EU AI Act Quick Assessment — fast 15-25 minute triage for preliminary classification and compliance assessment. This skill should be used when the user asks to "do a quick AI Act assessment", "check if the AI Act applies to us", "run a preliminary classification", "do an AI Act triage", "quick check", "preliminary assessment", "Schnellprüfung", "Ersteinschätzung", or needs a fast initial assessment before committing to full analysis.
Use this skill when the user needs to review, draft, or redline a Data Processing Agreement (DPA / Auftragsverarbeitungsvertrag / AVV) under Art. 28 GDPR, or to prepare a Joint Controller Arrangement under Art. 26 GDPR. Triggers include "DPA", "AVV", "Auftragsverarbeitung", "Auftragsverarbeitungsvertrag", "Art. 28 contract", "data processing agreement", "processor agreement", "Art. 26 arrangement", "joint controller agreement", "JCA", "review this DPA", "draft a DPA", "redline this DPA", or any request involving controller-processor / joint-controller contracting. Supports bilingual output (DE/EN), both controller- and processor-side perspectives, and both quick (Art. 28(3)(a)–(h) coverage) and negotiation-grade (clause-by-clause risk scoring) review depths.
NIS2 Compliance Navigator — scope classification, Art. 21 gap analysis (0-4 maturity scoring), and compliance roadmap under EU Directive 2022/2555 with deep German BSIG-neu coverage and profiles for Italy, France, Netherlands, Austria, Spain. Use when: (1) User mentions "NIS2", "NIS-2", "BSIG", "BSIG-neu", "NIS2UmsuCG", "Cyberbeveiligingswet", "Loi Résilience", "NISG", "decreto legislativo 138", (2) User asks if their organization falls under NIS2 or needs a cybersecurity compliance assessment, (3) User mentions essential/important entities, Annex I/II, BSI registration, § 30 BSIG, incident reporting, management body liability, supply chain security, (4) User wants a NIS2 gap analysis, readiness assessment, or compliance roadmap, (5) User asks about NIS2 fines, enforcement, or Nachweispflicht, (6) User asks about NIS2 in any EU Member State.
Draft GDPR/DSGVO-compliant privacy notices as .docx for any EU/EEA jurisdiction and audience. Use when user asks to create a privacy policy/notice, mentions "Datenschutzerklärung", "politique de confidentialité", "privacy notice", needs Art. 13/14 disclosures, AI Act transparency, cookie policy, or notices for applicants ("Bewerber-Datenschutz"), employees ("Beschäftigten-Datenschutz"), B2B partners, or B2C customers. Covers DE (DSGVO+BDSG+TDDDG), FR (RGPD+LIL+LCEN), AT, IT, ES, NL, BE, IE, UK GDPR. Five notice types: Website/App, Applicant, Employee, Business Partner, B2C Customer.
Use whenever the user is working on document production in international arbitration: drafting requests to produce, raising or replying to objections, or preparing the schedule for the tribunal to rule on. Builds and maintains the request-to-produce table (the Redfern Schedule) for the requesting party, the producing party, or the tribunal. Applies the IBA Rules (2020) Article 3.3 admissibility checklist and the Article 9.2 objection grounds, raises a content-based political and institutional sensitivity prompt for State or state-owned parties, and writes an internal memo flagging the user's own weak requests. Trigger it even when the user does not say Redfern Schedule but mentions requests to produce, document production in an arbitration, IBA objections, Article 3.3 or 9.2, or a tribunal ruling on production. It enforces form and does not decide materiality or whether an objection will succeed.
Apply the NIST AI Risk Management Framework (NIST AI 100-1 + the NIST AI 600-1 Generative AI Profile) to a specific AI system, governance question, or impact assessment. Three modes — consult, governance plan, full assessment — all cite Subcategories (`GOVERN 1.1`) and Profile Action IDs (`GV-1.2-001`) verbatim. Use when the user mentions the AI RMF, NIST RMF, NIST AI 100-1, NIST AI 600-1, GenAI Profile, the four functions (Govern / Map / Measure / Manage), the trustworthy AI characteristics, the 12 GAI risks (confabulation, harmful bias, information integrity, CBRN, data privacy, etc.), or asks "what does NIST say about X" for an AI system.
Template analyzer for CoQuill (v2). Parses docx/HTML templates, extracts variables including conditionals and loops, merges config.yaml overrides, infers types, and generates a v2 manifest.yaml. Called by the coquill orchestrator — not triggered directly by the user.
Document renderer for CoQuill. Takes a template, variable values, and produces rendered documents (docx or html+pdf). Validates output for unfilled placeholders. Called by the coquill orchestrator — not triggered directly by the user.