[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-anthropic-use-case-triage":3,"mdc-eq84lc-key":37,"related-repo-anthropic-use-case-triage":1526,"related-org-anthropic-use-case-triage":1624},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":12,"stars":26,"repoUrl":27,"updatedAt":28,"license":29,"forks":30,"topics":31,"repo":32,"sourceUrl":35,"mdContent":36},"use-case-triage","triage privacy impact assessments","Quickly determine whether a processing activity needs a PIA, a mandatory GDPR DPIA, or can proceed — surfaces privacy policy conflicts and routes to the right next step. Use when the user asks \"does this need a PIA\", \"triage this feature\", \"privacy check on X\", \"is this okay from a privacy perspective\", or describes a new data processing activity, product feature, or vendor relationship.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},"anthropic","Anthropic","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Fanthropic.png","anthropics",[13,17,20,23],{"name":14,"slug":15,"type":16},"GDPR","gdpr","tag",{"name":18,"slug":19,"type":16},"Compliance","compliance",{"name":21,"slug":22,"type":16},"Legal","legal",{"name":24,"slug":25,"type":16},"Privacy","privacy",8721,"https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fclaude-for-legal","2026-05-13T06:03:14.860848",null,1642,[],{"repoUrl":27,"stars":26,"forks":30,"topics":33,"description":34},[],"A suite of plugins for legal workflows","https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fclaude-for-legal\u002Ftree\u002FHEAD\u002Fprivacy-legal\u002Fskills\u002Fuse-case-triage","---\nname: use-case-triage\ndescription: >\n  Quickly determine whether a processing activity needs a PIA, a mandatory GDPR\n  DPIA, or can proceed — surfaces privacy policy conflicts and routes to the right\n  next step. Use when the user asks \"does this need a PIA\", \"triage this feature\",\n  \"privacy check on X\", \"is this okay from a privacy perspective\", or describes a\n  new data processing activity, product feature, or vendor relationship.\nargument-hint: \"[describe the data processing activity or feature]\"\n---\n\n# \u002Fuse-case-triage\n\n1. Read `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md`. Confirm privacy practice is configured — if not, stop and direct to setup.\n2. Run the workflow below. Clarify the activity if vague.\n3. House trigger check → mandatory DPIA check (if GDPR in footprint) → privacy policy conflict check.\n4. Output: classification (PROCEED \u002F PIA REQUIRED \u002F DPIA MANDATORY \u002F STOP), reasoning, conditions table if required, cross-plugin handoffs.\n5. Offer to continue into PIA generation if assessment is required.\n\n```\n\u002Fprivacy-legal:use-case-triage \"New feature that uses behavioral data to personalize content recommendations\"\n```\n\n---\n\n# Privacy Use Case Triage\n\n## Matter context\n\n**Matter context.** Check `## Matter workspaces` in the practice-level CLAUDE.md. If `Enabled` is `✗` (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: \"Which matter is this for? Run `\u002Fprivacy-legal:matter-workspace switch \u003Cslug>` or say `practice-level`.\" Load the active matter's `matter.md` for matter-specific context and overrides. Write outputs to the matter folder at `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002Fmatters\u002F\u003Cmatter-slug>\u002F`. Never read another matter's files unless `Cross-matter context` is `on`.\n\n---\n\n## Destination check\n\nBefore producing output, check where it's going. If the user has named a destination (a channel, a distribution list, a counterparty, \"everyone\"), ask whether it's inside the privilege circle. Public channels, company-wide lists, counterparty\u002Fopposing counsel, vendors, and clients (for work product) waive the protection. When the destination looks outside the circle, flag it and offer (a) the privileged version for legal only, (b) a sanitized version for the broader channel, or (c) both — don't silently apply a privileged header and then help paste it somewhere the header won't protect it. See the canonical `## Shared guardrails → Destination check` in this plugin's CLAUDE.md.\n\n## Purpose\n\nAnswer the question that comes up before anyone runs a PIA: \"does this thing even\nneed one?\" And if it does, what kind, and what's blocking the way?\n\nPrivacy triage is faster than PIA generation but upstream of it. It doesn't write\nthe assessment — it determines whether one is needed and on what terms. The PIA\ngeneration skill does the deep work.\n\nThe output is one of four classifications:\n- **PROCEED** — No PIA needed. Standard safeguards apply.\n- **PIA REQUIRED** — Assessment needed before or alongside deployment.\n- **DPIA MANDATORY** — A regime-mandated data protection impact assessment is\n  required (research the applicable regime's trigger and cite primary sources).\n  Harder bar, DPO\u002FGC involvement likely.\n- **STOP** — Processing activity conflicts with the privacy policy or has no\n  lawful basis as described. Needs redesign before proceeding.\n\n## Jurisdiction assumption\n\nThis triage assumes the jurisdictional scope specified in your configuration. Privacy rules, assessment triggers, and lawful bases vary materially by jurisdiction (GDPR vs. state consumer privacy laws vs. sectoral). If the processing activity, controller, or affected data subjects fall under a different jurisdiction, this classification may not apply as written.\n\n## Read the config first\n\nBefore triaging, always read `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md`. The PIA trigger criteria, regulatory\nfootprint, and privacy policy commitments there are authoritative. Generic privacy\nlaw reasoning is not a substitute for what this company has actually committed to.\n\nIf the file is missing or contains `[PLACEHOLDER]`, surface this bounce:\n\n> I notice you haven't configured your practice profile yet — that's how I tailor the PIA trigger criteria, regulatory footprint, and privacy policy commitments to your practice.\n>\n> **Two choices:**\n> - Run `\u002Fprivacy-legal:cold-start-interview` (2 minutes) to configure your profile, then I'll triage tailored to YOUR practice.\n> - Say **\"provisional\"** and I'll triage against generic defaults — US jurisdiction, middle risk appetite, lawyer role, no playbook — and tag every output `[PROVISIONAL — configure your profile for tailored output]` so you can see what I do before committing.\n\n### Provisional mode\n\nIf the user says \"provisional,\" run triage normally using these generic defaults: middle risk appetite, lawyer role, US jurisdiction (CCPA + common federal sectoral baselines), no playbook (classify from general privacy-law principles rather than matching to configured commitments). Tag the reviewer note and every finding block with `[PROVISIONAL]`. At the end of the output, append:\n\n> \"That was a generic run against default assumptions. Run `\u002Fprivacy-legal:cold-start-interview` to get output calibrated to YOUR practice — your regulatory footprint, your privacy policy commitments, your risk appetite. 2 minutes.\"\n\n---\n\n## Triage process\n\n### Step 1: Understand the activity\n\nIf the description is vague, ask before classifying. Get specific on:\n\n- What data is being collected or processed? Which categories?\n- Who are the data subjects — customers, employees, third parties?\n- What's the purpose? What problem is this solving?\n- Is this new data collection, or repurposing data you already have?\n- Is a third-party vendor involved? New vendor or existing?\n- Is any automated decision-making involved — does the output affect anyone?\n- What's the deployment context — internal only, customer-facing, public?\n\n\"New feature\" and \"data processing activity\" are not enough to triage accurately.\n\n---\n\n### Step 2: Check house triggers\n\nRead `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → `## PIA house style` → Trigger criteria. Apply them.\n\nIf the house trigger is met → at minimum **PIA REQUIRED**.\n\nIf house trigger is not met, continue to Step 3 before concluding PROCEED. Some\nactivities need a PIA regardless of internal policy.\n\n---\n\n### Step 3: Mandatory assessment check\n\n**Before researching regime-specific triggers, ask the activity-based federal overlay question first.** If the processing touches a federally-regulated data category, the federal overlay is usually the controlling framework, not state privacy law, and the triage needs to surface that early rather than as an afterthought.\n\n> **Activity-based federal overlays — ask first:**\n>\n> Does this processing touch:\n> - **Financial account data or \"nonpublic personal information\" about consumers** (GLBA \u002F Reg P — applies to financial institutions and their non-affiliated third parties; imposes substantive restrictions on sharing NPI for marketing, separate from and on top of any state privacy-law exemption)?\n> - **Protected health information held by a covered entity or business associate** (HIPAA Privacy \u002F Security Rules — substantive restrictions on use and disclosure, breach notification at 500+ records, BAA required for any vendor)?\n> - **Education records held by a school or a service provider acting for a school** (FERPA — consent requirements for disclosure, directory-information carve-outs)?\n> - **Data from children under 13 collected by an operator of an online service directed to children or with actual knowledge** (COPPA — parental consent, notice, deletion rights, strict limits on retention and sharing)?\n> - **Another sectoral federal regime** (e.g., VPPA for video-viewing records, CPNI for carrier data, DPPA for DMV records, TCPA for SMS\u002Fcall consent)?\n>\n> If yes to any: the federal overlay usually supplies the controlling substantive restriction, not just an exemption from a state consumer privacy law. Research and cite the specific provision before continuing. An activity that is \"exempt\" from CCPA under § 1798.145(e) because it is GLBA-covered is still subject to the GLBA restrictions (e.g., § 6802(a)-(c) on NPI sharing) — the CCPA exemption does not make the activity lawful; it just moves the governing framework to GLBA.\n\nFor each regime in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → `## Regulatory footprint`, **research the currently operative mandatory privacy\u002Fdata-protection assessment triggers**. Cite controlling statute, regulation, or regulator guidance with pinpoint references. Note effective dates — national and state regulators publish and update trigger lists regularly; do not rely on a static checklist. Flag uncertainty for attorney verification rather than guess.\n\nIf **any** applicable regime's mandatory trigger is met → **DPIA MANDATORY** (or the equivalent regime-specific mandate), regardless of house trigger.\n\n**Strong indicators (not necessarily mandatory but do one anyway):**\n- New technology or novel use of existing technology\n- Children's data\n- Combining datasets that weren't collected together\n- Data that could enable discrimination\n- Processing users would not expect\n- Lookalike audiences, cross-context behavioral advertising, or other tracking-based ad-tech activity (recurring question for consumer-facing companies; surfaces policy-commitment conflicts and federal sectoral overlays reliably)\n\nOne or more strong indicators with no researched mandatory trigger → escalate to **PIA REQUIRED**\n(not DPIA mandatory, but flag in the output).\n\n---\n\n### Step 4: Privacy policy conflict check\n\nRead `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → `## Privacy policy commitments`. Check the proposed activity\nagainst every stated commitment.\n\n**Common conflicts to catch:**\n- Policy says \"we collect X, Y, Z\" — this activity collects W. Policy update\n  needed before launch, or stop collecting W.\n- Policy says \"we don't sell or share data with third parties\" — this activity\n  passes data to a vendor for their own purposes. Research whether the flow falls\n  within a regulated \"sale,\" \"share,\" or other disclosure category under each\n  applicable regime.\n- Policy states retention limits — this activity retains data longer.\n- Policy says \"we use data only for [purpose]\" — this activity uses it for a new\n  purpose without fresh consent or legitimate interest assessment.\n- Policy specifies user rights offered — this activity creates a new data category\n  the rights process wasn't built for.\n\nIf a direct conflict exists → **STOP**. Not \"proceed with caution\" — the policy\nconflict has to be resolved (policy update or activity redesign) before this\nproceeds.\n\n---\n\n### Step 5: Classification and output\n\n---\n\n### Bottom line\n[PIA required \u002F Mandatory DPIA required \u002F Proceed — one-sentence why]\n\n---\n\n**ACTIVITY:** [State the processing activity as you understand it]\n\n**CLASSIFICATION:** [PROCEED \u002F PIA REQUIRED \u002F DPIA MANDATORY \u002F STOP]\n\n**House trigger met?** [Yes \u002F No]\n**GDPR mandatory DPIA trigger?** [Yes — [trigger] \u002F No \u002F N\u002FA (GDPR not in footprint)]\n**Privacy policy conflict?** [None \u002F Yes — [specific conflict]]\n\n**Reasoning:**\n[1-3 sentences. For PROCEED: what makes it safe under current policy. For PIA\u002FDPIA:\nwhat creates the obligation. For STOP: which specific policy commitment or principle\nis in conflict.]\n\n---\n\n*If PIA REQUIRED or DPIA MANDATORY — conditions before proceeding:*\n\n| Requirement | Owner | Done? |\n|---|---|---|\n| [e.g., Privacy Impact Assessment — full DPIA format] | [Privacy counsel] | ☐ |\n| [e.g., Legitimate interest assessment (if LI basis)] | [Privacy counsel] | ☐ |\n| [e.g., DPO consultation (DPIA mandatory track)] | [DPO] | ☐ |\n| [e.g., Vendor DPA in place] | [Privacy \u002F Legal] | ☐ |\n| [e.g., Privacy policy update before launch] | [Privacy counsel] | ☐ |\n| [e.g., Consent mechanism built and tested] | [Product] | ☐ |\n| [e.g., Data subject rights process covers new data category] | [Privacy \u002F Product] | ☐ |\n\n**Lawful basis (if GDPR in footprint):** [Consent \u002F Contract \u002F Legitimate Interest \u002F\nLegal Obligation — or \"unclear — needs determination in PIA\"]\n\n**Next step — offer to continue:**\n\nAfter presenting a PIA REQUIRED or DPIA MANDATORY result, always end with:\n\n> \"Want me to start the PIA now? I can run the intake questions and produce the\n> assessment document without you needing to run a separate command.\"\n\nIf they say yes, load the `pia-generation` skill and continue in the same\nconversation — pass the activity description and any triggers already identified.\n\nIf they say no, the triage result stands. The PIA can be run any time with:\n`\u002Fprivacy-legal:pia-generation [activity]`\n\n---\n\n*If STOP:*\n\n**Conflict:** [Specific privacy policy commitment or principle in conflict]\n\n**To proceed, one of these has to change:**\n- [Option A — redesign the activity so it doesn't create the conflict]\n- [Option B — update the privacy policy to cover this processing (requires review\n  of whether the update is itself consistent with lawful basis)]\n\nDon't offer a path forward if there isn't one. If the processing simply can't be\nreconciled with stated commitments or lawful basis, say so.\n\n---\n\n### Step 6: Cross-plugin handoffs\n\n**AI governance handoff:** If the activity involves an AI system making or\ninfluencing decisions about individuals:\n\n> \"This activity involves AI decision-making. An AI impact assessment is likely\n> required in addition to a PIA. Use `\u002Fai-governance-legal:aia-generation [activity]`\n> to run that in parallel — they're not substitutes.\"\n\n**Product counsel handoff:** If this is a new product feature or launch:\n\n> \"If this is part of a product launch, loop in product counsel.\n> Use `\u002Fproduct-legal:launch-review` — it will detect the privacy component\n> and route to this plugin.\"\n\nOnly flag handoffs that are actually relevant. Don't append both as boilerplate.\n\n---\n\n## Batch triage\n\nIf the user presents a feature list, roadmap, or backlog — summary table first,\nthen expand each non-PROCEED entry:\n\n| # | Activity | Classification | Key condition \u002F blocker |\n|---|---|---|---|\n| 1 | [activity] | 🟢 Proceed | — |\n| 2 | [activity] | 🟡 PIA required | Lawful-basis assessment needed; vendor DPA not in place |\n| 3 | [activity] | 🟠 DPIA mandatory | Large-scale special category data |\n| 4 | [activity] | 🔴 Stop | Privacy policy conflict — purpose limitation |\n\n---\n\n## Edge cases and failure modes\n\n**\"It's anonymized\" doesn't automatically mean PROCEED.**\nAsk how it's anonymized and whether re-identification is realistically possible\ngiven the data set. Pseudonymized data is still personal data under GDPR.\n\n**\"We already do something similar\" isn't a triage.**\nExisting processing that was never assessed doesn't grandfather new processing.\nIf the new activity is materially different in scale, purpose, or data category,\ntriage it fresh.\n\n**\"Just a pilot\" doesn't skip triage.**\nA pilot that touches real user or employee data is subject to the same triggers.\nApply the same classification; if a PIA is required, the pilot should have one.\n\n**\"The vendor handles all the privacy.\"**\nVendor handles the infrastructure. You're still the controller determining the\npurposes. If personal data flows to the vendor, a DPA is required and triage still\napplies to the purpose.\n\n**Inferred data and derived attributes count.**\nIf the activity generates inferred data about individuals (e.g., a behavioral score,\na predicted preference), treat the inferred attribute as personal data for triage\npurposes. Don't let \"we're just computing a score\" obscure what the score represents.\n\n## Close with the next-steps decision tree\n\nEnd with the next-steps decision tree per CLAUDE.md `## Outputs`. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.\n",{"data":38,"body":40},{"name":4,"description":6,"argument-hint":39},"[describe the data processing activity or feature]",{"type":41,"children":42},"root",[43,51,90,102,106,112,119,202,205,211,224,230,235,240,245,289,295,300,306,318,331,384,391,404,419,422,428,434,439,477,482,485,491,510,520,525,528,534,544,618,644,662,670,703,714,717,723,741,749,784,795,798,804,807,813,821,824,839,853,901,914,917,926,1119,1133,1141,1146,1154,1167,1178,1181,1189,1203,1211,1230,1235,1238,1244,1254,1270,1280,1296,1301,1304,1310,1315,1448,1451,1457,1467,1477,1487,1497,1507,1513],{"type":44,"tag":45,"props":46,"children":47},"element","h1",{"id":4},[48],{"type":49,"value":50},"text","\u002Fuse-case-triage",{"type":44,"tag":52,"props":53,"children":54},"ol",{},[55,70,75,80,85],{"type":44,"tag":56,"props":57,"children":58},"li",{},[59,61,68],{"type":49,"value":60},"Read ",{"type":44,"tag":62,"props":63,"children":65},"code",{"className":64},[],[66],{"type":49,"value":67},"~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md",{"type":49,"value":69},". Confirm privacy practice is configured — if not, stop and direct to setup.",{"type":44,"tag":56,"props":71,"children":72},{},[73],{"type":49,"value":74},"Run the workflow below. Clarify the activity if vague.",{"type":44,"tag":56,"props":76,"children":77},{},[78],{"type":49,"value":79},"House trigger check → mandatory DPIA check (if GDPR in footprint) → privacy policy conflict check.",{"type":44,"tag":56,"props":81,"children":82},{},[83],{"type":49,"value":84},"Output: classification (PROCEED \u002F PIA REQUIRED \u002F DPIA MANDATORY \u002F STOP), reasoning, conditions table if required, cross-plugin handoffs.",{"type":44,"tag":56,"props":86,"children":87},{},[88],{"type":49,"value":89},"Offer to continue into PIA generation if assessment is required.",{"type":44,"tag":91,"props":92,"children":96},"pre",{"className":93,"code":95,"language":49},[94],"language-text","\u002Fprivacy-legal:use-case-triage \"New feature that uses behavioral data to personalize content recommendations\"\n",[97],{"type":44,"tag":62,"props":98,"children":100},{"__ignoreMap":99},"",[101],{"type":49,"value":95},{"type":44,"tag":103,"props":104,"children":105},"hr",{},[],{"type":44,"tag":45,"props":107,"children":109},{"id":108},"privacy-use-case-triage",[110],{"type":49,"value":111},"Privacy Use Case Triage",{"type":44,"tag":113,"props":114,"children":116},"h2",{"id":115},"matter-context",[117],{"type":49,"value":118},"Matter context",{"type":44,"tag":120,"props":121,"children":122},"p",{},[123,129,131,137,139,145,147,153,155,161,163,169,171,177,179,185,187,193,194,200],{"type":44,"tag":124,"props":125,"children":126},"strong",{},[127],{"type":49,"value":128},"Matter context.",{"type":49,"value":130}," Check ",{"type":44,"tag":62,"props":132,"children":134},{"className":133},[],[135],{"type":49,"value":136},"## Matter workspaces",{"type":49,"value":138}," in the practice-level CLAUDE.md. If ",{"type":44,"tag":62,"props":140,"children":142},{"className":141},[],[143],{"type":49,"value":144},"Enabled",{"type":49,"value":146}," is ",{"type":44,"tag":62,"props":148,"children":150},{"className":149},[],[151],{"type":49,"value":152},"✗",{"type":49,"value":154}," (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: \"Which matter is this for? Run ",{"type":44,"tag":62,"props":156,"children":158},{"className":157},[],[159],{"type":49,"value":160},"\u002Fprivacy-legal:matter-workspace switch \u003Cslug>",{"type":49,"value":162}," or say ",{"type":44,"tag":62,"props":164,"children":166},{"className":165},[],[167],{"type":49,"value":168},"practice-level",{"type":49,"value":170},".\" Load the active matter's ",{"type":44,"tag":62,"props":172,"children":174},{"className":173},[],[175],{"type":49,"value":176},"matter.md",{"type":49,"value":178}," for matter-specific context and overrides. Write outputs to the matter folder at ",{"type":44,"tag":62,"props":180,"children":182},{"className":181},[],[183],{"type":49,"value":184},"~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002Fmatters\u002F\u003Cmatter-slug>\u002F",{"type":49,"value":186},". Never read another matter's files unless ",{"type":44,"tag":62,"props":188,"children":190},{"className":189},[],[191],{"type":49,"value":192},"Cross-matter context",{"type":49,"value":146},{"type":44,"tag":62,"props":195,"children":197},{"className":196},[],[198],{"type":49,"value":199},"on",{"type":49,"value":201},".",{"type":44,"tag":103,"props":203,"children":204},{},[],{"type":44,"tag":113,"props":206,"children":208},{"id":207},"destination-check",[209],{"type":49,"value":210},"Destination check",{"type":44,"tag":120,"props":212,"children":213},{},[214,216,222],{"type":49,"value":215},"Before producing output, check where it's going. If the user has named a destination (a channel, a distribution list, a counterparty, \"everyone\"), ask whether it's inside the privilege circle. Public channels, company-wide lists, counterparty\u002Fopposing counsel, vendors, and clients (for work product) waive the protection. When the destination looks outside the circle, flag it and offer (a) the privileged version for legal only, (b) a sanitized version for the broader channel, or (c) both — don't silently apply a privileged header and then help paste it somewhere the header won't protect it. See the canonical ",{"type":44,"tag":62,"props":217,"children":219},{"className":218},[],[220],{"type":49,"value":221},"## Shared guardrails → Destination check",{"type":49,"value":223}," in this plugin's CLAUDE.md.",{"type":44,"tag":113,"props":225,"children":227},{"id":226},"purpose",[228],{"type":49,"value":229},"Purpose",{"type":44,"tag":120,"props":231,"children":232},{},[233],{"type":49,"value":234},"Answer the question that comes up before anyone runs a PIA: \"does this thing even\nneed one?\" And if it does, what kind, and what's blocking the way?",{"type":44,"tag":120,"props":236,"children":237},{},[238],{"type":49,"value":239},"Privacy triage is faster than PIA generation but upstream of it. It doesn't write\nthe assessment — it determines whether one is needed and on what terms. The PIA\ngeneration skill does the deep work.",{"type":44,"tag":120,"props":241,"children":242},{},[243],{"type":49,"value":244},"The output is one of four classifications:",{"type":44,"tag":246,"props":247,"children":248},"ul",{},[249,259,269,279],{"type":44,"tag":56,"props":250,"children":251},{},[252,257],{"type":44,"tag":124,"props":253,"children":254},{},[255],{"type":49,"value":256},"PROCEED",{"type":49,"value":258}," — No PIA needed. Standard safeguards apply.",{"type":44,"tag":56,"props":260,"children":261},{},[262,267],{"type":44,"tag":124,"props":263,"children":264},{},[265],{"type":49,"value":266},"PIA REQUIRED",{"type":49,"value":268}," — Assessment needed before or alongside deployment.",{"type":44,"tag":56,"props":270,"children":271},{},[272,277],{"type":44,"tag":124,"props":273,"children":274},{},[275],{"type":49,"value":276},"DPIA MANDATORY",{"type":49,"value":278}," — A regime-mandated data protection impact assessment is\nrequired (research the applicable regime's trigger and cite primary sources).\nHarder bar, DPO\u002FGC involvement likely.",{"type":44,"tag":56,"props":280,"children":281},{},[282,287],{"type":44,"tag":124,"props":283,"children":284},{},[285],{"type":49,"value":286},"STOP",{"type":49,"value":288}," — Processing activity conflicts with the privacy policy or has no\nlawful basis as described. Needs redesign before proceeding.",{"type":44,"tag":113,"props":290,"children":292},{"id":291},"jurisdiction-assumption",[293],{"type":49,"value":294},"Jurisdiction assumption",{"type":44,"tag":120,"props":296,"children":297},{},[298],{"type":49,"value":299},"This triage assumes the jurisdictional scope specified in your configuration. Privacy rules, assessment triggers, and lawful bases vary materially by jurisdiction (GDPR vs. state consumer privacy laws vs. sectoral). If the processing activity, controller, or affected data subjects fall under a different jurisdiction, this classification may not apply as written.",{"type":44,"tag":113,"props":301,"children":303},{"id":302},"read-the-config-first",[304],{"type":49,"value":305},"Read the config first",{"type":44,"tag":120,"props":307,"children":308},{},[309,311,316],{"type":49,"value":310},"Before triaging, always read ",{"type":44,"tag":62,"props":312,"children":314},{"className":313},[],[315],{"type":49,"value":67},{"type":49,"value":317},". The PIA trigger criteria, regulatory\nfootprint, and privacy policy commitments there are authoritative. Generic privacy\nlaw reasoning is not a substitute for what this company has actually committed to.",{"type":44,"tag":120,"props":319,"children":320},{},[321,323,329],{"type":49,"value":322},"If the file is missing or contains ",{"type":44,"tag":62,"props":324,"children":326},{"className":325},[],[327],{"type":49,"value":328},"[PLACEHOLDER]",{"type":49,"value":330},", surface this bounce:",{"type":44,"tag":332,"props":333,"children":334},"blockquote",{},[335,340,348],{"type":44,"tag":120,"props":336,"children":337},{},[338],{"type":49,"value":339},"I notice you haven't configured your practice profile yet — that's how I tailor the PIA trigger criteria, regulatory footprint, and privacy policy commitments to your practice.",{"type":44,"tag":120,"props":341,"children":342},{},[343],{"type":44,"tag":124,"props":344,"children":345},{},[346],{"type":49,"value":347},"Two choices:",{"type":44,"tag":246,"props":349,"children":350},{},[351,364],{"type":44,"tag":56,"props":352,"children":353},{},[354,356,362],{"type":49,"value":355},"Run ",{"type":44,"tag":62,"props":357,"children":359},{"className":358},[],[360],{"type":49,"value":361},"\u002Fprivacy-legal:cold-start-interview",{"type":49,"value":363}," (2 minutes) to configure your profile, then I'll triage tailored to YOUR practice.",{"type":44,"tag":56,"props":365,"children":366},{},[367,369,374,376,382],{"type":49,"value":368},"Say ",{"type":44,"tag":124,"props":370,"children":371},{},[372],{"type":49,"value":373},"\"provisional\"",{"type":49,"value":375}," and I'll triage against generic defaults — US jurisdiction, middle risk appetite, lawyer role, no playbook — and tag every output ",{"type":44,"tag":62,"props":377,"children":379},{"className":378},[],[380],{"type":49,"value":381},"[PROVISIONAL — configure your profile for tailored output]",{"type":49,"value":383}," so you can see what I do before committing.",{"type":44,"tag":385,"props":386,"children":388},"h3",{"id":387},"provisional-mode",[389],{"type":49,"value":390},"Provisional mode",{"type":44,"tag":120,"props":392,"children":393},{},[394,396,402],{"type":49,"value":395},"If the user says \"provisional,\" run triage normally using these generic defaults: middle risk appetite, lawyer role, US jurisdiction (CCPA + common federal sectoral baselines), no playbook (classify from general privacy-law principles rather than matching to configured commitments). Tag the reviewer note and every finding block with ",{"type":44,"tag":62,"props":397,"children":399},{"className":398},[],[400],{"type":49,"value":401},"[PROVISIONAL]",{"type":49,"value":403},". At the end of the output, append:",{"type":44,"tag":332,"props":405,"children":406},{},[407],{"type":44,"tag":120,"props":408,"children":409},{},[410,412,417],{"type":49,"value":411},"\"That was a generic run against default assumptions. Run ",{"type":44,"tag":62,"props":413,"children":415},{"className":414},[],[416],{"type":49,"value":361},{"type":49,"value":418}," to get output calibrated to YOUR practice — your regulatory footprint, your privacy policy commitments, your risk appetite. 2 minutes.\"",{"type":44,"tag":103,"props":420,"children":421},{},[],{"type":44,"tag":113,"props":423,"children":425},{"id":424},"triage-process",[426],{"type":49,"value":427},"Triage process",{"type":44,"tag":385,"props":429,"children":431},{"id":430},"step-1-understand-the-activity",[432],{"type":49,"value":433},"Step 1: Understand the activity",{"type":44,"tag":120,"props":435,"children":436},{},[437],{"type":49,"value":438},"If the description is vague, ask before classifying. Get specific on:",{"type":44,"tag":246,"props":440,"children":441},{},[442,447,452,457,462,467,472],{"type":44,"tag":56,"props":443,"children":444},{},[445],{"type":49,"value":446},"What data is being collected or processed? Which categories?",{"type":44,"tag":56,"props":448,"children":449},{},[450],{"type":49,"value":451},"Who are the data subjects — customers, employees, third parties?",{"type":44,"tag":56,"props":453,"children":454},{},[455],{"type":49,"value":456},"What's the purpose? What problem is this solving?",{"type":44,"tag":56,"props":458,"children":459},{},[460],{"type":49,"value":461},"Is this new data collection, or repurposing data you already have?",{"type":44,"tag":56,"props":463,"children":464},{},[465],{"type":49,"value":466},"Is a third-party vendor involved? New vendor or existing?",{"type":44,"tag":56,"props":468,"children":469},{},[470],{"type":49,"value":471},"Is any automated decision-making involved — does the output affect anyone?",{"type":44,"tag":56,"props":473,"children":474},{},[475],{"type":49,"value":476},"What's the deployment context — internal only, customer-facing, public?",{"type":44,"tag":120,"props":478,"children":479},{},[480],{"type":49,"value":481},"\"New feature\" and \"data processing activity\" are not enough to triage accurately.",{"type":44,"tag":103,"props":483,"children":484},{},[],{"type":44,"tag":385,"props":486,"children":488},{"id":487},"step-2-check-house-triggers",[489],{"type":49,"value":490},"Step 2: Check house triggers",{"type":44,"tag":120,"props":492,"children":493},{},[494,495,500,502,508],{"type":49,"value":60},{"type":44,"tag":62,"props":496,"children":498},{"className":497},[],[499],{"type":49,"value":67},{"type":49,"value":501}," → ",{"type":44,"tag":62,"props":503,"children":505},{"className":504},[],[506],{"type":49,"value":507},"## PIA house style",{"type":49,"value":509}," → Trigger criteria. Apply them.",{"type":44,"tag":120,"props":511,"children":512},{},[513,515,519],{"type":49,"value":514},"If the house trigger is met → at minimum ",{"type":44,"tag":124,"props":516,"children":517},{},[518],{"type":49,"value":266},{"type":49,"value":201},{"type":44,"tag":120,"props":521,"children":522},{},[523],{"type":49,"value":524},"If house trigger is not met, continue to Step 3 before concluding PROCEED. Some\nactivities need a PIA regardless of internal policy.",{"type":44,"tag":103,"props":526,"children":527},{},[],{"type":44,"tag":385,"props":529,"children":531},{"id":530},"step-3-mandatory-assessment-check",[532],{"type":49,"value":533},"Step 3: Mandatory assessment check",{"type":44,"tag":120,"props":535,"children":536},{},[537,542],{"type":44,"tag":124,"props":538,"children":539},{},[540],{"type":49,"value":541},"Before researching regime-specific triggers, ask the activity-based federal overlay question first.",{"type":49,"value":543}," If the processing touches a federally-regulated data category, the federal overlay is usually the controlling framework, not state privacy law, and the triage needs to surface that early rather than as an afterthought.",{"type":44,"tag":332,"props":545,"children":546},{},[547,555,560,613],{"type":44,"tag":120,"props":548,"children":549},{},[550],{"type":44,"tag":124,"props":551,"children":552},{},[553],{"type":49,"value":554},"Activity-based federal overlays — ask first:",{"type":44,"tag":120,"props":556,"children":557},{},[558],{"type":49,"value":559},"Does this processing touch:",{"type":44,"tag":246,"props":561,"children":562},{},[563,573,583,593,603],{"type":44,"tag":56,"props":564,"children":565},{},[566,571],{"type":44,"tag":124,"props":567,"children":568},{},[569],{"type":49,"value":570},"Financial account data or \"nonpublic personal information\" about consumers",{"type":49,"value":572}," (GLBA \u002F Reg P — applies to financial institutions and their non-affiliated third parties; imposes substantive restrictions on sharing NPI for marketing, separate from and on top of any state privacy-law exemption)?",{"type":44,"tag":56,"props":574,"children":575},{},[576,581],{"type":44,"tag":124,"props":577,"children":578},{},[579],{"type":49,"value":580},"Protected health information held by a covered entity or business associate",{"type":49,"value":582}," (HIPAA Privacy \u002F Security Rules — substantive restrictions on use and disclosure, breach notification at 500+ records, BAA required for any vendor)?",{"type":44,"tag":56,"props":584,"children":585},{},[586,591],{"type":44,"tag":124,"props":587,"children":588},{},[589],{"type":49,"value":590},"Education records held by a school or a service provider acting for a school",{"type":49,"value":592}," (FERPA — consent requirements for disclosure, directory-information carve-outs)?",{"type":44,"tag":56,"props":594,"children":595},{},[596,601],{"type":44,"tag":124,"props":597,"children":598},{},[599],{"type":49,"value":600},"Data from children under 13 collected by an operator of an online service directed to children or with actual knowledge",{"type":49,"value":602}," (COPPA — parental consent, notice, deletion rights, strict limits on retention and sharing)?",{"type":44,"tag":56,"props":604,"children":605},{},[606,611],{"type":44,"tag":124,"props":607,"children":608},{},[609],{"type":49,"value":610},"Another sectoral federal regime",{"type":49,"value":612}," (e.g., VPPA for video-viewing records, CPNI for carrier data, DPPA for DMV records, TCPA for SMS\u002Fcall consent)?",{"type":44,"tag":120,"props":614,"children":615},{},[616],{"type":49,"value":617},"If yes to any: the federal overlay usually supplies the controlling substantive restriction, not just an exemption from a state consumer privacy law. Research and cite the specific provision before continuing. An activity that is \"exempt\" from CCPA under § 1798.145(e) because it is GLBA-covered is still subject to the GLBA restrictions (e.g., § 6802(a)-(c) on NPI sharing) — the CCPA exemption does not make the activity lawful; it just moves the governing framework to GLBA.",{"type":44,"tag":120,"props":619,"children":620},{},[621,623,628,629,635,637,642],{"type":49,"value":622},"For each regime in ",{"type":44,"tag":62,"props":624,"children":626},{"className":625},[],[627],{"type":49,"value":67},{"type":49,"value":501},{"type":44,"tag":62,"props":630,"children":632},{"className":631},[],[633],{"type":49,"value":634},"## Regulatory footprint",{"type":49,"value":636},", ",{"type":44,"tag":124,"props":638,"children":639},{},[640],{"type":49,"value":641},"research the currently operative mandatory privacy\u002Fdata-protection assessment triggers",{"type":49,"value":643},". Cite controlling statute, regulation, or regulator guidance with pinpoint references. Note effective dates — national and state regulators publish and update trigger lists regularly; do not rely on a static checklist. Flag uncertainty for attorney verification rather than guess.",{"type":44,"tag":120,"props":645,"children":646},{},[647,649,654,656,660],{"type":49,"value":648},"If ",{"type":44,"tag":124,"props":650,"children":651},{},[652],{"type":49,"value":653},"any",{"type":49,"value":655}," applicable regime's mandatory trigger is met → ",{"type":44,"tag":124,"props":657,"children":658},{},[659],{"type":49,"value":276},{"type":49,"value":661}," (or the equivalent regime-specific mandate), regardless of house trigger.",{"type":44,"tag":120,"props":663,"children":664},{},[665],{"type":44,"tag":124,"props":666,"children":667},{},[668],{"type":49,"value":669},"Strong indicators (not necessarily mandatory but do one anyway):",{"type":44,"tag":246,"props":671,"children":672},{},[673,678,683,688,693,698],{"type":44,"tag":56,"props":674,"children":675},{},[676],{"type":49,"value":677},"New technology or novel use of existing technology",{"type":44,"tag":56,"props":679,"children":680},{},[681],{"type":49,"value":682},"Children's data",{"type":44,"tag":56,"props":684,"children":685},{},[686],{"type":49,"value":687},"Combining datasets that weren't collected together",{"type":44,"tag":56,"props":689,"children":690},{},[691],{"type":49,"value":692},"Data that could enable discrimination",{"type":44,"tag":56,"props":694,"children":695},{},[696],{"type":49,"value":697},"Processing users would not expect",{"type":44,"tag":56,"props":699,"children":700},{},[701],{"type":49,"value":702},"Lookalike audiences, cross-context behavioral advertising, or other tracking-based ad-tech activity (recurring question for consumer-facing companies; surfaces policy-commitment conflicts and federal sectoral overlays reliably)",{"type":44,"tag":120,"props":704,"children":705},{},[706,708,712],{"type":49,"value":707},"One or more strong indicators with no researched mandatory trigger → escalate to ",{"type":44,"tag":124,"props":709,"children":710},{},[711],{"type":49,"value":266},{"type":49,"value":713},"\n(not DPIA mandatory, but flag in the output).",{"type":44,"tag":103,"props":715,"children":716},{},[],{"type":44,"tag":385,"props":718,"children":720},{"id":719},"step-4-privacy-policy-conflict-check",[721],{"type":49,"value":722},"Step 4: Privacy policy conflict check",{"type":44,"tag":120,"props":724,"children":725},{},[726,727,732,733,739],{"type":49,"value":60},{"type":44,"tag":62,"props":728,"children":730},{"className":729},[],[731],{"type":49,"value":67},{"type":49,"value":501},{"type":44,"tag":62,"props":734,"children":736},{"className":735},[],[737],{"type":49,"value":738},"## Privacy policy commitments",{"type":49,"value":740},". Check the proposed activity\nagainst every stated commitment.",{"type":44,"tag":120,"props":742,"children":743},{},[744],{"type":44,"tag":124,"props":745,"children":746},{},[747],{"type":49,"value":748},"Common conflicts to catch:",{"type":44,"tag":246,"props":750,"children":751},{},[752,757,762,767,779],{"type":44,"tag":56,"props":753,"children":754},{},[755],{"type":49,"value":756},"Policy says \"we collect X, Y, Z\" — this activity collects W. Policy update\nneeded before launch, or stop collecting W.",{"type":44,"tag":56,"props":758,"children":759},{},[760],{"type":49,"value":761},"Policy says \"we don't sell or share data with third parties\" — this activity\npasses data to a vendor for their own purposes. Research whether the flow falls\nwithin a regulated \"sale,\" \"share,\" or other disclosure category under each\napplicable regime.",{"type":44,"tag":56,"props":763,"children":764},{},[765],{"type":49,"value":766},"Policy states retention limits — this activity retains data longer.",{"type":44,"tag":56,"props":768,"children":769},{},[770,772,777],{"type":49,"value":771},"Policy says \"we use data only for ",{"type":44,"tag":773,"props":774,"children":775},"span",{},[776],{"type":49,"value":226},{"type":49,"value":778},"\" — this activity uses it for a new\npurpose without fresh consent or legitimate interest assessment.",{"type":44,"tag":56,"props":780,"children":781},{},[782],{"type":49,"value":783},"Policy specifies user rights offered — this activity creates a new data category\nthe rights process wasn't built for.",{"type":44,"tag":120,"props":785,"children":786},{},[787,789,793],{"type":49,"value":788},"If a direct conflict exists → ",{"type":44,"tag":124,"props":790,"children":791},{},[792],{"type":49,"value":286},{"type":49,"value":794},". Not \"proceed with caution\" — the policy\nconflict has to be resolved (policy update or activity redesign) before this\nproceeds.",{"type":44,"tag":103,"props":796,"children":797},{},[],{"type":44,"tag":385,"props":799,"children":801},{"id":800},"step-5-classification-and-output",[802],{"type":49,"value":803},"Step 5: Classification and output",{"type":44,"tag":103,"props":805,"children":806},{},[],{"type":44,"tag":385,"props":808,"children":810},{"id":809},"bottom-line",[811],{"type":49,"value":812},"Bottom line",{"type":44,"tag":120,"props":814,"children":815},{},[816],{"type":44,"tag":773,"props":817,"children":818},{},[819],{"type":49,"value":820},"PIA required \u002F Mandatory DPIA required \u002F Proceed — one-sentence why",{"type":44,"tag":103,"props":822,"children":823},{},[],{"type":44,"tag":120,"props":825,"children":826},{},[827,832,834],{"type":44,"tag":124,"props":828,"children":829},{},[830],{"type":49,"value":831},"ACTIVITY:",{"type":49,"value":833}," ",{"type":44,"tag":773,"props":835,"children":836},{},[837],{"type":49,"value":838},"State the processing activity as you understand it",{"type":44,"tag":120,"props":840,"children":841},{},[842,847,848],{"type":44,"tag":124,"props":843,"children":844},{},[845],{"type":49,"value":846},"CLASSIFICATION:",{"type":49,"value":833},{"type":44,"tag":773,"props":849,"children":850},{},[851],{"type":49,"value":852},"PROCEED \u002F PIA REQUIRED \u002F DPIA MANDATORY \u002F STOP",{"type":44,"tag":120,"props":854,"children":855},{},[856,861,862,867,872,873,885,890,891],{"type":44,"tag":124,"props":857,"children":858},{},[859],{"type":49,"value":860},"House trigger met?",{"type":49,"value":833},{"type":44,"tag":773,"props":863,"children":864},{},[865],{"type":49,"value":866},"Yes \u002F No",{"type":44,"tag":124,"props":868,"children":869},{},[870],{"type":49,"value":871},"GDPR mandatory DPIA trigger?",{"type":49,"value":833},{"type":44,"tag":773,"props":874,"children":875},{},[876,878,883],{"type":49,"value":877},"Yes — ",{"type":44,"tag":773,"props":879,"children":880},{},[881],{"type":49,"value":882},"trigger",{"type":49,"value":884}," \u002F No \u002F N\u002FA (GDPR not in footprint)",{"type":44,"tag":124,"props":886,"children":887},{},[888],{"type":49,"value":889},"Privacy policy conflict?",{"type":49,"value":833},{"type":44,"tag":773,"props":892,"children":893},{},[894,896],{"type":49,"value":895},"None \u002F Yes — ",{"type":44,"tag":773,"props":897,"children":898},{},[899],{"type":49,"value":900},"specific conflict",{"type":44,"tag":120,"props":902,"children":903},{},[904,909],{"type":44,"tag":124,"props":905,"children":906},{},[907],{"type":49,"value":908},"Reasoning:",{"type":44,"tag":773,"props":910,"children":911},{},[912],{"type":49,"value":913},"1-3 sentences. For PROCEED: what makes it safe under current policy. For PIA\u002FDPIA:\nwhat creates the obligation. For STOP: which specific policy commitment or principle\nis in conflict.",{"type":44,"tag":103,"props":915,"children":916},{},[],{"type":44,"tag":120,"props":918,"children":919},{},[920],{"type":44,"tag":921,"props":922,"children":923},"em",{},[924],{"type":49,"value":925},"If PIA REQUIRED or DPIA MANDATORY — conditions before proceeding:",{"type":44,"tag":927,"props":928,"children":929},"table",{},[930,954],{"type":44,"tag":931,"props":932,"children":933},"thead",{},[934],{"type":44,"tag":935,"props":936,"children":937},"tr",{},[938,944,949],{"type":44,"tag":939,"props":940,"children":941},"th",{},[942],{"type":49,"value":943},"Requirement",{"type":44,"tag":939,"props":945,"children":946},{},[947],{"type":49,"value":948},"Owner",{"type":44,"tag":939,"props":950,"children":951},{},[952],{"type":49,"value":953},"Done?",{"type":44,"tag":955,"props":956,"children":957},"tbody",{},[958,983,1005,1028,1051,1073,1096],{"type":44,"tag":935,"props":959,"children":960},{},[961,970,978],{"type":44,"tag":962,"props":963,"children":964},"td",{},[965],{"type":44,"tag":773,"props":966,"children":967},{},[968],{"type":49,"value":969},"e.g., Privacy Impact Assessment — full DPIA format",{"type":44,"tag":962,"props":971,"children":972},{},[973],{"type":44,"tag":773,"props":974,"children":975},{},[976],{"type":49,"value":977},"Privacy counsel",{"type":44,"tag":962,"props":979,"children":980},{},[981],{"type":49,"value":982},"☐",{"type":44,"tag":935,"props":984,"children":985},{},[986,994,1001],{"type":44,"tag":962,"props":987,"children":988},{},[989],{"type":44,"tag":773,"props":990,"children":991},{},[992],{"type":49,"value":993},"e.g., Legitimate interest assessment (if LI basis)",{"type":44,"tag":962,"props":995,"children":996},{},[997],{"type":44,"tag":773,"props":998,"children":999},{},[1000],{"type":49,"value":977},{"type":44,"tag":962,"props":1002,"children":1003},{},[1004],{"type":49,"value":982},{"type":44,"tag":935,"props":1006,"children":1007},{},[1008,1016,1024],{"type":44,"tag":962,"props":1009,"children":1010},{},[1011],{"type":44,"tag":773,"props":1012,"children":1013},{},[1014],{"type":49,"value":1015},"e.g., DPO consultation (DPIA mandatory track)",{"type":44,"tag":962,"props":1017,"children":1018},{},[1019],{"type":44,"tag":773,"props":1020,"children":1021},{},[1022],{"type":49,"value":1023},"DPO",{"type":44,"tag":962,"props":1025,"children":1026},{},[1027],{"type":49,"value":982},{"type":44,"tag":935,"props":1029,"children":1030},{},[1031,1039,1047],{"type":44,"tag":962,"props":1032,"children":1033},{},[1034],{"type":44,"tag":773,"props":1035,"children":1036},{},[1037],{"type":49,"value":1038},"e.g., Vendor DPA in place",{"type":44,"tag":962,"props":1040,"children":1041},{},[1042],{"type":44,"tag":773,"props":1043,"children":1044},{},[1045],{"type":49,"value":1046},"Privacy \u002F Legal",{"type":44,"tag":962,"props":1048,"children":1049},{},[1050],{"type":49,"value":982},{"type":44,"tag":935,"props":1052,"children":1053},{},[1054,1062,1069],{"type":44,"tag":962,"props":1055,"children":1056},{},[1057],{"type":44,"tag":773,"props":1058,"children":1059},{},[1060],{"type":49,"value":1061},"e.g., Privacy policy update before launch",{"type":44,"tag":962,"props":1063,"children":1064},{},[1065],{"type":44,"tag":773,"props":1066,"children":1067},{},[1068],{"type":49,"value":977},{"type":44,"tag":962,"props":1070,"children":1071},{},[1072],{"type":49,"value":982},{"type":44,"tag":935,"props":1074,"children":1075},{},[1076,1084,1092],{"type":44,"tag":962,"props":1077,"children":1078},{},[1079],{"type":44,"tag":773,"props":1080,"children":1081},{},[1082],{"type":49,"value":1083},"e.g., Consent mechanism built and tested",{"type":44,"tag":962,"props":1085,"children":1086},{},[1087],{"type":44,"tag":773,"props":1088,"children":1089},{},[1090],{"type":49,"value":1091},"Product",{"type":44,"tag":962,"props":1093,"children":1094},{},[1095],{"type":49,"value":982},{"type":44,"tag":935,"props":1097,"children":1098},{},[1099,1107,1115],{"type":44,"tag":962,"props":1100,"children":1101},{},[1102],{"type":44,"tag":773,"props":1103,"children":1104},{},[1105],{"type":49,"value":1106},"e.g., Data subject rights process covers new data category",{"type":44,"tag":962,"props":1108,"children":1109},{},[1110],{"type":44,"tag":773,"props":1111,"children":1112},{},[1113],{"type":49,"value":1114},"Privacy \u002F Product",{"type":44,"tag":962,"props":1116,"children":1117},{},[1118],{"type":49,"value":982},{"type":44,"tag":120,"props":1120,"children":1121},{},[1122,1127,1128],{"type":44,"tag":124,"props":1123,"children":1124},{},[1125],{"type":49,"value":1126},"Lawful basis (if GDPR in footprint):",{"type":49,"value":833},{"type":44,"tag":773,"props":1129,"children":1130},{},[1131],{"type":49,"value":1132},"Consent \u002F Contract \u002F Legitimate Interest \u002F\nLegal Obligation — or \"unclear — needs determination in PIA\"",{"type":44,"tag":120,"props":1134,"children":1135},{},[1136],{"type":44,"tag":124,"props":1137,"children":1138},{},[1139],{"type":49,"value":1140},"Next step — offer to continue:",{"type":44,"tag":120,"props":1142,"children":1143},{},[1144],{"type":49,"value":1145},"After presenting a PIA REQUIRED or DPIA MANDATORY result, always end with:",{"type":44,"tag":332,"props":1147,"children":1148},{},[1149],{"type":44,"tag":120,"props":1150,"children":1151},{},[1152],{"type":49,"value":1153},"\"Want me to start the PIA now? I can run the intake questions and produce the\nassessment document without you needing to run a separate command.\"",{"type":44,"tag":120,"props":1155,"children":1156},{},[1157,1159,1165],{"type":49,"value":1158},"If they say yes, load the ",{"type":44,"tag":62,"props":1160,"children":1162},{"className":1161},[],[1163],{"type":49,"value":1164},"pia-generation",{"type":49,"value":1166}," skill and continue in the same\nconversation — pass the activity description and any triggers already identified.",{"type":44,"tag":120,"props":1168,"children":1169},{},[1170,1172],{"type":49,"value":1171},"If they say no, the triage result stands. The PIA can be run any time with:\n",{"type":44,"tag":62,"props":1173,"children":1175},{"className":1174},[],[1176],{"type":49,"value":1177},"\u002Fprivacy-legal:pia-generation [activity]",{"type":44,"tag":103,"props":1179,"children":1180},{},[],{"type":44,"tag":120,"props":1182,"children":1183},{},[1184],{"type":44,"tag":921,"props":1185,"children":1186},{},[1187],{"type":49,"value":1188},"If STOP:",{"type":44,"tag":120,"props":1190,"children":1191},{},[1192,1197,1198],{"type":44,"tag":124,"props":1193,"children":1194},{},[1195],{"type":49,"value":1196},"Conflict:",{"type":49,"value":833},{"type":44,"tag":773,"props":1199,"children":1200},{},[1201],{"type":49,"value":1202},"Specific privacy policy commitment or principle in conflict",{"type":44,"tag":120,"props":1204,"children":1205},{},[1206],{"type":44,"tag":124,"props":1207,"children":1208},{},[1209],{"type":49,"value":1210},"To proceed, one of these has to change:",{"type":44,"tag":246,"props":1212,"children":1213},{},[1214,1222],{"type":44,"tag":56,"props":1215,"children":1216},{},[1217],{"type":44,"tag":773,"props":1218,"children":1219},{},[1220],{"type":49,"value":1221},"Option A — redesign the activity so it doesn't create the conflict",{"type":44,"tag":56,"props":1223,"children":1224},{},[1225],{"type":44,"tag":773,"props":1226,"children":1227},{},[1228],{"type":49,"value":1229},"Option B — update the privacy policy to cover this processing (requires review\nof whether the update is itself consistent with lawful basis)",{"type":44,"tag":120,"props":1231,"children":1232},{},[1233],{"type":49,"value":1234},"Don't offer a path forward if there isn't one. If the processing simply can't be\nreconciled with stated commitments or lawful basis, say so.",{"type":44,"tag":103,"props":1236,"children":1237},{},[],{"type":44,"tag":385,"props":1239,"children":1241},{"id":1240},"step-6-cross-plugin-handoffs",[1242],{"type":49,"value":1243},"Step 6: Cross-plugin handoffs",{"type":44,"tag":120,"props":1245,"children":1246},{},[1247,1252],{"type":44,"tag":124,"props":1248,"children":1249},{},[1250],{"type":49,"value":1251},"AI governance handoff:",{"type":49,"value":1253}," If the activity involves an AI system making or\ninfluencing decisions about individuals:",{"type":44,"tag":332,"props":1255,"children":1256},{},[1257],{"type":44,"tag":120,"props":1258,"children":1259},{},[1260,1262,1268],{"type":49,"value":1261},"\"This activity involves AI decision-making. An AI impact assessment is likely\nrequired in addition to a PIA. Use ",{"type":44,"tag":62,"props":1263,"children":1265},{"className":1264},[],[1266],{"type":49,"value":1267},"\u002Fai-governance-legal:aia-generation [activity]",{"type":49,"value":1269},"\nto run that in parallel — they're not substitutes.\"",{"type":44,"tag":120,"props":1271,"children":1272},{},[1273,1278],{"type":44,"tag":124,"props":1274,"children":1275},{},[1276],{"type":49,"value":1277},"Product counsel handoff:",{"type":49,"value":1279}," If this is a new product feature or launch:",{"type":44,"tag":332,"props":1281,"children":1282},{},[1283],{"type":44,"tag":120,"props":1284,"children":1285},{},[1286,1288,1294],{"type":49,"value":1287},"\"If this is part of a product launch, loop in product counsel.\nUse ",{"type":44,"tag":62,"props":1289,"children":1291},{"className":1290},[],[1292],{"type":49,"value":1293},"\u002Fproduct-legal:launch-review",{"type":49,"value":1295}," — it will detect the privacy component\nand route to this plugin.\"",{"type":44,"tag":120,"props":1297,"children":1298},{},[1299],{"type":49,"value":1300},"Only flag handoffs that are actually relevant. Don't append both as boilerplate.",{"type":44,"tag":103,"props":1302,"children":1303},{},[],{"type":44,"tag":113,"props":1305,"children":1307},{"id":1306},"batch-triage",[1308],{"type":49,"value":1309},"Batch triage",{"type":44,"tag":120,"props":1311,"children":1312},{},[1313],{"type":49,"value":1314},"If the user presents a feature list, roadmap, or backlog — summary table first,\nthen expand each non-PROCEED entry:",{"type":44,"tag":927,"props":1316,"children":1317},{},[1318,1344],{"type":44,"tag":931,"props":1319,"children":1320},{},[1321],{"type":44,"tag":935,"props":1322,"children":1323},{},[1324,1329,1334,1339],{"type":44,"tag":939,"props":1325,"children":1326},{},[1327],{"type":49,"value":1328},"#",{"type":44,"tag":939,"props":1330,"children":1331},{},[1332],{"type":49,"value":1333},"Activity",{"type":44,"tag":939,"props":1335,"children":1336},{},[1337],{"type":49,"value":1338},"Classification",{"type":44,"tag":939,"props":1340,"children":1341},{},[1342],{"type":49,"value":1343},"Key condition \u002F blocker",{"type":44,"tag":955,"props":1345,"children":1346},{},[1347,1373,1398,1423],{"type":44,"tag":935,"props":1348,"children":1349},{},[1350,1355,1363,1368],{"type":44,"tag":962,"props":1351,"children":1352},{},[1353],{"type":49,"value":1354},"1",{"type":44,"tag":962,"props":1356,"children":1357},{},[1358],{"type":44,"tag":773,"props":1359,"children":1360},{},[1361],{"type":49,"value":1362},"activity",{"type":44,"tag":962,"props":1364,"children":1365},{},[1366],{"type":49,"value":1367},"🟢 Proceed",{"type":44,"tag":962,"props":1369,"children":1370},{},[1371],{"type":49,"value":1372},"—",{"type":44,"tag":935,"props":1374,"children":1375},{},[1376,1381,1388,1393],{"type":44,"tag":962,"props":1377,"children":1378},{},[1379],{"type":49,"value":1380},"2",{"type":44,"tag":962,"props":1382,"children":1383},{},[1384],{"type":44,"tag":773,"props":1385,"children":1386},{},[1387],{"type":49,"value":1362},{"type":44,"tag":962,"props":1389,"children":1390},{},[1391],{"type":49,"value":1392},"🟡 PIA required",{"type":44,"tag":962,"props":1394,"children":1395},{},[1396],{"type":49,"value":1397},"Lawful-basis assessment needed; vendor DPA not in place",{"type":44,"tag":935,"props":1399,"children":1400},{},[1401,1406,1413,1418],{"type":44,"tag":962,"props":1402,"children":1403},{},[1404],{"type":49,"value":1405},"3",{"type":44,"tag":962,"props":1407,"children":1408},{},[1409],{"type":44,"tag":773,"props":1410,"children":1411},{},[1412],{"type":49,"value":1362},{"type":44,"tag":962,"props":1414,"children":1415},{},[1416],{"type":49,"value":1417},"🟠 DPIA mandatory",{"type":44,"tag":962,"props":1419,"children":1420},{},[1421],{"type":49,"value":1422},"Large-scale special category data",{"type":44,"tag":935,"props":1424,"children":1425},{},[1426,1431,1438,1443],{"type":44,"tag":962,"props":1427,"children":1428},{},[1429],{"type":49,"value":1430},"4",{"type":44,"tag":962,"props":1432,"children":1433},{},[1434],{"type":44,"tag":773,"props":1435,"children":1436},{},[1437],{"type":49,"value":1362},{"type":44,"tag":962,"props":1439,"children":1440},{},[1441],{"type":49,"value":1442},"🔴 Stop",{"type":44,"tag":962,"props":1444,"children":1445},{},[1446],{"type":49,"value":1447},"Privacy policy conflict — purpose limitation",{"type":44,"tag":103,"props":1449,"children":1450},{},[],{"type":44,"tag":113,"props":1452,"children":1454},{"id":1453},"edge-cases-and-failure-modes",[1455],{"type":49,"value":1456},"Edge cases and failure modes",{"type":44,"tag":120,"props":1458,"children":1459},{},[1460,1465],{"type":44,"tag":124,"props":1461,"children":1462},{},[1463],{"type":49,"value":1464},"\"It's anonymized\" doesn't automatically mean PROCEED.",{"type":49,"value":1466},"\nAsk how it's anonymized and whether re-identification is realistically possible\ngiven the data set. Pseudonymized data is still personal data under GDPR.",{"type":44,"tag":120,"props":1468,"children":1469},{},[1470,1475],{"type":44,"tag":124,"props":1471,"children":1472},{},[1473],{"type":49,"value":1474},"\"We already do something similar\" isn't a triage.",{"type":49,"value":1476},"\nExisting processing that was never assessed doesn't grandfather new processing.\nIf the new activity is materially different in scale, purpose, or data category,\ntriage it fresh.",{"type":44,"tag":120,"props":1478,"children":1479},{},[1480,1485],{"type":44,"tag":124,"props":1481,"children":1482},{},[1483],{"type":49,"value":1484},"\"Just a pilot\" doesn't skip triage.",{"type":49,"value":1486},"\nA pilot that touches real user or employee data is subject to the same triggers.\nApply the same classification; if a PIA is required, the pilot should have one.",{"type":44,"tag":120,"props":1488,"children":1489},{},[1490,1495],{"type":44,"tag":124,"props":1491,"children":1492},{},[1493],{"type":49,"value":1494},"\"The vendor handles all the privacy.\"",{"type":49,"value":1496},"\nVendor handles the infrastructure. You're still the controller determining the\npurposes. If personal data flows to the vendor, a DPA is required and triage still\napplies to the purpose.",{"type":44,"tag":120,"props":1498,"children":1499},{},[1500,1505],{"type":44,"tag":124,"props":1501,"children":1502},{},[1503],{"type":49,"value":1504},"Inferred data and derived attributes count.",{"type":49,"value":1506},"\nIf the activity generates inferred data about individuals (e.g., a behavioral score,\na predicted preference), treat the inferred attribute as personal data for triage\npurposes. Don't let \"we're just computing a score\" obscure what the score represents.",{"type":44,"tag":113,"props":1508,"children":1510},{"id":1509},"close-with-the-next-steps-decision-tree",[1511],{"type":49,"value":1512},"Close with the next-steps decision tree",{"type":44,"tag":120,"props":1514,"children":1515},{},[1516,1518,1524],{"type":49,"value":1517},"End with the next-steps decision tree per CLAUDE.md ",{"type":44,"tag":62,"props":1519,"children":1521},{"className":1520},[],[1522],{"type":49,"value":1523},"## Outputs",{"type":49,"value":1525},". Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.",{"items":1527,"total":1623},[1528,1540,1557,1574,1586,1597,1608],{"slug":1529,"name":1529,"fn":1530,"description":1531,"org":1532,"tags":1533,"stars":26,"repoUrl":27,"updatedAt":1539},"ai-inventory","track AI systems for EU AI Act","EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer, distributor, authorized representative, product manufacturer) and risk tier (prohibited, high-risk, limited, minimal, GPAI, GPAI+systemic). Role and tier are assessed per system, not per company. Use when the user says \"ai inventory\", \"add an ai system\", \"what systems do we have\", \"classify this ai system\", \"eu ai act register\", or \"ai system registry\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1534,1535,1538],{"name":18,"slug":19,"type":16},{"name":1536,"slug":1537,"type":16},"Governance","governance",{"name":21,"slug":22,"type":16},"2026-05-14T06:02:19.677579",{"slug":1541,"name":1541,"fn":1542,"description":1543,"org":1544,"tags":1545,"stars":26,"repoUrl":27,"updatedAt":1556},"ai-tool-handoff","manage handoff to bulk legal review tools","Detects when Luminance, Kira, or a similar bulk-review tool is in use, hands off the high-volume clause extraction to it, and QAs its output per the trust level in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fcorporate-legal\u002FCLAUDE.md`. Use when user says \"send to Luminance\", \"bulk review\", \"AI extraction\", or when diligence-issue-extraction hits a high-volume category.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1546,1549,1552,1553],{"name":1547,"slug":1548,"type":16},"Automation","automation",{"name":1550,"slug":1551,"type":16},"Contracts","contracts",{"name":21,"slug":22,"type":16},{"name":1554,"slug":1555,"type":16},"QA","qa","2026-05-14T06:01:31.00555",{"slug":1558,"name":1558,"fn":1559,"description":1560,"org":1561,"tags":1562,"stars":26,"repoUrl":27,"updatedAt":1573},"aia-generation","run AI impact assessments","Run an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommendation with conditions. Uses the house-style structure learned from the seed impact assessment in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fai-governance-legal\u002FCLAUDE.md`. Use when user says \"impact assessment for\", \"assess this AI use case\", \"run an AIA\", \"generate an AIA\", \"we need to document this AI system\", \"AI risk assessment for X\", or follows a conditional triage result.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1563,1564,1567,1570],{"name":21,"slug":22,"type":16},{"name":1565,"slug":1566,"type":16},"Policy","policy",{"name":1568,"slug":1569,"type":16},"Regulatory Compliance","regulatory-compliance",{"name":1571,"slug":1572,"type":16},"Risk Assessment","risk-assessment","2026-05-13T06:03:19.61029",{"slug":1575,"name":1575,"fn":1576,"description":1577,"org":1578,"tags":1579,"stars":26,"repoUrl":27,"updatedAt":1585},"amendment-history","trace contract amendment history","Trace how a contract has changed across its base agreement and all amendments — either a summary of all changes over time, or a provision trace for a specific clause. Use when the user says \"what changed in this contract over time\", \"show me the amendment history\", \"where's the latest [clause]\", \"how has [provision] evolved\", or uploads multiple versions of an agreement.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1580,1581,1584],{"name":1550,"slug":1551,"type":16},{"name":1582,"slug":1583,"type":16},"Documents","documents",{"name":21,"slug":22,"type":16},"2026-05-13T06:03:34.070339",{"slug":1587,"name":1587,"fn":1588,"description":1589,"org":1590,"tags":1591,"stars":26,"repoUrl":27,"updatedAt":1596},"auto-updater","check for community skill updates","Check installed community skills for updates. Shows a diff and requires explicit approval before applying. Use when the user says \"check for updates\", \"update my skills\", \"anything new for my installed skills\", or when invoked from the registry-sync agent.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1592,1593],{"name":1547,"slug":1548,"type":16},{"name":1594,"slug":1595,"type":16},"Plugin Development","plugin-development","2026-05-13T06:02:55.642269",{"slug":1598,"name":1598,"fn":1599,"description":1600,"org":1601,"tags":1602,"stars":26,"repoUrl":27,"updatedAt":1607},"bar-prep-questions","provide bar exam practice questions","Bar prep questions — MBE or essay, targeted at your weak subjects and bar jurisdiction. Tracks misses and comes back to patterns. Use when the user says \"bar prep\", \"MBE questions\", \"practice essay\", or \"test me for the bar\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1603,1606],{"name":1604,"slug":1605,"type":16},"Education","education",{"name":21,"slug":22,"type":16},"2026-07-24T05:41:43.01243",{"slug":1609,"name":1609,"fn":1610,"description":1611,"org":1612,"tags":1613,"stars":26,"repoUrl":27,"updatedAt":1622},"board-minutes","draft board and committee meeting minutes","Drafts board or committee meeting minutes in your house format. Auto-detects upcoming board and committee meetings from your calendar, asks for the agenda and any slides or pre-read materials, and produces a complete draft in the format learned from your seed minutes. Also handles written consents in lieu of meetings. Trigger: \"board minutes\", \"draft minutes\", \"upcoming board meeting\", \"committee minutes\", \"written consent\", or calendar detection of an upcoming board or committee event.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1614,1617,1618,1619],{"name":1615,"slug":1616,"type":16},"Documentation","documentation",{"name":1536,"slug":1537,"type":16},{"name":21,"slug":22,"type":16},{"name":1620,"slug":1621,"type":16},"Meetings","meetings","2026-05-14T06:01:29.792942",118,{"items":1625,"total":1808},[1626,1647,1661,1673,1692,1703,1722,1742,1756,1771,1779,1792],{"slug":1627,"name":1627,"fn":1628,"description":1629,"org":1630,"tags":1631,"stars":1644,"repoUrl":1645,"updatedAt":1646},"algorithmic-art","create algorithmic art with p5.js","Creating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems. Create original algorithmic art rather than copying existing artists' work to avoid copyright violations.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1632,1635,1638,1641],{"name":1633,"slug":1634,"type":16},"Creative","creative",{"name":1636,"slug":1637,"type":16},"Design","design",{"name":1639,"slug":1640,"type":16},"Generative Art","generative-art",{"name":1642,"slug":1643,"type":16},"JavaScript","javascript",161831,"https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fskills","2026-04-06T17:56:15.455818",{"slug":1648,"name":1648,"fn":1649,"description":1650,"org":1651,"tags":1652,"stars":1644,"repoUrl":1645,"updatedAt":1660},"brand-guidelines","apply Anthropic brand colors and typography","Applies Anthropic's official brand colors and typography to any sort of artifact that may benefit from having Anthropic's look-and-feel. Use it when brand colors or style guidelines, visual formatting, or company design standards apply.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1653,1656,1657],{"name":1654,"slug":1655,"type":16},"Branding","branding",{"name":1636,"slug":1637,"type":16},{"name":1658,"slug":1659,"type":16},"Typography","typography","2026-04-06T17:56:05.042852",{"slug":1662,"name":1662,"fn":1663,"description":1664,"org":1665,"tags":1666,"stars":1644,"repoUrl":1645,"updatedAt":1672},"canvas-design","create posters and visual art as PNG or PDF","Create beautiful visual art in .png and .pdf documents using design philosophy. You should use this skill when the user asks to create a poster, piece of art, design, or other static piece. Create original visual designs, never copying existing artists' work to avoid copyright violations.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1667,1668,1669],{"name":1633,"slug":1634,"type":16},{"name":1636,"slug":1637,"type":16},{"name":1670,"slug":1671,"type":16},"PDF","pdf","2026-04-06T17:56:03.794732",{"slug":1674,"name":1674,"fn":1675,"description":1676,"org":1677,"tags":1678,"stars":1644,"repoUrl":1645,"updatedAt":1691},"claude-api","build apps with the Claude API","Reference for the Claude API \u002F Anthropic SDK — model ids, pricing, params, streaming, tool use, MCP, agents, caching, token counting, model migration.\nTRIGGER — read BEFORE opening the target file; don't skip because it \"looks like a one-liner\" — whenever: the prompt names Claude\u002FAnthropic in any form (Claude, Anthropic, Fable, Opus, Sonnet, Haiku, `anthropic`, `@anthropic-ai`, `claude-*`, `us.anthropic.*`, `[1m]`); the user asks about an LLM (pricing\u002Fmodel choice\u002Flimits\u002Fcaching) — never answer from memory; OR the task is LLM-shaped with provider unstated (agent\u002FMCP\u002Ftool-definition\u002Fmulti-agent\u002FRAG\u002FLLM-judge\u002Fcomputer-use; generate\u002Fsummarize\u002Fextract\u002Fclassify\u002Frewrite\u002Fconverse over NL; debugging refusals\u002Fcutoffs\u002Fstreaming\u002Ftool-calls\u002Ftokens).\nSKIP only when another provider is being worked on (overrides all triggers): OpenAI\u002FGPT\u002FGemini\u002FLlama\u002FMistral\u002FCohere\u002FOllama named in the query; OR `grep -rE 'openai|langchain_openai|google.generativeai|genai|mistralai|cohere|ollama'` over the project hits (run this grep FIRST if no provider named — don't Read the file).",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1679,1682,1683,1686,1688],{"name":1680,"slug":1681,"type":16},"Agents","agents",{"name":9,"slug":8,"type":16},{"name":1684,"slug":1685,"type":16},"Anthropic SDK","anthropic-sdk",{"name":1687,"slug":1674,"type":16},"Claude API",{"name":1689,"slug":1690,"type":16},"LLM","llm","2026-07-28T05:36:08.213335",{"slug":1693,"name":1693,"fn":1694,"description":1695,"org":1696,"tags":1697,"stars":1644,"repoUrl":1645,"updatedAt":1702},"doc-coauthoring","co-author documentation and technical specs","Guide users through a structured workflow for co-authoring documentation. Use when user wants to write documentation, proposals, technical specs, decision docs, or similar structured content. This workflow helps users efficiently transfer context, refine content through iteration, and verify the doc works for readers. Trigger when user mentions writing docs, creating proposals, drafting specs, or similar documentation tasks.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1698,1699],{"name":1615,"slug":1616,"type":16},{"name":1700,"slug":1701,"type":16},"Technical Writing","technical-writing","2026-04-06T17:56:14.18897",{"slug":1704,"name":1704,"fn":1705,"description":1706,"org":1707,"tags":1708,"stars":1644,"repoUrl":1645,"updatedAt":1721},"docx","create and edit Word documents","Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when extracting or reorganizing content from .docx or .dotx files, inserting or replacing images in documents, performing find-and-replace in Word files, working with tracked changes or comments, or converting content into a polished Word document. If the user asks for a 'report', 'memo', 'letter', 'template', or similar deliverable as a Word or .docx file, use this skill. Do NOT use for PDFs, spreadsheets, Google Docs, or general coding tasks unrelated to document generation.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1709,1710,1712,1715,1718],{"name":1582,"slug":1583,"type":16},{"name":1711,"slug":1704,"type":16},"DOCX",{"name":1713,"slug":1714,"type":16},"Office","office",{"name":1716,"slug":1717,"type":16},"Templates","templates",{"name":1719,"slug":1720,"type":16},"Word","word","2026-07-18T05:16:23.136271",{"slug":1723,"name":1723,"fn":1724,"description":1725,"org":1726,"tags":1727,"stars":1644,"repoUrl":1645,"updatedAt":1741},"frontend-design","design production-grade frontend interfaces","Guidance for distinctive, intentional visual design when building new UI or reshaping an existing one. Helps with aesthetic direction, typography, and making choices that don't read as templated defaults.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1728,1729,1732,1735,1738],{"name":1636,"slug":1637,"type":16},{"name":1730,"slug":1731,"type":16},"Frontend","frontend",{"name":1733,"slug":1734,"type":16},"React","react",{"name":1736,"slug":1737,"type":16},"Tailwind CSS","tailwind-css",{"name":1739,"slug":1740,"type":16},"UI Components","ui-components","2026-04-06T17:56:16.723469",{"slug":1743,"name":1743,"fn":1744,"description":1745,"org":1746,"tags":1747,"stars":1644,"repoUrl":1645,"updatedAt":1755},"internal-comms","write internal company communications","A set of resources to help me write all kinds of internal communications, using the formats that my company likes to use. Claude should use this skill whenever asked to write some sort of internal communications (status reports, leadership updates, 3P updates, company newsletters, FAQs, incident reports, project updates, etc.).",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1748,1751,1752],{"name":1749,"slug":1750,"type":16},"Communications","communications",{"name":1716,"slug":1717,"type":16},{"name":1753,"slug":1754,"type":16},"Writing","writing","2026-04-06T17:56:20.695522",{"slug":1757,"name":1757,"fn":1758,"description":1759,"org":1760,"tags":1761,"stars":1644,"repoUrl":1645,"updatedAt":1770},"mcp-builder","build MCP servers","Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node\u002FTypeScript (MCP SDK).",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1762,1763,1766,1767],{"name":1680,"slug":1681,"type":16},{"name":1764,"slug":1765,"type":16},"API Development","api-development",{"name":1689,"slug":1690,"type":16},{"name":1768,"slug":1769,"type":16},"MCP","mcp","2026-04-06T17:56:10.357665",{"slug":1671,"name":1671,"fn":1772,"description":1773,"org":1774,"tags":1775,"stars":1644,"repoUrl":1645,"updatedAt":1778},"read edit and manipulate PDF files","Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text\u002Ftables from PDFs, combining or merging multiple PDFs into one, splitting PDFs apart, rotating pages, adding watermarks, creating new PDFs, filling PDF forms, encrypting\u002Fdecrypting PDFs, extracting images, and OCR on scanned PDFs to make them searchable. If the user mentions a .pdf file or asks to produce one, use this skill.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1776,1777],{"name":1582,"slug":1583,"type":16},{"name":1670,"slug":1671,"type":16},"2026-04-06T17:56:02.483316",{"slug":1780,"name":1780,"fn":1781,"description":1782,"org":1783,"tags":1784,"stars":1644,"repoUrl":1645,"updatedAt":1791},"pptx","create and edit PowerPoint presentations","Use this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an email or summary); editing, modifying, or updating existing presentations; combining or splitting slide files; working with templates (.potx), layouts, speaker notes, or comments. Trigger whenever the user mentions \"deck,\" \"slides,\" \"presentation,\" or references a .pptx or .potx filename, regardless of what they plan to do with the content afterward. If a .pptx or .potx file needs to be opened, created, or touched, use this skill.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1785,1788],{"name":1786,"slug":1787,"type":16},"PowerPoint","powerpoint",{"name":1789,"slug":1790,"type":16},"Presentations","presentations","2026-07-18T05:16:24.1471",{"slug":1793,"name":1793,"fn":1794,"description":1795,"org":1796,"tags":1797,"stars":1644,"repoUrl":1645,"updatedAt":1807},"skill-creator","create and optimize agent skills","Create new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with variance analysis, or optimize a skill's description for better triggering accuracy.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[1798,1799,1800,1803,1806],{"name":1680,"slug":1681,"type":16},{"name":1615,"slug":1616,"type":16},{"name":1801,"slug":1802,"type":16},"Evals","evals",{"name":1804,"slug":1805,"type":16},"Performance","performance",{"name":1700,"slug":1701,"type":16},"2026-04-19T06:45:40.804",490]