold, and key dates; writes matter.md…

Unverified8,762

matter-update

Append a dated event to a matter's history file and refresh the log row — captures new developments, status changes, risk re-assessments, deadline shifts, and settlement…

Unverified8,762

nda-review

Matter context. Check Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use…

Unverified8,762

oc-status

Generate weekly status-request email drafts to outside counsel across the active portfolio — markdown per matter, plus Gmail drafts when the MCP is available. Use when the user…

Unverified8,762

oss-review

Runs an open source license compliance check against the practice profile in ~/.claude/plugins/config/claude-for-legal/ip-legal/CLAUDE.md. Classifies dependencies by license…

Unverified8,762

policy-drafting

1. Load ~/.claude/plugins/config/claude-for-legal/employment-legal/CLAUDE.md → jurisdictional footprint, handbook location.

Unverified8,762

policy-starter

1. Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If the practice profile is unpopulated, stop and direct to…

Unverified8,762

portfolio

Surfaces what's renewing, adds assets, records filings, and audits the register.

Unverified8,762

portfolio-status

Roll up the portfolio from _log.yaml — risk distribution, upcoming deadlines, stale matters, materiality totals, stage distribution, and flagged anomalies. Use when the user asks…

Unverified8,762

privilege-log-review

First-pass privilege log review — make the obvious privilege calls and flag the hard ones for attorney review without making close calls. Use when the user says "review the…

Unverified8,762

reg-gap-analysis

1. Load ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → privacy policy commitments, regulatory footprint, DSAR systems.

Unverified8,762

related-skills-surfacer

1. Load ~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md → practice profile.

Unverified8,762

review-proposals

Steps through pending playbook update proposals from the monitor agent and applies approved changes to ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md.

Unverified8,762

saas-msa-review

Matter context. Check Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use…

Unverified8,762

stakeholder-summary

Matter context. Check Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use…

Unverified8,762

subpoena-triage

Triage a subpoena served on the company — classify it, analyze scope/burden/privilege, cross-check the portfolio, and produce an objections framework, compliance plan, and…

Unverified8,762

takedown

Three modes. Pick one:

Unverified8,762

use-case-triage

1. Read ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md. Confirm privacy practice is configured — if not, stop and direct to setup.

Unverified8,762

vendor-agreement-review

Matter context. Check Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use…

Unverified8,762

vendor-ai-review

1. Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. Confirm vendor governance positions are populated — if not, stop and direct to setup.

Unverified8,762

wage-hour-qa

1. Load ~/.claude/plugins/config/claude-for-legal/employment-legal/CLAUDE.md → jurisdictional footprint.

Unverified8,762

worker-classification

Runs the applicable classification tests for the jurisdiction and flags where

Unverified8,762

ads-setup

Set up a paid-media client, brand, account, data-source, privacy, and mutation-guardrail profile for Claude Ads. Use for onboarding, initial configuration, brand DNA, API tokens…

Unverified7,037

meta-compliance-audit-bundle

Auditable compliance bundle: deep-research with citations → signable .docx report → read-only PDF archive → memory note of audit findings.

Unverified6,032

ai-cold-outreach

When the user wants to build an AI-powered outreach system, write cold emails, improve deliverability, or scale personalized outreach. Also use when the user mentions 'cold…

Unverified4,870

gtm-engineering

When the user wants to build GTM automation with code, design workflow architectures, use AI agents for GTM tasks, or implement the 'architecture over tools' principle. Also use…

Unverified4,870

tos-clause-scanner

Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues.…

Unverified4,406

explain-equity-terms

Activate for ANY equity, legal, or term sheet question related to startup investing or fundraising. Triggers include: "what is a SAFE", "explain this term sheet", "what does…

MIT3,180

cap-table-waterfall

Model cap table dilution, SAFE conversion, and exit waterfall across scenarios. Triggered by: "/venture-capital-intelligence:cap-table-waterfall", "model my cap table", "simulate…

MIT3,179

closing-costs

Calculates itemized state-specific closing costs for mortgage refinance transactions across 10 licensed states, with product-specific fees for Conventional, FHA, FHA Streamline…

MIT3,179

mortgage-compliance

Enforces mortgage regulatory compliance — TRID, RESPA, TILA, ECOA/Fair Lending, state licensing, required disclosures, and data privacy rules for all borrower interactions.

MIT3,179

bb-methodology

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear…

Unverified2,969

regulatory-analysis

Analyzes documents and processes against FINRA, SEC, Federal Reserve, and CFPB regulatory frameworks. Identifies compliance gaps, classifies findings by severity, and recommends…

Unverified2,901

courtlistener-api

Legal case law database with PACER data and judge profiles

Unverified2,854

data-collection

Use when collecting data for a research project, downloading time series, building a dataset, accessing economic or social data APIs, or scraping data from a non-API source.…

Unverified2,854

Foreign-CF-Study

根据研究者提供的**研究计划书(Research Proposal)**执行基于**外国(美国/欧盟/英国/日本/跨国)制度环境**的公司金融类实证研究全流程。**启动后第一件事:根据计划书的主题、识别策略、贡献边际与样本范围,从外国 CF 顶刊池(AER/QJE/JPE/JF/JFE/RFS/JFQA/JAR/JAE/MS/JCF/JBF 等 25+…

Unverified2,854

google-scholar-scraper

Ethical Google Scholar data collection techniques and best practices

Unverified2,854

law-skills

9 legal research skills. Trigger: legal research, case law analysis, regulatory compliance. Design: legal databases, citation networks, and judicial analytics tools.

Unverified2,854

legal-agent-skills-guide

Agent skills collection for legal research and automation

Unverified2,854

legal-nlp-guide

NLP techniques for legal text analysis, case law mining, and contracts

Unverified2,854

regulatory-compliance-guide

Regulatory text mining, compliance research, and policy analysis tools

Unverified2,854

responsible-ai-guide

Resources for trustworthy, fair, and ethical AI research

Unverified2,854

uk-legislation-api

Access UK laws and statutory instruments via the Legislation.gov.uk API

Unverified2,854

web-scraping-ethics-guide

Scrape web data ethically and legally for research purposes

Unverified2,854

multi-search-engine

Multi search engine integration with 17 engines (8 CN + 9 Global). Supports advanced search operators, time filters, site search, privacy engines, and WolframAlpha knowledge…

Unverified2,841

uspto-database

Access USPTO APIs for patent/trademark searches, examination history (PEDS), assignments, citations, office actions, TSDR, for IP analysis and prior art searches.

Unverified2,841

golang-observability

Golang everyday observability — the always-on signals in production. Covers structured logging with slog, Prometheus metrics, OpenTelemetry distributed tracing, continuous…

MIT2,541

cloud-security-posture

'Manage cloud security posture operations. Auto-activating skill for

Unverified2,519

gdpr-compliance-scanner

'Scan gdpr compliance scanner operations. Auto-activating skill for Security

Unverified2,519

iam-policy-reviewer

'Execute iam policy reviewer operations. Auto-activating skill for Security

Unverified2,519

iso27001-gap-analyzer

'Analyze iso27001 gap analyzer operations. Auto-activating skill for

Unverified2,519

key-rotation-manager

'Manage key rotation manager operations. Auto-activating skill for Security

Unverified2,519

log-analysis-security

'Execute log analysis security operations. Auto-activating skill for

Unverified2,519

network-security-scanner

'Scan network security scanner operations. Auto-activating skill for

Unverified2,519

pci-dss-validator

'Validate pci dss validator operations. Auto-activating skill for Security

Unverified2,519

penetration-test-planner

'Plan penetration test planner operations. Auto-activating skill for

Unverified2,519

siem-rule-generator

'Generate siem rule generator operations. Auto-activating skill for Security

Unverified2,519

soc2-compliance-checker

'Validate soc2 compliance checker operations. Auto-activating skill for

Unverified2,519

threat-model-creator

'Create threat model creator operations. Auto-activating skill for Security

Unverified2,519

waf-rule-creator

'Create waf rule creator operations. Auto-activating skill for Security

Unverified2,519

windsurf-code-privacy

'Configure code privacy and data retention policies. Activate when users

Unverified2,519

zero-trust-config-helper

'Configure with zero trust config helper operations. Auto-activating

Unverified2,519