← all publishers

ThomasMoreAI

@thomasmoreai source repo

3569 published skills · page 1 of 36

  1. Iso27701 · thomasmoreai
    Expert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 27701:2025, ISO/IEC 27701:2019, privacy information management, PIMS certification, PII controller or processor obligations, privacy risk assessment, Statement of Applicability for privacy, privacy by design, data subject rights, DPIA, records of processing activities, transitioning from ISO 27701:2019, GDPR alignment with ISO 27701, or any privacy management system topic. Also trigger for questions about Annex A.1 (controller controls), A.2 (processor controls), A.3 (shared security controls), or implementing a standalone PIMS without ISO 27001. When in doubt, use this skill — it covers the full ISO 27701 lifecycle from gap assessment through certification.
    0
    installs
  2. Office Lease · thomasmoreai
    Drafts commercial office lease agreements with rent schedules, expense allocations, maintenance splits, and protective provisions for landlord and tenant. Covers NNN, gross, and modified gross structures. Use when drafting office leases, commercial lease agreements, landlord-tenant contracts, or space rental agreements for commercial office premises.
    0
    installs
  3. Form D Notice · thomasmoreai
    Drafts U.S. SEC Form D notice data sets for Regulation D exempt offerings (Rule 504, 506(b), 506(c)), ready for EDGAR submission. Use when preparing a Form D filing, notice of exempt offering, Reg D compliance, or unregistered securities offering notice.
    0
    installs
  4. Kentucky Kppa · thomasmoreai
    Kentucky Consumer Privacy Protection Act (KPPA) compliance. Effective January 1, 2026. Covers consumer rights, controller thresholds at 100,000 consumers, sensitive data processing consent, cure period provisions, and AG enforcement framework.
    0
    installs
  5. Montana Mtdpa · thomasmoreai
    Montana Consumer Data Privacy Act (MTDPA) compliance. Lowest consumer threshold at 50,000 consumers. Covers sensitive data consent, universal opt-out recognition, consumer rights, controller obligations, 60-day cure period, and AG enforcement. Effective October 1, 2024.
    0
    installs
  6. Hipaa Privacy Rule · thomasmoreai
    Implements HIPAA Privacy Rule requirements under 45 CFR §164.500-534 for covered entities and business associates. Covers minimum necessary standard, treatment-payment-operations exceptions, directory opt-out, personal representative rules, and authorization requirements. Keywords: HIPAA Privacy Rule, PHI, minimum necessary, TPO, authorization, covered entity.
    0
    installs
  7. Hitech Act Privacy · thomasmoreai
    Implements HITECH Act privacy and security requirements including breach notification expansion, four-tier penalty structure, state attorney general enforcement authority, EHR meaningful use privacy conditions, and business associate direct liability. Keywords: HITECH Act, breach notification, penalty tiers, state AG enforcement, meaningful use, EHR privacy.
    0
    installs
  8. Telehealth Privacy · thomasmoreai
    Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors, cross-state prescribing rules, and OCR enforcement discretion during public health emergencies. Keywords: telehealth privacy, virtual care, HIPAA, recording consent, platform BAA, cross-state licensing, OCR enforcement.
    0
    installs
  9. Epc Contract · thomasmoreai
    Drafts turnkey Engineering, Procurement, and Construction (EPC) contracts for industrial facility projects. Covers scope of work, commercial terms, performance guarantees, risk allocation, warranties, and dispute resolution. Use when drafting EPC agreements, turnkey construction contracts, or energy infrastructure project contracts (power plants, petrochemical facilities, water treatment plants).
    0
    installs
  10. New Jersey Dpa · thomasmoreai
    New Jersey Data Privacy Act (NJDPA) compliance, effective January 15, 2025. Covers consumer rights (access, correction, deletion, portability, opt-out), controller obligations, sensitive data requirements, universal opt-out mechanism recognition, 30-day cure period (sunsets after 18 months), and AG enforcement. Keywords: NJDPA, New Jersey, data privacy, consumer rights, sensitive data, universal opt-out, AG enforcement.
    0
    installs
  11. Hipaa Breach Notify · thomasmoreai
    Implements HIPAA breach notification requirements under 45 CFR §164.400-414. Covers individual notification within 60 days, HHS reporting thresholds (500+ immediate, under 500 annual), state attorney general notification, media notification for 500+ in a state, and breach risk assessment. Keywords: HIPAA breach notification, HHS reporting, OCR breach portal, individual notice, state attorney general.
    0
    installs
  12. Hipaa Security Rule · thomasmoreai
    Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. Covers access controls with unique user identification, emergency access procedures, automatic logoff, encryption, audit controls, integrity controls, and transmission security. Keywords: HIPAA Security Rule, ePHI, access controls, encryption, audit controls, technical safeguards.
    0
    installs
  13. Lpa Agreement · thomasmoreai
    Drafts institutional-quality Limited Partnership Agreements for PE/VC fund formation. Covers GP/LP terms, capital commitments, distribution waterfall, carried interest, LPAC governance, clawback, and tax provisions. Use when drafting LPA, fund formation agreement, limited partnership terms, or PE/VC fund documents.
    0
    installs
  14. Gdpr Compliance · thomasmoreai
    Generate UK/EU GDPR compliance documents — privacy policies, cookie policies, DPIAs, ROPA, DSAR responses, data breach notifications, and consent forms. Use when a business needs GDPR documentation, data protection policies, or privacy compliance.
    0
    installs
  15. Lex V2 · thomasmoreai
    LEX: Legal-Entity-X-ref workflow skill. Use this skill when the user needs Centralized 'Truth Engine' for cross-jurisdictional legal context (US, EU, CA) and contract scaffolding and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
    0
    installs
  16. Comply Simota · thomasmoreai
    Regulatory compliance and audit agent. Maps business regulatory requirements (SOC2/PCI-DSS/HIPAA/ISO 27001), checks control implementations, designs audit trails, and implements Policy as Code. Use when compliance auditing is needed.
    0
    installs
  17. Coppa Compliance · thomasmoreai
    Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312. Covers verifiable parental consent methods including signed forms, credit card verification, government ID, knowledge-based authentication, and video call. Includes FTC safe harbor programs and enforcement actions. Keywords: COPPA, FTC, children, parental consent, safe harbor, verifiable consent.
    0
    installs
  18. Vcdpa Compliance · thomasmoreai
    Virginia Consumer Data Protection Act (VCDPA) compliance implementation. Covers 5 consumer rights, controller obligations, processor requirements, opt-in for sensitive data, data protection impact assessments, AG enforcement, and cure period provisions. Effective January 1, 2023.
    0
    installs
  19. Dd Form 254 · thomasmoreai
    Drafts DD Form 254 Contract Security Classification Specifications for classified government contracts. Use when preparing security classification specs for prime contractors, subcontractors, SAP/SCI access, or facility clearance documentation per NISPOM (32 CFR Part 117) and DCSA regulations.
    0
    installs
  20. Rea Request · thomasmoreai
    Drafts a Request for Equitable Adjustment (REA) for U.S. federal government contracts under FAR provisions. Enforces element-driven cost/schedule narratives, FAR Part 31 cost structures, FAR 52.233-1 certification, and contemporaneous evidence marshaling. Use when a contractor seeks contract modification relief due to government-directed changes, differing site conditions, defective specifications, or government-caused delays.
    0
    installs
  21. Flp Agreement · thomasmoreai
    Drafts Family Limited Partnership agreements for estate planning and intergenerational wealth transfer. Ensures IRS enforceability under IRC §2036 with legitimate business purpose, valuation discounts, and senior-generation control. Use when drafting FLP agreements, family partnership documents, or estate planning partnership structures.
    0
    installs
  22. Universal Opt Out · thomasmoreai
    Universal opt-out mechanism implementation across US state privacy laws. Covers Global Privacy Control (GPC) signal technical implementation, state-by-state recognition requirements, browser detection methods, authenticated vs unauthenticated handling, and compliance testing.
    0
    installs
  23. Rfp Response · thomasmoreai
    Drafts evaluation-ready U.S. federal RFP responses across all standard proposal volumes (cover letter, technical, cost/price, reps and certs). Enforces FAR compliance, CPARS references, and Section L/M alignment. Use when preparing federal solicitation submissions, responding to government RFPs, or drafting procurement bids.
    0
    installs
  24. Dsar Intake System · thomasmoreai
    Builds a multi-channel DSAR intake system supporting web form, email, phone, and in-person requests with identity verification tiers, automated routing logic, SLA tracking, and response generation. Activate for DSAR intake, rights request portal, multi-channel intake, SLA tracking, request management queries.
    0
    installs
  25. Legal Advisor · thomasmoreai
    legal-advisor workflow skill. Use this skill when the user needs Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
    0
    installs
  26. Soc2 Privacy Audit · thomasmoreai
    Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent, collection, use/retention/disposal, access, disclosure, security, and quality. Includes evidence collection, control testing, and report review. Keywords: SOC 2, privacy criteria, TSP, AICPA, Type II, trust services.
    0
    installs
  27. Us Privacy Federal · thomasmoreai
    Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.
    0
    installs
  28. South Africa Popia · thomasmoreai
    Implements compliance with South Africa's Protection of Personal Information Act (POPIA), Act No. 4 of 2013. Covers conditions for lawful processing, data subject rights, cross-border transfer restrictions, Information Regulator enforcement, and responsible party obligations. Keywords: POPIA, South Africa, Information Regulator, responsible party, operator, prior authorisation.
    0
    installs
  29. Biometric Dpia · thomasmoreai
    Guides DPIA for biometric processing systems including facial recognition, fingerprint, voice, iris, and gait analysis. Covers Art. 9 special category requirements, Art. 35(3)(b) mandatory DPIA triggers for large-scale biometric processing, and EDPB Guidelines 3/2019 on video surveillance. Keywords: biometric, facial recognition, fingerprint, DPIA, Art. 9, special category, EDPB Guidelines 3/2019.
    0
    installs
  30. AI Transparency Reqs · thomasmoreai
    Implements AI transparency requirements under EU AI Act Arts. 13-14 and GDPR Arts. 13-14. Covers user notification of AI interaction, system capability disclosure, limitation documentation, and meaningful information about automated logic. Keywords: AI transparency, EU AI Act, GDPR notification, explainability, automated decision.
    0
    installs
  31. Dsar Processing · thomasmoreai
    Guides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day deadline calculation with extensions, response formatting, exemptions, and fee provisions. Activate when handling DSAR, access request, subject access, Art. 15, or SAR queries.
    0
    installs
  32. Right To Object · thomasmoreai
    Handles GDPR Article 21 right to object to processing, including compelling legitimate grounds assessment, ceasing processing obligations, documentation requirements, and the relationship with erasure under Article 17(1)(c). Activate for right to object, Art. 21, objection to processing, legitimate interest queries.
    0
    installs
  33. Data Portability · thomasmoreai
    Executes GDPR Article 20 data portability requests, covering machine-readable format requirements (JSON, CSV, XML), direct controller-to-controller transfer mechanisms, and scope limitations to data provided by the subject on consent or contract basis. Activate for portability, data export, Art. 20, data transfer queries.
    0
    installs
  34. Legal Advisor V2 · thomasmoreai
    legal-advisor workflow skill. Use this skill when the user needs Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
    0
    installs
  35. Nist Pf Identify · thomasmoreai
    Implement the NIST Privacy Framework IDENTIFY function including ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories. Provides control mapping, gap analysis templates, and implementation workflows for privacy risk identification.
    0
    installs
  36. Right To Erasure · thomasmoreai
    Implements the GDPR Article 17 right to erasure (right to be forgotten) workflow, covering all six grounds for erasure, five exceptions, technical deletion versus anonymization decisions, and third-party notification under Article 19. Activate for erasure request, deletion request, right to be forgotten, Art. 17 queries.
    0
    installs
  37. Bcr Establishment · thomasmoreai
    Guides development and approval of Binding Corporate Rules under GDPR Article 47 for intra-group international data transfers. Covers Art. 47(2)(a)-(n) content requirements, BCR approval process with lead supervisory authority, and WP256/WP257 referentials. Keywords: BCR, binding corporate rules, intra-group transfers, Art. 47.
    0
    installs
  38. Breach Simulation · thomasmoreai
    Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities. Covers scenario creation with realistic inject timelines, participant role assignment, communication testing across internal and external channels, decision-point evaluation, and after-action report generation. Keywords: tabletop exercise, breach simulation, incident response testing, scenario design, after-action report.
    0
    installs
  39. Dpia Risk Scoring · thomasmoreai
    Provides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134. Covers likelihood and severity assessment, risk matrix construction, inherent vs residual risk calculation, and risk appetite thresholds per EDPB WP248rev.01 guidance. Keywords: risk scoring, DPIA risk matrix, likelihood, severity, ENISA, ISO 29134, residual risk, risk appetite.
    0
    installs
  40. Fetching Arbitration Rules 2 · thomasmoreai
    Use when retrieving arbitration institutional rules (ICC, LCIA, SCC, SIAC, HKIAC, VIAC, МКАС/МАК при ТПП України, UNCITRAL) — fetching current version, verifying redaction applicable to the date of arbitration agreement, constructing URLs for official rule texts
    0
    installs
  41. Consent Withdrawal · thomasmoreai
    Implementation guide for GDPR Article 7(3) consent withdrawal mechanisms. Covers the equal ease requirement ensuring withdrawal is as easy as giving consent, one-click withdrawal implementation, cascading effects on downstream processing, third-party notification workflows, and technical architecture for real-time consent revocation.
    0
    installs
  42. Gdpr Certification · thomasmoreai
    Guides implementation of GDPR Article 42-43 data protection certification mechanisms including accredited certification bodies, criteria development, and periodic review. Activate when pursuing privacy certifications, evaluating certification bodies, or developing certification criteria. Keywords: certification, Article 42, Article 43, accreditation, seal, privacy mark.
    0
    installs
  43. Personal Data Test · thomasmoreai
    Classifies personal vs non-personal data per GDPR Art. 4(1) definition test with decision tree for borderline cases. References Breyer v Germany CJEU C-582/14 dynamic IP ruling and WP29 Opinion 4/2007. Keywords: personal data, GDPR Art 4, data classification, Breyer ruling, identifiability test, PII.
    0
    installs
  44. Pia Review Cadence · thomasmoreai
    Guides the periodic DPIA review lifecycle including trigger identification for regulatory changes, new data categories, technology changes, and breach incidents. Covers version control, stakeholder sign-off procedures, and DPIA register management per Art. 35(11). Keywords: DPIA review, PIA update, review cadence, version control, Art. 35(11), periodic review, trigger events, stakeholder sign-off.
    0
    installs
  45. Dpa Inspection Prep · thomasmoreai
    Guides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for key personnel, technical demonstration procedures, on-site logistics, response protocols, and post-inspection follow-up. Covers unannounced inspections, formal audits, and complaint-triggered investigations. Keywords: DPA inspection, supervisory authority, investigation, readiness, interview preparation, response protocol.
    0
    installs
  46. Pseudo Vs Anon Data · thomasmoreai
    Classifies data as pseudonymised or anonymised using Recital 26 reasonably likely test, Breyer ruling C-582/14, motivated intruder test, and WP29 Opinion 05/2014 on anonymisation techniques. Covers singling out, linkability, and inference tests. Keywords: pseudonymisation, anonymisation, Recital 26, re-identification, k-anonymity, differential privacy, WP29 Opinion 05/2014.
    0
    installs
  47. Applying New York Convention 2 · thomasmoreai
    Use when preparing applications for recognition and enforcement of foreign arbitral awards in Ukraine, applications for setting aside arbitral awards, or opposing such applications — mapping Article V of the 1958 New York Convention to Article 478 of the Ukrainian CPC, identifying grounds for refusal, structuring public policy arguments
    0
    installs
  48. Lex Ignvvcio254 · thomasmoreai
    Centralized 'Truth Engine' for cross-jurisdictional legal context (US, EU, CA) and contract scaffolding.
    0
    installs
  49. Dsar Form · thomasmoreai
    Drafts a GDPR- and CCPA-compliant Data Subject Access Request (DSAR) intake form for collecting requester information and processing privacy rights. Use when drafting DSAR forms, privacy rights request templates, or data subject rights workflows for EU/US-regulated organizations.
    0
    installs
  50. Breach Documentation · thomasmoreai
    Maintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was required. Covers mandatory register fields including facts, effects, and remedial actions, retention periods, audit readiness, and integration with the accountability framework. Keywords: breach register, Article 33(5), breach documentation, accountability, audit readiness, remedial actions.
    0
    installs
  51. Breach Subject Comms · thomasmoreai
    Manages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in a high risk to their rights and freedoms. Covers the high risk threshold, required notification content per Art. 34(2), exemptions under Art. 34(3), and breach notification letter templates for five scenarios. Keywords: data subject notification, Article 34, high risk, breach communication, GDPR.
    0
    installs
  52. Reviewing B2b Service Contract 2 · thomasmoreai
    Use when auditing Polish B2B service contract (umowa o świadczenie usług / umowa współpracy / kontrakt B2B / staff augmentation / IT outsourcing) — zakaz konkurencji B2B (art. 353¹ KC, SN II CSK 58/18), klauzule wyłączności vs pozorny stosunek pracy (art. 22 § 1¹ KP), kary umowne (art. 483-484 KC, miarkowanie), IP (prawa autorskie do kodu / dzieła), JDG-specyficzne (Prawo Przedsiębiorców art. 6, CEIDG), obowiązek pierwszeństwa, rejestry (CEIDG, KRS, biała lista VAT)
    0
    installs
  53. Lex Diegosouzapw · thomasmoreai
    LEX: Legal-Entity-X-ref workflow skill. Use this skill when the user needs Centralized 'Truth Engine' for cross-jurisdictional legal context (US, EU, CA) and contract scaffolding and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
    0
    installs
  54. Legal Review Projectious Work · thomasmoreai
    Structures a systematic legal and compliance review of contracts, policies, or technical decisions — identifying key clauses, risks, and questions for counsel. Use when asked to review a contract, check compliance implications, flag legal risks in a technical design, or prepare for a legal consultation. Always surfaces work for qualified counsel; never replaces legal advice.
    0
    installs
  55. Specialized Legal Client Intake · thomasmoreai
    Comprehensive legal client intake specialist for qualifying prospects, collecting case information, scheduling consultations, managing conflict checks, and delivering attorney-ready intake summaries across any practice area and firm size
    0
    installs
  56. Fda Medtech Compliance Auditor · thomasmoreai
    FDA MedTech Compliance Auditor workflow skill. Use this skill when the user needs Expert AI auditor for Medical Device (SaMD) compliance, IEC 62304, and 21 CFR Part 820. Reviews DHFs, technical files, and software validation and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
    0
    installs
  57. Apac Transfers · thomasmoreai
    Guides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
    0
    installs
  58. Apec Cbpr Cert · thomasmoreai
    Guides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
    0
    installs
  59. Customs Trade Compliance · thomasmoreai
    Customs & Trade Compliance workflow skill. Use this skill when the user needs Codified expertise for customs documentation, tariff classification, duty optimisation, restricted party screening, and regulatory compliance across multiple jurisdictions and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
    0
    installs
  60. Pia Health Data · thomasmoreai
    Conducts Privacy Impact Assessment for health data processing under GDPR Article 9, HIPAA, and sector-specific health privacy regulations. Covers special category data safeguards, clinical research data, patient portals, health wearables, genetic data, and cross-border health data transfers. Keywords: health data PIA, DPIA, Article 9, HIPAA, special category data, clinical research, patient privacy, genetic data.
    0
    installs
  61. Fda Medtech Compliance Auditor V2 · thomasmoreai
    FDA MedTech Compliance Auditor workflow skill. Use this skill when the user needs Expert AI auditor for Medical Device (SaMD) compliance, IEC 62304, and 21 CFR Part 820. Reviews DHFs, technical files, and software validation and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
    0
    installs
  62. Health Data Dpia · thomasmoreai
    Guides DPIA for health and medical data processing covering Art. 9(2)(h)-(j) exemptions, HIPAA crosswalk for transatlantic operations, clinical trial data protection under EU CTR 536/2014, and genetic data specifics under Art. 9(1). Activate for healthcare systems, clinical research, health apps, or medical device data. Keywords: health data, DPIA, Art. 9, clinical trial, genetic data, HIPAA, medical records, special category.
    0
    installs
  63. Specialized Legal Document Review · thomasmoreai
    Comprehensive legal document review specialist for contracts, litigation documents, and real estate agreements — summarizing documents, flagging risk clauses, comparing contract versions, and checking compliance across any law firm size or practice area
    0
    installs
  64. Employment Contract Templates V2 · thomasmoreai
    Employment Contract Templates workflow skill. Use this skill when the user needs Templates and patterns for creating legally sound employment documentation including contracts, offer letters, and HR policies and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
    0
    installs
  65. Legal Advisor Rmyndharis · thomasmoreai
    Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements. Use PROACTIVELY for legal documentation, compliance texts, or regulatory requirements.
    0
    installs
  66. Employment Contract Templates Diegosouzapw · thomasmoreai
    Employment Contract Templates workflow skill. Use this skill when the user needs Templates and patterns for creating legally sound employment documentation including contracts, offer letters, and HR policies and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
    0
    installs
  67. Implementing Gdpr Data Subject Access Request · thomasmoreai
    Automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging. Covers ICO/EDPB guidance compliance, exemption handling, and scalable batch processing. Use when building or auditing DSAR response capabilities under GDPR/UK GDPR.
    0
    installs
  68. Itar · thomasmoreai
    Expert ITAR compliance advisor for US defense contractors, exporters, and manufacturers. Use this skill for any question about 22 CFR Parts 120-130, the United States Munitions List (USML), DDTC registration, export license applications (DSP-5/73/94), Technical Assistance Agreements (TAA), Manufacturing License Agreements (MLA), brokering regulations (Part 129), deemed export rules for foreign nationals, technology control plans, voluntary disclosures, violation mitigation, jurisdiction determination (ITAR vs EAR), or US Munitions List category scoping. Trigger even if the user doesn't say "skill" — any ITAR or US defense export control question should use this skill.
    0
    installs
  69. Csrd · thomasmoreai
    Expert CSRD (Corporate Sustainability Reporting Directive, EU 2022/2464) compliance advisor. Use this skill whenever a user asks about CSRD, European Sustainability Reporting Standards (ESRS), double materiality assessment, sustainability reporting obligations, ESG disclosure, CSRD scope and thresholds, value chain reporting, XBRL digital tagging, third-party assurance, CSRD gap assessments, CSRD implementation timelines, ESRS E1–E5 environmental standards, ESRS S1–S4 social standards, ESRS G1 governance, CSRD vs GRI/TCFD/SASB alignment, or any EU corporate sustainability reporting question. Trigger even if the user only mentions "ESG reporting Europe", "sustainability disclosure EU", or "non-financial reporting".
    0
    installs
  70. Piia · thomasmoreai
    Drafts a Proprietary Information and Inventions Agreement (PIIA) for employment or consulting relationships. Covers confidentiality, invention assignment with state-law carve-outs, DTSA immunity notice, and prior inventions disclosure. Trigger when onboarding employees/consultants, drafting IP assignment agreements, or creating confidentiality and invention assignment contracts.
    0
    installs
  71. Deposition Ip · thomasmoreai
    Supplements general deposition preparation with IP-specific examination frameworks for patent, trademark, copyright, and trade secret cases. Covers witness strategies for inventors, accused infringers, licensing witnesses, and experts. Use alongside @deposition-preparation and @deposition-expert-witness when planning IP depositions, drafting outlines, or analyzing witness strategy.
    0
    installs
  72. Snda · thomasmoreai
    Drafts a Subordination, Non-Disturbance, and Attornment Agreement (SNDA) for commercial real estate. Extracts key terms from lease and loan documents, structures tri-party protections balancing landlord, tenant, and lender interests. Trigger when new financing or refinancing requires subordinating tenant leases to lender liens, drafting non-disturbance protections, or preparing tri-party SNDA agreements.
    0
    installs
  73. Ism · thomasmoreai
    Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Use for ISM control selection, gap analysis, system authorisation, IRAP assessment preparation, security documentation, and ASD compliance. Triggers on: ISM controls, ASD compliance, IRAP assessment, PROTECTED system scoping, Essential Eight vs ISM, system authorisation, NC/OS/ PROTECTED/SECRET/TOP SECRET classification markings, security objectives, ISM guidelines or chapters, control applicability markings, cybersecurity documentation for Australian government, and any question about the ASD Information Security Manual framework or Australian government cybersecurity obligations.
    0
    installs
  74. Qdro Draft · thomasmoreai
    Drafts Qualified Domestic Relations Orders (QDROs) compliant with ERISA §206(d)(3) and IRC §414(p) to divide retirement benefits in divorce. Covers defined benefit pensions, 401(k)s, and defined contribution plans with plan-specific division formulas and alternate payee protections. Use when drafting QDROs, dividing retirement assets post-judgment, or preparing domestic relations orders for plan administrator review.
    0
    installs
  75. Dora · thomasmoreai
    Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident classification or reporting, threat-led penetration testing (TLPT), ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of critical ICT third-party service providers (CTPPs), or any DORA RTS/ITS obligation. Also trigger for: "DORA gap analysis", "DORA readiness", "Art. 6 ICT risk framework", "Art. 17 incident reporting", "Art. 26 TLPT", "Art. 28 third-party policy", "Art. 30 contractual provisions", "Register of Information CIR 2024/2956", "critical TPSP designation", "DORA vs NIS2", "DORA simplified framework", or EBA/ESMA/EIOPA digital resilience guidance.
    0
    installs
  76. Cmmc · thomasmoreai
    Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021. Also trigger for: "CMMC gap analysis", "CMMC readiness", "FCI protection", "CUI scoping", "CMMC practices", "DoD contract cybersecurity", "defense supply chain security", or "prime contractor flow-down requirements".
    0
    installs
  77. Wisp · thomasmoreai
    Drafts a Written Information Security Program compliant with Massachusetts 201 CMR 17.00 and supplementary frameworks (GDPR, CCPA, HIPAA, GLBA, PCI-DSS). Produces a board-ready regulatory document covering coordinator designation, risk assessment, safeguards, training, incident response with breach notification, and vendor oversight. Use when an organization handles personal information of MA residents and needs a standalone WISP for regulatory examination or executive approval.
    0
    installs
  78. Itar Tcp · thomasmoreai
    Drafts ITAR Technology Control Plans (TCPs) for managing USML defense articles and technical data under 22 CFR Parts 120-130. Covers DDTC registration, classification, access controls, deemed export prevention, secure handling, training, audits, and incident response. Use when creating or updating export control compliance plans, technology control plans, or DDTC submission documents.
    0
    installs
  79. Corporate · thomasmoreai
    Advises on corporate law matters including entity formation, governance, finance, M&A, securities, venture capital, non-profits, and dissolution. Use when drafting governance documents, structuring transactions, selecting entity types, or navigating fiduciary duties and corporate formalities.
    0
    installs
  80. Oilfield Msa · thomasmoreai
    Drafts a Master Service Agreement for upstream oilfield services (Operator-Contractor). Covers knock-for-knock indemnification, anti-indemnity statute compliance (TX, LA, WY, NM), work order framework, HSE, insurance minimums, and IP/data ownership. Use when drafting oilfield MSAs, drilling service agreements, well service contracts, or upstream operator-contractor master agreements.
    0
    installs
  81. Swppp · thomasmoreai
    Drafts a Stormwater Pollution Prevention Plan (SWPPP) compliant with 40 CFR Part 122, EPA Construction General Permit (CGP), and applicable state NPDES requirements for construction projects disturbing one or more acres. Use when drafting SWPPPs, construction stormwater permits, erosion control plans, NPDES compliance documents, or BMP selection memoranda.
    0
    installs
  82. Form 1023 · thomasmoreai
    Drafts IRS Form 1023 applications for Section 501(c)(3) tax-exempt recognition. Analyzes organizing documents, finances, governance, and operations to produce a complete, internally consistent application. Use when forming non-profits, applying for tax-exempt status, seeking 501(c)(3) recognition, or preparing exemption applications.
    0
    installs
  83. Hsr Filing · thomasmoreai
    Prepares Hart-Scott-Rodino Act premerger notification filings for FTC/DOJ submission under 15 U.S.C. § 18a and 16 C.F.R. Parts 801-803. Covers threshold verification, NAICS revenue breakdowns, Item 4(c)/(d) document collection, competitive overlap analysis, prior acquisitions disclosure, and filing assembly. Use when an M&A deal may meet HSR size thresholds and requires antitrust clearance, premerger notification, or FTC/DOJ merger review.
    0
    installs
  84. Ccpa · thomasmoreai
    California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of sale/sharing, limit SPI), privacy notice drafting, service provider vs. contractor vs. third-party classification, sensitive personal information (SPI) handling, data minimization, opt-out mechanisms, CPPA enforcement, penalty exposure, GDPR comparison, and gap assessments for businesses operating in or targeting California residents.
    0
    installs
  85. Dvro Petition · thomasmoreai
    Drafts court-ready Domestic Violence Restraining Order petitions compiling chronological abuse incidents into element-driven pleadings supporting ex parte TRO and permanent protective order relief. Covers personal conduct orders, stay-away orders, custody/visitation, move-out orders, property control, and firearms relinquishment. Use when drafting DVRO petitions, protective order requests, ex parte TRO applications, or domestic violence pleadings.
    0
    installs
  86. Hipaa Baa · thomasmoreai
    Drafts HIPAA/HITECH-compliant Business Associate Agreements governing PHI/ePHI handling between covered entities and business associates. Covers Privacy Rule and Security Rule obligations, breach notification, subcontractor flow-downs, individual-rights support, and state-law overlays. Use when drafting or updating a BAA, negotiating vendor PHI access, or attaching HIPAA terms to a services agreement. Trigger keywords: BAA, business associate agreement, HIPAA contract, PHI vendor agreement, HITECH breach notice.
    0
    installs
  87. Ecp Manual · thomasmoreai
    Drafts an audit-ready Export Compliance Program manual covering EAR, ITAR, and OFAC requirements. Use when creating or updating an export compliance policy, international trade compliance program, or preparing enforcement defense documentation for regulatory review.
    0
    installs
  88. Ip Assignment · thomasmoreai
    Drafts intellectual property assignment agreements transferring patents, trademarks, copyrights, and trade secrets. Covers conveyancing language, registration recordation, consideration, representations and warranties, and post-closing obligations. Use when drafting IP assignments, asset purchase IP transfers, or technology transfer documents.
    0
    installs
  89. Dpdpa · thomasmoreai
    Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: "Section 6 consent", "Section 7 legitimate uses", "Section 9 children's data", "Section 10 SDF", "Section 16 cross-border", "Rule 6 breach notification", "Rule 13 SDF obligations", "Data Protection Board complaint", "verifiable parental consent India", "DPDPA compliance roadmap", or "India privacy law global company".
    0
    installs
  90. Alibi Notice · thomasmoreai
    Drafts a Notice of Alibi Defense under Fed. R. Crim. P. 12.1 or state equivalents. Triggers on alibi notice drafting, alibi defense filing, Rule 12.1 disclosure, or pre-trial criminal defense notice tasks.
    0
    installs
  91. Cognovit Note · thomasmoreai
    Drafts cognovit promissory notes with confession of judgment provisions, gated by mandatory jurisdictional enforceability research, usury compliance, and statutory disclosure requirements. Advises on alternatives where cognovit clauses are prohibited. Use when drafting cognovit notes, confession of judgment instruments, or loan documents requiring waiver-of-defense provisions.
    0
    installs
  92. Gmp Sop · thomasmoreai
    Drafts inspection-ready GMP standard operating procedures for regulated manufacturing. Covers document control, role accountability, process controls, deviation/CAPA handling, and records management aligned to FDA CGMP (21 CFR 210/211), Part 11, ICH Q7/Q9/Q10, WHO GMP, PIC/S, and EU GMP. Use when creating or overhauling a GMP SOP, preparing for audits or inspections, or building compliance-ready procedures. Trigger: GMP, SOP, CGMP, 21 CFR 210, 21 CFR 211, Part 11, ICH Q7, ICH Q9, ICH Q10, WHO GMP, PIC/S, EU GMP.
    0
    installs
  93. Legal Memo · thomasmoreai
    Drafts U.S. internal legal memoranda using IRAC structure to analyze issues, synthesize authority, assess risks, and recommend strategy. Use when asked to draft a research memo, internal memo, issue analysis, case strategy memo, or any IRAC-based legal analysis.
    0
    installs
  94. Haccp Plan · thomasmoreai
    Drafts U.S. HACCP plans for food production under FDA or USDA regimes. Triggers on requests involving HACCP plans, food safety plans, hazard analysis, critical control points, FSMA compliance, seafood HACCP (21 CFR 123), or meat/poultry HACCP (9 CFR 417).
    0
    installs
  95. Regulatory · thomasmoreai
    Navigates regulatory compliance, government relations, and administrative law across financial services, healthcare, environmental, FDA, privacy, energy, government contracts, trade, and securities domains. Use when handling agency interactions, compliance programs, enforcement defense, rulemaking comments, or administrative proceedings.
    0
    installs
  96. Form D · thomasmoreai
    Drafts SEC Form D Notice of Exempt Offering for EDGAR filing under Regulation D. Captures issuer details, related persons, offering structure, exemption basis (Rule 504, 506(b), 506(c)), sales compensation, and use of proceeds. Use when filing Form D, preparing an exempt offering notice, or handling Regulation D compliance for unregistered securities.
    0
    installs
  97. Fdd Receipt · thomasmoreai
    Drafts a Receipt of Franchise Disclosure Document proving FTC Franchise Rule compliance under 16 C.F.R. § 436. Produces an execution-ready acknowledgment with franchisee identification, delivery date, FDD version, exhibit inventory, and dual signature blocks. Use when creating FDD receipts, franchise disclosure acknowledgments, or Item 19 FPR attestations.
    0
    installs
  98. Bill Of Sale · thomasmoreai
    Drafts a U.S. Bill of Sale for transferring personal property ownership from seller to buyer. Covers vehicles, equipment, watercraft, firearms, business assets, and general personal property. Enforces party identification, property description, consideration, condition representations, title warranty, lien disclosure, and jurisdiction-specific execution requirements. Use when drafting a bill of sale, asset transfer document, or ownership transfer instrument.
    0
    installs
  99. Rofr Co Sale · thomasmoreai
    Drafts Right of First Refusal and Co-Sale Agreements for venture-backed and closely-held companies. Establishes ROFR mechanics, tag-along/co-sale rights, transfer restrictions, and permitted transfer carve-outs aligned with NVCA standards. Use when drafting ROFR agreements, co-sale agreements, tag-along rights, share transfer restrictions, or investor protective provisions in venture capital, private equity, or startup financing transactions.
    0
    installs
  100. Series A Spa · thomasmoreai
    Drafts market-standard Series A Stock Purchase Agreements for venture capital financings. Covers preferred stock issuance, rep/warranty packages, indemnification, closing conditions, and securities law compliance. Coordinates with ancillary documents (IRA, Voting Agreement, ROFR/Co-Sale). Use when drafting SPA, stock purchase agreement, Series A financing, preferred stock purchase, venture capital closing documents, or equity financing agreements.
    0
    installs