ThomasMoreAI
- 3.6k skills
- 0 followers
- 4 hours ago last updated
- ▌ Iso27701 · thomasmoreaiExpert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 27701:2025, ISO/IEC 27701:2019, privacy information management, PIMS certification, PII controller or processor obligations, privacy risk assessment, Statement of Applicability for privacy, privacy by design, data subject rights, DPIA, records of processing activities, transitioning from ISO 27701:2019, GDPR alignment with ISO 27701, or any privacy management system topic. Also trigger for questions about Annex A.1 (controller controls), A.2 (processor controls), A.3 (shared security controls), or implementing a standalone PIMS without ISO 27001. When in doubt, use this skill — it covers the full ISO 27701 lifecycle from gap assessment through certification.
- ▌ Office Lease · thomasmoreaiDrafts commercial office lease agreements with rent schedules, expense allocations, maintenance splits, and protective provisions for landlord and tenant. Covers NNN, gross, and modified gross structures. Use when drafting office leases, commercial lease agreements, landlord-tenant contracts, or space rental agreements for commercial office premises.
- ▌ Form D Notice · thomasmoreaiDrafts U.S. SEC Form D notice data sets for Regulation D exempt offerings (Rule 504, 506(b), 506(c)), ready for EDGAR submission. Use when preparing a Form D filing, notice of exempt offering, Reg D compliance, or unregistered securities offering notice.
- ▌ Kentucky Kppa · thomasmoreaiKentucky Consumer Privacy Protection Act (KPPA) compliance. Effective January 1, 2026. Covers consumer rights, controller thresholds at 100,000 consumers, sensitive data processing consent, cure period provisions, and AG enforcement framework.
- ▌ Montana Mtdpa · thomasmoreaiMontana Consumer Data Privacy Act (MTDPA) compliance. Lowest consumer threshold at 50,000 consumers. Covers sensitive data consent, universal opt-out recognition, consumer rights, controller obligations, 60-day cure period, and AG enforcement. Effective October 1, 2024.
- ▌ Hipaa Privacy Rule · thomasmoreaiImplements HIPAA Privacy Rule requirements under 45 CFR §164.500-534 for covered entities and business associates. Covers minimum necessary standard, treatment-payment-operations exceptions, directory opt-out, personal representative rules, and authorization requirements. Keywords: HIPAA Privacy Rule, PHI, minimum necessary, TPO, authorization, covered entity.
- ▌ Hitech Act Privacy · thomasmoreaiImplements HITECH Act privacy and security requirements including breach notification expansion, four-tier penalty structure, state attorney general enforcement authority, EHR meaningful use privacy conditions, and business associate direct liability. Keywords: HITECH Act, breach notification, penalty tiers, state AG enforcement, meaningful use, EHR privacy.
- ▌ Telehealth Privacy · thomasmoreaiImplements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors, cross-state prescribing rules, and OCR enforcement discretion during public health emergencies. Keywords: telehealth privacy, virtual care, HIPAA, recording consent, platform BAA, cross-state licensing, OCR enforcement.
- ▌ Epc Contract · thomasmoreaiDrafts turnkey Engineering, Procurement, and Construction (EPC) contracts for industrial facility projects. Covers scope of work, commercial terms, performance guarantees, risk allocation, warranties, and dispute resolution. Use when drafting EPC agreements, turnkey construction contracts, or energy infrastructure project contracts (power plants, petrochemical facilities, water treatment plants).
- ▌ New Jersey Dpa · thomasmoreaiNew Jersey Data Privacy Act (NJDPA) compliance, effective January 15, 2025. Covers consumer rights (access, correction, deletion, portability, opt-out), controller obligations, sensitive data requirements, universal opt-out mechanism recognition, 30-day cure period (sunsets after 18 months), and AG enforcement. Keywords: NJDPA, New Jersey, data privacy, consumer rights, sensitive data, universal opt-out, AG enforcement.
- ▌ Hipaa Breach Notify · thomasmoreaiImplements HIPAA breach notification requirements under 45 CFR §164.400-414. Covers individual notification within 60 days, HHS reporting thresholds (500+ immediate, under 500 annual), state attorney general notification, media notification for 500+ in a state, and breach risk assessment. Keywords: HIPAA breach notification, HHS reporting, OCR breach portal, individual notice, state attorney general.
- ▌ Hipaa Security Rule · thomasmoreaiImplements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. Covers access controls with unique user identification, emergency access procedures, automatic logoff, encryption, audit controls, integrity controls, and transmission security. Keywords: HIPAA Security Rule, ePHI, access controls, encryption, audit controls, technical safeguards.
- ▌ Lpa Agreement · thomasmoreaiDrafts institutional-quality Limited Partnership Agreements for PE/VC fund formation. Covers GP/LP terms, capital commitments, distribution waterfall, carried interest, LPAC governance, clawback, and tax provisions. Use when drafting LPA, fund formation agreement, limited partnership terms, or PE/VC fund documents.
- ▌ Gdpr Compliance · thomasmoreaiGenerate UK/EU GDPR compliance documents — privacy policies, cookie policies, DPIAs, ROPA, DSAR responses, data breach notifications, and consent forms. Use when a business needs GDPR documentation, data protection policies, or privacy compliance.
- ▌ Lex V2 · thomasmoreaiLEX: Legal-Entity-X-ref workflow skill. Use this skill when the user needs Centralized 'Truth Engine' for cross-jurisdictional legal context (US, EU, CA) and contract scaffolding and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
- ▌ Comply Simota · thomasmoreaiRegulatory compliance and audit agent. Maps business regulatory requirements (SOC2/PCI-DSS/HIPAA/ISO 27001), checks control implementations, designs audit trails, and implements Policy as Code. Use when compliance auditing is needed.
- ▌ Coppa Compliance · thomasmoreaiImplements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312. Covers verifiable parental consent methods including signed forms, credit card verification, government ID, knowledge-based authentication, and video call. Includes FTC safe harbor programs and enforcement actions. Keywords: COPPA, FTC, children, parental consent, safe harbor, verifiable consent.
- ▌ Vcdpa Compliance · thomasmoreaiVirginia Consumer Data Protection Act (VCDPA) compliance implementation. Covers 5 consumer rights, controller obligations, processor requirements, opt-in for sensitive data, data protection impact assessments, AG enforcement, and cure period provisions. Effective January 1, 2023.
- ▌ Dd Form 254 · thomasmoreaiDrafts DD Form 254 Contract Security Classification Specifications for classified government contracts. Use when preparing security classification specs for prime contractors, subcontractors, SAP/SCI access, or facility clearance documentation per NISPOM (32 CFR Part 117) and DCSA regulations.
- ▌ Rea Request · thomasmoreaiDrafts a Request for Equitable Adjustment (REA) for U.S. federal government contracts under FAR provisions. Enforces element-driven cost/schedule narratives, FAR Part 31 cost structures, FAR 52.233-1 certification, and contemporaneous evidence marshaling. Use when a contractor seeks contract modification relief due to government-directed changes, differing site conditions, defective specifications, or government-caused delays.
- ▌ Flp Agreement · thomasmoreaiDrafts Family Limited Partnership agreements for estate planning and intergenerational wealth transfer. Ensures IRS enforceability under IRC §2036 with legitimate business purpose, valuation discounts, and senior-generation control. Use when drafting FLP agreements, family partnership documents, or estate planning partnership structures.
- ▌ Universal Opt Out · thomasmoreaiUniversal opt-out mechanism implementation across US state privacy laws. Covers Global Privacy Control (GPC) signal technical implementation, state-by-state recognition requirements, browser detection methods, authenticated vs unauthenticated handling, and compliance testing.
- ▌ Rfp Response · thomasmoreaiDrafts evaluation-ready U.S. federal RFP responses across all standard proposal volumes (cover letter, technical, cost/price, reps and certs). Enforces FAR compliance, CPARS references, and Section L/M alignment. Use when preparing federal solicitation submissions, responding to government RFPs, or drafting procurement bids.
- ▌ Dsar Intake System · thomasmoreaiBuilds a multi-channel DSAR intake system supporting web form, email, phone, and in-person requests with identity verification tiers, automated routing logic, SLA tracking, and response generation. Activate for DSAR intake, rights request portal, multi-channel intake, SLA tracking, request management queries.
- ▌ Legal Advisor · thomasmoreailegal-advisor workflow skill. Use this skill when the user needs Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
- ▌ Soc2 Privacy Audit · thomasmoreaiGuides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent, collection, use/retention/disposal, access, disclosure, security, and quality. Includes evidence collection, control testing, and report review. Keywords: SOC 2, privacy criteria, TSP, AICPA, Type II, trust services.
- ▌ Us Privacy Federal · thomasmoreaiMaps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.
- ▌ South Africa Popia · thomasmoreaiImplements compliance with South Africa's Protection of Personal Information Act (POPIA), Act No. 4 of 2013. Covers conditions for lawful processing, data subject rights, cross-border transfer restrictions, Information Regulator enforcement, and responsible party obligations. Keywords: POPIA, South Africa, Information Regulator, responsible party, operator, prior authorisation.
- ▌ Biometric Dpia · thomasmoreaiGuides DPIA for biometric processing systems including facial recognition, fingerprint, voice, iris, and gait analysis. Covers Art. 9 special category requirements, Art. 35(3)(b) mandatory DPIA triggers for large-scale biometric processing, and EDPB Guidelines 3/2019 on video surveillance. Keywords: biometric, facial recognition, fingerprint, DPIA, Art. 9, special category, EDPB Guidelines 3/2019.
- ▌ AI Transparency Reqs · thomasmoreaiImplements AI transparency requirements under EU AI Act Arts. 13-14 and GDPR Arts. 13-14. Covers user notification of AI interaction, system capability disclosure, limitation documentation, and meaningful information about automated logic. Keywords: AI transparency, EU AI Act, GDPR notification, explainability, automated decision.
- ▌ Dsar Processing · thomasmoreaiGuides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day deadline calculation with extensions, response formatting, exemptions, and fee provisions. Activate when handling DSAR, access request, subject access, Art. 15, or SAR queries.
- ▌ Right To Object · thomasmoreaiHandles GDPR Article 21 right to object to processing, including compelling legitimate grounds assessment, ceasing processing obligations, documentation requirements, and the relationship with erasure under Article 17(1)(c). Activate for right to object, Art. 21, objection to processing, legitimate interest queries.
- ▌ Data Portability · thomasmoreaiExecutes GDPR Article 20 data portability requests, covering machine-readable format requirements (JSON, CSV, XML), direct controller-to-controller transfer mechanisms, and scope limitations to data provided by the subject on consent or contract basis. Activate for portability, data export, Art. 20, data transfer queries.
- ▌ Legal Advisor V2 · thomasmoreailegal-advisor workflow skill. Use this skill when the user needs Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
- ▌ Nist Pf Identify · thomasmoreaiImplement the NIST Privacy Framework IDENTIFY function including ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories. Provides control mapping, gap analysis templates, and implementation workflows for privacy risk identification.
- ▌ Right To Erasure · thomasmoreaiImplements the GDPR Article 17 right to erasure (right to be forgotten) workflow, covering all six grounds for erasure, five exceptions, technical deletion versus anonymization decisions, and third-party notification under Article 19. Activate for erasure request, deletion request, right to be forgotten, Art. 17 queries.
- ▌ Bcr Establishment · thomasmoreaiGuides development and approval of Binding Corporate Rules under GDPR Article 47 for intra-group international data transfers. Covers Art. 47(2)(a)-(n) content requirements, BCR approval process with lead supervisory authority, and WP256/WP257 referentials. Keywords: BCR, binding corporate rules, intra-group transfers, Art. 47.
- ▌ Breach Simulation · thomasmoreaiDesigns and executes tabletop breach simulation exercises for testing organizational breach response capabilities. Covers scenario creation with realistic inject timelines, participant role assignment, communication testing across internal and external channels, decision-point evaluation, and after-action report generation. Keywords: tabletop exercise, breach simulation, incident response testing, scenario design, after-action report.
- ▌ Dpia Risk Scoring · thomasmoreaiProvides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134. Covers likelihood and severity assessment, risk matrix construction, inherent vs residual risk calculation, and risk appetite thresholds per EDPB WP248rev.01 guidance. Keywords: risk scoring, DPIA risk matrix, likelihood, severity, ENISA, ISO 29134, residual risk, risk appetite.
- ▌ Fetching Arbitration Rules 2 · thomasmoreaiUse when retrieving arbitration institutional rules (ICC, LCIA, SCC, SIAC, HKIAC, VIAC, МКАС/МАК при ТПП України, UNCITRAL) — fetching current version, verifying redaction applicable to the date of arbitration agreement, constructing URLs for official rule texts
- ▌ Consent Withdrawal · thomasmoreaiImplementation guide for GDPR Article 7(3) consent withdrawal mechanisms. Covers the equal ease requirement ensuring withdrawal is as easy as giving consent, one-click withdrawal implementation, cascading effects on downstream processing, third-party notification workflows, and technical architecture for real-time consent revocation.
- ▌ Gdpr Certification · thomasmoreaiGuides implementation of GDPR Article 42-43 data protection certification mechanisms including accredited certification bodies, criteria development, and periodic review. Activate when pursuing privacy certifications, evaluating certification bodies, or developing certification criteria. Keywords: certification, Article 42, Article 43, accreditation, seal, privacy mark.
- ▌ Personal Data Test · thomasmoreaiClassifies personal vs non-personal data per GDPR Art. 4(1) definition test with decision tree for borderline cases. References Breyer v Germany CJEU C-582/14 dynamic IP ruling and WP29 Opinion 4/2007. Keywords: personal data, GDPR Art 4, data classification, Breyer ruling, identifiability test, PII.
- ▌ Pia Review Cadence · thomasmoreaiGuides the periodic DPIA review lifecycle including trigger identification for regulatory changes, new data categories, technology changes, and breach incidents. Covers version control, stakeholder sign-off procedures, and DPIA register management per Art. 35(11). Keywords: DPIA review, PIA update, review cadence, version control, Art. 35(11), periodic review, trigger events, stakeholder sign-off.
- ▌ Dpa Inspection Prep · thomasmoreaiGuides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for key personnel, technical demonstration procedures, on-site logistics, response protocols, and post-inspection follow-up. Covers unannounced inspections, formal audits, and complaint-triggered investigations. Keywords: DPA inspection, supervisory authority, investigation, readiness, interview preparation, response protocol.
- ▌ Pseudo Vs Anon Data · thomasmoreaiClassifies data as pseudonymised or anonymised using Recital 26 reasonably likely test, Breyer ruling C-582/14, motivated intruder test, and WP29 Opinion 05/2014 on anonymisation techniques. Covers singling out, linkability, and inference tests. Keywords: pseudonymisation, anonymisation, Recital 26, re-identification, k-anonymity, differential privacy, WP29 Opinion 05/2014.
- ▌ Applying New York Convention 2 · thomasmoreaiUse when preparing applications for recognition and enforcement of foreign arbitral awards in Ukraine, applications for setting aside arbitral awards, or opposing such applications — mapping Article V of the 1958 New York Convention to Article 478 of the Ukrainian CPC, identifying grounds for refusal, structuring public policy arguments
- ▌ Lex Ignvvcio254 · thomasmoreaiCentralized 'Truth Engine' for cross-jurisdictional legal context (US, EU, CA) and contract scaffolding.
- ▌ Dsar Form · thomasmoreaiDrafts a GDPR- and CCPA-compliant Data Subject Access Request (DSAR) intake form for collecting requester information and processing privacy rights. Use when drafting DSAR forms, privacy rights request templates, or data subject rights workflows for EU/US-regulated organizations.
- ▌ Breach Documentation · thomasmoreaiMaintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was required. Covers mandatory register fields including facts, effects, and remedial actions, retention periods, audit readiness, and integration with the accountability framework. Keywords: breach register, Article 33(5), breach documentation, accountability, audit readiness, remedial actions.
- ▌ Breach Subject Comms · thomasmoreaiManages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in a high risk to their rights and freedoms. Covers the high risk threshold, required notification content per Art. 34(2), exemptions under Art. 34(3), and breach notification letter templates for five scenarios. Keywords: data subject notification, Article 34, high risk, breach communication, GDPR.
- ▌ Reviewing B2b Service Contract 2 · thomasmoreaiUse when auditing Polish B2B service contract (umowa o świadczenie usług / umowa współpracy / kontrakt B2B / staff augmentation / IT outsourcing) — zakaz konkurencji B2B (art. 353¹ KC, SN II CSK 58/18), klauzule wyłączności vs pozorny stosunek pracy (art. 22 § 1¹ KP), kary umowne (art. 483-484 KC, miarkowanie), IP (prawa autorskie do kodu / dzieła), JDG-specyficzne (Prawo Przedsiębiorców art. 6, CEIDG), obowiązek pierwszeństwa, rejestry (CEIDG, KRS, biała lista VAT)
- ▌ Lex Diegosouzapw · thomasmoreaiLEX: Legal-Entity-X-ref workflow skill. Use this skill when the user needs Centralized 'Truth Engine' for cross-jurisdictional legal context (US, EU, CA) and contract scaffolding and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
- ▌ Legal Review Projectious Work · thomasmoreaiStructures a systematic legal and compliance review of contracts, policies, or technical decisions — identifying key clauses, risks, and questions for counsel. Use when asked to review a contract, check compliance implications, flag legal risks in a technical design, or prepare for a legal consultation. Always surfaces work for qualified counsel; never replaces legal advice.
- ▌ Specialized Legal Client Intake · thomasmoreaiComprehensive legal client intake specialist for qualifying prospects, collecting case information, scheduling consultations, managing conflict checks, and delivering attorney-ready intake summaries across any practice area and firm size
- ▌ Fda Medtech Compliance Auditor · thomasmoreaiFDA MedTech Compliance Auditor workflow skill. Use this skill when the user needs Expert AI auditor for Medical Device (SaMD) compliance, IEC 62304, and 21 CFR Part 820. Reviews DHFs, technical files, and software validation and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
- ▌ Apac Transfers · thomasmoreaiGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
- ▌ Apec Cbpr Cert · thomasmoreaiGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
- ▌ Customs Trade Compliance · thomasmoreaiCustoms & Trade Compliance workflow skill. Use this skill when the user needs Codified expertise for customs documentation, tariff classification, duty optimisation, restricted party screening, and regulatory compliance across multiple jurisdictions and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
- ▌ Pia Health Data · thomasmoreaiConducts Privacy Impact Assessment for health data processing under GDPR Article 9, HIPAA, and sector-specific health privacy regulations. Covers special category data safeguards, clinical research data, patient portals, health wearables, genetic data, and cross-border health data transfers. Keywords: health data PIA, DPIA, Article 9, HIPAA, special category data, clinical research, patient privacy, genetic data.
- ▌ Fda Medtech Compliance Auditor V2 · thomasmoreaiFDA MedTech Compliance Auditor workflow skill. Use this skill when the user needs Expert AI auditor for Medical Device (SaMD) compliance, IEC 62304, and 21 CFR Part 820. Reviews DHFs, technical files, and software validation and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
- ▌ Health Data Dpia · thomasmoreaiGuides DPIA for health and medical data processing covering Art. 9(2)(h)-(j) exemptions, HIPAA crosswalk for transatlantic operations, clinical trial data protection under EU CTR 536/2014, and genetic data specifics under Art. 9(1). Activate for healthcare systems, clinical research, health apps, or medical device data. Keywords: health data, DPIA, Art. 9, clinical trial, genetic data, HIPAA, medical records, special category.
- ▌ Specialized Legal Document Review · thomasmoreaiComprehensive legal document review specialist for contracts, litigation documents, and real estate agreements — summarizing documents, flagging risk clauses, comparing contract versions, and checking compliance across any law firm size or practice area
- ▌ Employment Contract Templates V2 · thomasmoreaiEmployment Contract Templates workflow skill. Use this skill when the user needs Templates and patterns for creating legally sound employment documentation including contracts, offer letters, and HR policies and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
- ▌ Legal Advisor Rmyndharis · thomasmoreaiDraft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements. Use PROACTIVELY for legal documentation, compliance texts, or regulatory requirements.
- ▌ Employment Contract Templates Diegosouzapw · thomasmoreaiEmployment Contract Templates workflow skill. Use this skill when the user needs Templates and patterns for creating legally sound employment documentation including contracts, offer letters, and HR policies and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
- ▌ Implementing Gdpr Data Subject Access Request · thomasmoreaiAutomates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging. Covers ICO/EDPB guidance compliance, exemption handling, and scalable batch processing. Use when building or auditing DSAR response capabilities under GDPR/UK GDPR.
- ▌ Itar · thomasmoreaiExpert ITAR compliance advisor for US defense contractors, exporters, and manufacturers. Use this skill for any question about 22 CFR Parts 120-130, the United States Munitions List (USML), DDTC registration, export license applications (DSP-5/73/94), Technical Assistance Agreements (TAA), Manufacturing License Agreements (MLA), brokering regulations (Part 129), deemed export rules for foreign nationals, technology control plans, voluntary disclosures, violation mitigation, jurisdiction determination (ITAR vs EAR), or US Munitions List category scoping. Trigger even if the user doesn't say "skill" — any ITAR or US defense export control question should use this skill.
- ▌ Csrd · thomasmoreaiExpert CSRD (Corporate Sustainability Reporting Directive, EU 2022/2464) compliance advisor. Use this skill whenever a user asks about CSRD, European Sustainability Reporting Standards (ESRS), double materiality assessment, sustainability reporting obligations, ESG disclosure, CSRD scope and thresholds, value chain reporting, XBRL digital tagging, third-party assurance, CSRD gap assessments, CSRD implementation timelines, ESRS E1–E5 environmental standards, ESRS S1–S4 social standards, ESRS G1 governance, CSRD vs GRI/TCFD/SASB alignment, or any EU corporate sustainability reporting question. Trigger even if the user only mentions "ESG reporting Europe", "sustainability disclosure EU", or "non-financial reporting".
- ▌ Piia · thomasmoreaiDrafts a Proprietary Information and Inventions Agreement (PIIA) for employment or consulting relationships. Covers confidentiality, invention assignment with state-law carve-outs, DTSA immunity notice, and prior inventions disclosure. Trigger when onboarding employees/consultants, drafting IP assignment agreements, or creating confidentiality and invention assignment contracts.
- ▌ Deposition Ip · thomasmoreaiSupplements general deposition preparation with IP-specific examination frameworks for patent, trademark, copyright, and trade secret cases. Covers witness strategies for inventors, accused infringers, licensing witnesses, and experts. Use alongside @deposition-preparation and @deposition-expert-witness when planning IP depositions, drafting outlines, or analyzing witness strategy.
- ▌ Snda · thomasmoreaiDrafts a Subordination, Non-Disturbance, and Attornment Agreement (SNDA) for commercial real estate. Extracts key terms from lease and loan documents, structures tri-party protections balancing landlord, tenant, and lender interests. Trigger when new financing or refinancing requires subordinating tenant leases to lender liens, drafting non-disturbance protections, or preparing tri-party SNDA agreements.
- ▌ Ism · thomasmoreaiExpert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Use for ISM control selection, gap analysis, system authorisation, IRAP assessment preparation, security documentation, and ASD compliance. Triggers on: ISM controls, ASD compliance, IRAP assessment, PROTECTED system scoping, Essential Eight vs ISM, system authorisation, NC/OS/ PROTECTED/SECRET/TOP SECRET classification markings, security objectives, ISM guidelines or chapters, control applicability markings, cybersecurity documentation for Australian government, and any question about the ASD Information Security Manual framework or Australian government cybersecurity obligations.
- ▌ Qdro Draft · thomasmoreaiDrafts Qualified Domestic Relations Orders (QDROs) compliant with ERISA §206(d)(3) and IRC §414(p) to divide retirement benefits in divorce. Covers defined benefit pensions, 401(k)s, and defined contribution plans with plan-specific division formulas and alternate payee protections. Use when drafting QDROs, dividing retirement assets post-judgment, or preparing domestic relations orders for plan administrator review.
- ▌ Dora · thomasmoreaiExpert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident classification or reporting, threat-led penetration testing (TLPT), ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of critical ICT third-party service providers (CTPPs), or any DORA RTS/ITS obligation. Also trigger for: "DORA gap analysis", "DORA readiness", "Art. 6 ICT risk framework", "Art. 17 incident reporting", "Art. 26 TLPT", "Art. 28 third-party policy", "Art. 30 contractual provisions", "Register of Information CIR 2024/2956", "critical TPSP designation", "DORA vs NIS2", "DORA simplified framework", or EBA/ESMA/EIOPA digital resilience guidance.
- ▌ Cmmc · thomasmoreaiExpert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021. Also trigger for: "CMMC gap analysis", "CMMC readiness", "FCI protection", "CUI scoping", "CMMC practices", "DoD contract cybersecurity", "defense supply chain security", or "prime contractor flow-down requirements".
- ▌ Wisp · thomasmoreaiDrafts a Written Information Security Program compliant with Massachusetts 201 CMR 17.00 and supplementary frameworks (GDPR, CCPA, HIPAA, GLBA, PCI-DSS). Produces a board-ready regulatory document covering coordinator designation, risk assessment, safeguards, training, incident response with breach notification, and vendor oversight. Use when an organization handles personal information of MA residents and needs a standalone WISP for regulatory examination or executive approval.
- ▌ Itar Tcp · thomasmoreaiDrafts ITAR Technology Control Plans (TCPs) for managing USML defense articles and technical data under 22 CFR Parts 120-130. Covers DDTC registration, classification, access controls, deemed export prevention, secure handling, training, audits, and incident response. Use when creating or updating export control compliance plans, technology control plans, or DDTC submission documents.
- ▌ Corporate · thomasmoreaiAdvises on corporate law matters including entity formation, governance, finance, M&A, securities, venture capital, non-profits, and dissolution. Use when drafting governance documents, structuring transactions, selecting entity types, or navigating fiduciary duties and corporate formalities.
- ▌ Oilfield Msa · thomasmoreaiDrafts a Master Service Agreement for upstream oilfield services (Operator-Contractor). Covers knock-for-knock indemnification, anti-indemnity statute compliance (TX, LA, WY, NM), work order framework, HSE, insurance minimums, and IP/data ownership. Use when drafting oilfield MSAs, drilling service agreements, well service contracts, or upstream operator-contractor master agreements.
- ▌ Swppp · thomasmoreaiDrafts a Stormwater Pollution Prevention Plan (SWPPP) compliant with 40 CFR Part 122, EPA Construction General Permit (CGP), and applicable state NPDES requirements for construction projects disturbing one or more acres. Use when drafting SWPPPs, construction stormwater permits, erosion control plans, NPDES compliance documents, or BMP selection memoranda.
- ▌ Form 1023 · thomasmoreaiDrafts IRS Form 1023 applications for Section 501(c)(3) tax-exempt recognition. Analyzes organizing documents, finances, governance, and operations to produce a complete, internally consistent application. Use when forming non-profits, applying for tax-exempt status, seeking 501(c)(3) recognition, or preparing exemption applications.
- ▌ Hsr Filing · thomasmoreaiPrepares Hart-Scott-Rodino Act premerger notification filings for FTC/DOJ submission under 15 U.S.C. § 18a and 16 C.F.R. Parts 801-803. Covers threshold verification, NAICS revenue breakdowns, Item 4(c)/(d) document collection, competitive overlap analysis, prior acquisitions disclosure, and filing assembly. Use when an M&A deal may meet HSR size thresholds and requires antitrust clearance, premerger notification, or FTC/DOJ merger review.
- ▌ Ccpa · thomasmoreaiCalifornia Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of sale/sharing, limit SPI), privacy notice drafting, service provider vs. contractor vs. third-party classification, sensitive personal information (SPI) handling, data minimization, opt-out mechanisms, CPPA enforcement, penalty exposure, GDPR comparison, and gap assessments for businesses operating in or targeting California residents.
- ▌ Dvro Petition · thomasmoreaiDrafts court-ready Domestic Violence Restraining Order petitions compiling chronological abuse incidents into element-driven pleadings supporting ex parte TRO and permanent protective order relief. Covers personal conduct orders, stay-away orders, custody/visitation, move-out orders, property control, and firearms relinquishment. Use when drafting DVRO petitions, protective order requests, ex parte TRO applications, or domestic violence pleadings.
- ▌ Hipaa Baa · thomasmoreaiDrafts HIPAA/HITECH-compliant Business Associate Agreements governing PHI/ePHI handling between covered entities and business associates. Covers Privacy Rule and Security Rule obligations, breach notification, subcontractor flow-downs, individual-rights support, and state-law overlays. Use when drafting or updating a BAA, negotiating vendor PHI access, or attaching HIPAA terms to a services agreement. Trigger keywords: BAA, business associate agreement, HIPAA contract, PHI vendor agreement, HITECH breach notice.
- ▌ Ecp Manual · thomasmoreaiDrafts an audit-ready Export Compliance Program manual covering EAR, ITAR, and OFAC requirements. Use when creating or updating an export compliance policy, international trade compliance program, or preparing enforcement defense documentation for regulatory review.
- ▌ Ip Assignment · thomasmoreaiDrafts intellectual property assignment agreements transferring patents, trademarks, copyrights, and trade secrets. Covers conveyancing language, registration recordation, consideration, representations and warranties, and post-closing obligations. Use when drafting IP assignments, asset purchase IP transfers, or technology transfer documents.
- ▌ Dpdpa · thomasmoreaiExpert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: "Section 6 consent", "Section 7 legitimate uses", "Section 9 children's data", "Section 10 SDF", "Section 16 cross-border", "Rule 6 breach notification", "Rule 13 SDF obligations", "Data Protection Board complaint", "verifiable parental consent India", "DPDPA compliance roadmap", or "India privacy law global company".
- ▌ Alibi Notice · thomasmoreaiDrafts a Notice of Alibi Defense under Fed. R. Crim. P. 12.1 or state equivalents. Triggers on alibi notice drafting, alibi defense filing, Rule 12.1 disclosure, or pre-trial criminal defense notice tasks.
- ▌ Cognovit Note · thomasmoreaiDrafts cognovit promissory notes with confession of judgment provisions, gated by mandatory jurisdictional enforceability research, usury compliance, and statutory disclosure requirements. Advises on alternatives where cognovit clauses are prohibited. Use when drafting cognovit notes, confession of judgment instruments, or loan documents requiring waiver-of-defense provisions.
- ▌ Gmp Sop · thomasmoreaiDrafts inspection-ready GMP standard operating procedures for regulated manufacturing. Covers document control, role accountability, process controls, deviation/CAPA handling, and records management aligned to FDA CGMP (21 CFR 210/211), Part 11, ICH Q7/Q9/Q10, WHO GMP, PIC/S, and EU GMP. Use when creating or overhauling a GMP SOP, preparing for audits or inspections, or building compliance-ready procedures. Trigger: GMP, SOP, CGMP, 21 CFR 210, 21 CFR 211, Part 11, ICH Q7, ICH Q9, ICH Q10, WHO GMP, PIC/S, EU GMP.
- ▌ Legal Memo · thomasmoreaiDrafts U.S. internal legal memoranda using IRAC structure to analyze issues, synthesize authority, assess risks, and recommend strategy. Use when asked to draft a research memo, internal memo, issue analysis, case strategy memo, or any IRAC-based legal analysis.
- ▌ Haccp Plan · thomasmoreaiDrafts U.S. HACCP plans for food production under FDA or USDA regimes. Triggers on requests involving HACCP plans, food safety plans, hazard analysis, critical control points, FSMA compliance, seafood HACCP (21 CFR 123), or meat/poultry HACCP (9 CFR 417).
- ▌ Regulatory · thomasmoreaiNavigates regulatory compliance, government relations, and administrative law across financial services, healthcare, environmental, FDA, privacy, energy, government contracts, trade, and securities domains. Use when handling agency interactions, compliance programs, enforcement defense, rulemaking comments, or administrative proceedings.
- ▌ Form D · thomasmoreaiDrafts SEC Form D Notice of Exempt Offering for EDGAR filing under Regulation D. Captures issuer details, related persons, offering structure, exemption basis (Rule 504, 506(b), 506(c)), sales compensation, and use of proceeds. Use when filing Form D, preparing an exempt offering notice, or handling Regulation D compliance for unregistered securities.
- ▌ Fdd Receipt · thomasmoreaiDrafts a Receipt of Franchise Disclosure Document proving FTC Franchise Rule compliance under 16 C.F.R. § 436. Produces an execution-ready acknowledgment with franchisee identification, delivery date, FDD version, exhibit inventory, and dual signature blocks. Use when creating FDD receipts, franchise disclosure acknowledgments, or Item 19 FPR attestations.
- ▌ Bill Of Sale · thomasmoreaiDrafts a U.S. Bill of Sale for transferring personal property ownership from seller to buyer. Covers vehicles, equipment, watercraft, firearms, business assets, and general personal property. Enforces party identification, property description, consideration, condition representations, title warranty, lien disclosure, and jurisdiction-specific execution requirements. Use when drafting a bill of sale, asset transfer document, or ownership transfer instrument.
- ▌ Rofr Co Sale · thomasmoreaiDrafts Right of First Refusal and Co-Sale Agreements for venture-backed and closely-held companies. Establishes ROFR mechanics, tag-along/co-sale rights, transfer restrictions, and permitted transfer carve-outs aligned with NVCA standards. Use when drafting ROFR agreements, co-sale agreements, tag-along rights, share transfer restrictions, or investor protective provisions in venture capital, private equity, or startup financing transactions.
- ▌ Series A Spa · thomasmoreaiDrafts market-standard Series A Stock Purchase Agreements for venture capital financings. Covers preferred stock issuance, rep/warranty packages, indemnification, closing conditions, and securities law compliance. Coordinates with ancillary documents (IRA, Voting Agreement, ROFR/Co-Sale). Use when drafting SPA, stock purchase agreement, Series A financing, preferred stock purchase, venture capital closing documents, or equity financing agreements.