
[COMMUNITY] Generate an ASD Information Security Manual (ISM) control applicability statement for Australian Government projects, scoped to the system's classification and supporting DISP attestation.
[COMMUNITY] Generate a DISP (Defence Industry Security Program) Member self-attestation pack covering E8 ML2, ISM applicability, governance, personnel security, and incident reporting — supports DISP Levels 1, 2, 3.
[COMMUNITY] Generate an Australian energy-sector compliance architecture pack covering AER ring-fencing, AEMC NER/NGR, AEMO interfaces, and SOCI escalation evidence.
[COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments.
Research technology, services, and products to meet requirements with build vs buy analysis
Competitor landscape — rival suppliers, awarded-value market share, head-to-head and concentration, from the UK Tenders MCP
Create Strategic Outline Business Case (SOBC) using UK Government Green Book 5-case model
Procurement market intelligence — award-value benchmarks, top suppliers, incumbency and concentration, from the UK Tenders MCP
Score vendor proposals against evaluation criteria with persistent structured storage
[COMMUNITY] Generate an Australian Energy Sector Cyber Security Framework maturity assessment for energy-sector projects with IT, OT, market, and grid-edge dependencies.
Create comprehensive risk register following HM Treasury Orange Book principles
[COMMUNITY] Generate a SOCI Act Critical Infrastructure Risk Management Program (CIRMP) governance and evidence pack for Australian critical infrastructure assets.
[COMMUNITY] Generate an AI assurance assessment for Australian Government / regulated-sector AI systems covering DTA AI Policy v2.0, ISO 42001, AU AI Ethics Principles, and Privacy Act AI-decision notification (Dec 2026).
Create new document templates by interviewing the user about their organization's requirements
[COMMUNITY] Generate a Protective Security Policy Framework (PSPF) compliance assessment for Australian Government entities and contractors against the four security outcomes and 16 core requirements.
[COMMUNITY] Generate a DTA Digital Service Standard compliance assessment for Australian Government digital services against all 13 criteria.
[COMMUNITY] Generate an ASD Essential Eight maturity posture assessment for Australian Government projects against all eight mitigation strategies at ML0–ML3.
[COMMUNITY] Generate a Notifiable Data Breach (NDB) scheme response playbook under Privacy Act 1988 Part IIIC — eligible-data-breach test, 30-day OAIC notification timeline, individual notification, containment, and lessons-learned framework.
This skill should be used when the user asks about Wardley Mapping, evolution stages, strategic positioning, creating maps, value chain decomposition, gameplay patterns, doctrine assessment, climatic patterns, build vs. buy, or inertia analysis.
[COMMUNITY] Generate a Privacy Impact Assessment (PIA) for Australian Government entities under Privacy Act 1988 s33D, assessing compliance with all 13 Australian Privacy Principles (APPs).
Map the UK government code landscape for a domain — who built what, common patterns, standards, maturity
[COMMUNITY] Assess a US federal civilian system against the CISA Zero Trust Maturity Model v2.0 — scoring 5 pillars (Identity, Devices, Networks, Apps & Workloads, Data) and 3 cross-cuts (Visibility & Analytics, Automation & Orchestration, Governance) across 4 maturity stages.
[COMMUNITY] Produce a 3PAO-style Readiness Assessment Report for a FedRAMP authorization — capability statement, gap register, evidence inventory, and recommended ATO path (Agency vs JAB).
Prepare for GDS Service Standard assessment - analyze evidence against 14 points, identify gaps, generate readiness report
[COMMUNITY] Generate a NHS DCB0129 manufacturer Clinical Safety Case Report and Hazard Log (Marcus Baw SAFETY.md 3-file spec) for a digital health product placed on the NHS market.
Scan all projects for stale research, forgotten ADRs, unresolved review conditions, orphaned artifacts, missing traceability, and version drift
[COMMUNITY] Generate a NHS DCB0160 deployer Clinical Safety Case Report and deployment Hazard Log for an NHS organisation deploying or significantly configuring a health IT product into a specific clinical setting.
[COMMUNITY] Generate an NHS Digital Technology Assessment Criteria (DTAC v3) assessment for a digital health product being procured or assured by an NHS organisation.
[COMMUNITY] Design a US federal Identity, Credential, and Access Management architecture per OMB M-19-17 and NIST SP 800-63-3, determining IAL/AAL/FAL levels per use case and selecting PIV / login.gov / agency-specific identity providers.
[COMMUNITY] Generate a Privacy Impact Assessment under E-Government Act §208 and OMB M-03-22 for a US federal civilian system handling PII, including Privacy Act §552a alignment and SORN trigger check.
[COMMUNITY] Determine whether an AI system is rights-impacting or safety-impacting under OMB M-24-10 and document the minimum risk-management practices, M-25-21 acquisition controls, and public disclosure obligations.
[COMMUNITY] Draft a FedRAMP System Security Plan (Moderate / High baseline) aligned to the current FedRAMP SSP template structure — system identification, boundary, types of users, interconnections, control implementations, continuous monitoring.
[COMMUNITY] Generate a Critical Third Parties (CTP) dependency assessment — register of designated CTPs the firm relies on (cloud hyperscalers, payment networks, BaaS providers), materiality assessment per provider, resilience testing plan including exit and substitution drills (BoE/PRA/FCA PS24/16).
Create strategic Wardley Maps for architecture decisions and build vs buy analysis
[COMMUNITY] Produce an EO 14028 secure-software self-attestation (per OMB M-22-18 / M-23-16) and an accompanying Software Bill of Materials (SBOM) conforming to NTIA Minimum Elements in CycloneDX or SPDX format.
[COMMUNITY] Tailor the NIST SP 800-53 Rev 5 control catalog against the Low / Moderate / High baseline for a US federal information system, recording implementation status, inheritance from cloud providers, parameter assignments, and compensating controls.
[COMMUNITY] Generate an FCA Consumer Duty annual Board Report — customer outcomes evidence pack across the four outcomes (Products & Services, Price & Value, Consumer Understanding, Consumer Support), price & value assessment, target market assessment, fair-value framework.
[COMMUNITY] Generate a UK PSD2 SCA-RTS exemption design document — exemption applicability matrix, transaction risk analysis (TRA) thresholds, fraud monitoring framework, and per-exemption decision rationale.
[COMMUNITY] Determine medical-device classification for software-as-medical-device (SaMD) or AI-as-medical-device (AIaMD) under UK MDR 2002 (as amended) and EU MDR 2017/745, including UKCA / UKNI / CE marking pathway and Windsor Framework NI handling.
[COMMUNITY] Generate an EMI / PI safeguarding assessment — method statement (segregation vs insurance vs guarantee), designated safeguarding bank/insurance arrangements, reconciliation cadence + sign-off chain, end-to-end client-funds flow, audit plan aligned to FCA REP-CRIM expectations.
[COMMUNITY] Conduct a NIST AI Risk Management Framework 1.0 assessment (Govern / Map / Measure / Manage) of an AI system, including the Generative AI Profile (NIST AI 600-1) where applicable.
Generate prioritised product backlog from ArcKit artifacts - convert requirements to user stories, organise into sprints
[COMMUNITY] Generate FIPS 199 system categorization (Low/Moderate/High water-mark) for a US federal civilian information system, mapping information types to NIST SP 800-60 Vol 2 and recording the CIA impact matrix.
Analyze G-Cloud service gaps and generate supplier clarification questions
Generate a Technology Code of Practice (TCoP) review document for a UK Government technology project
Generate a consolidated project glossary of terms, acronyms, and definitions from existing artifacts
Generate MOD JSP 936 AI assurance documentation for defence AI/ML systems
Analyze stakeholder drivers, goals, and measurable outcomes
Research AWS services and architecture patterns using AWS Knowledge MCP for authoritative guidance
Discover external data sources (APIs, datasets, open data portals) to fulfil project requirements
Synthesise strategic artifacts into executive-level Architecture Strategy document
Find G-Cloud services on UK Digital Marketplace with live search and comparison
Create or update enterprise architecture principles
Generate MARP presentation slides from existing project artifacts for governance boards and stakeholder briefings
Generate Digital Outcomes and Specialists (DOS) procurement documentation for UK Digital Marketplace
Generate requirements traceability matrix from requirements to design to tests
Assess UK Government AI Playbook compliance for responsible AI deployment
Document architectural decisions with options analysis and traceability
Create comprehensive data model with entity relationships, GDPR compliance, and data governance
Generate architecture diagrams using Mermaid or PlantUML C4 for visual documentation
Review Detailed Design (DLD) for implementation readiness
Create vendor evaluation framework and score vendor proposals
Research Google Cloud services and architecture patterns using Google Developer Knowledge MCP for authoritative guidance
Discover reusable UK government code before building from scratch
Create comprehensive business and technical requirements
Create strategic architecture roadmap with multi-year timeline, capability evolution, and governance
Generate Statement of Work (SOW) / RFP document for vendor procurement
Assess organizational doctrine maturity using Wardley's 4-phase framework
Decompose user needs into value chains for Wardley Mapping
Generate Algorithmic Transparency Recording Standard (ATRS) record for AI/algorithmic tools
Perform comprehensive governance quality analysis across architecture artifacts (requirements, principles, designs, assessments)
Create federated data product contracts for mesh architectures with SLAs, governance, and interoperability guarantees (project)
Generate Yourdon-DeMarco Data Flow Diagrams (DFDs) with structured analysis notation
Search 24,500+ UK government repositories using natural language queries
Review High-Level Design (HLD) against architecture principles and requirements
Generate a MOD Secure by Design assessment for UK Ministry of Defence projects using CAAT and continuous assurance
Generate a capability maturity model with assessment criteria and level definitions
Generate a Secure by Design assessment for UK Government projects (civilian departments)
Create comprehensive ServiceNow service design with CMDB, SLAs, incident management, and change control
Assess climatic patterns affecting Wardley Map components
Create project plan with timeline, phases, gates, and Mermaid diagrams
Analyze strategic play options from Wardley Maps using 60+ gameplay patterns
Research Azure services and architecture patterns using Microsoft Learn MCP for authoritative guidance
Transform existing project artifacts into a structured, phased framework with overview and executive guide
[COMMUNITY] Generate a National Priorities Alignment Statement under the UAE Federal Government Guide. Captures reuse-vs-build justification, capability-reuse register (UAE Pass, FedNet), and strategy alignment to NIS 2031 / AI 2031 / Digital Economy Strategy / We the UAE 2031.
This skill should be used when the user is starting an architecture project or asking what to run next. Load whenever the task sounds like 'I'm starting a new project', 'guide me through', 'what command should I run', 'what comes next', 'how do I begin', 'help me get started', 'which $arckit-* in what order', 'set up a new project', 'new system build', or 'where do I start'. Recommends a tailored command sequence based on sector, project type, current stage, and timeline.
This skill should be used when the user asks about PlantUML syntax for C4-PlantUML, sequence, class, activity, state, ER, component, deployment, or use case diagrams, rendering errors, layout conflicts, skinparams, or themes.
This skill should be used when the user asks about Mermaid diagram syntax, how to write flowchart, sequence, class, state, ER, Gantt, C4, mindmap, timeline, or other diagram types, node shapes, styling, theming, or rendering errors.
Copy plugin templates to project for customization
[COMMUNITY] Generate an ITSG-33 Statement of Applicability with TBS Standard on Security Categorization — Protected A/B/C, Secret, Top Secret tailoring, control profile selection (PBMM / PBMM-Cloud / Secret-High), CMVP / FIPS 140-3 module validation, supply chain security, and continuous monitoring plan.
[COMMUNITY] Generate a Canada ATIP reconciliation — Access to Information Act exemption mapping, Privacy Act §4–§8 use/disclosure register, severance design for hybrid public/protected systems, ATIP request workflow.
[COMMUNITY] Generate a Canada FITAA (Foreign Influence Transparency and Accountability Act, Bill C-70 2024) compliance assessment — activity scoping, arrangement register design, public vs protected views, Commissioner liaison protocol, Charter §2 risk register.
[COMMUNITY] Generate a Canada sovereign cloud residency assessment — GC Cloud Adoption Strategy alignment, Direction on the Secure Use of Commercial Cloud Services, residency at Protected B+, sovereign options matrix (AWS Canada, Azure Canada Central/East, GCP Canada), CLOUD Act foreign-access analysis, exit and portability plan.
[COMMUNITY] Assess Diffusion Restreinte (DR) handling compliance — marking, storage, transmission, and destruction rules for French administrative sensitive information
[COMMUNITY] Generate a Canada Charter rights design review — s.2 (expression and association), s.7 (life, liberty, security of person), s.8 (search and seizure), s.15 (equality) — applying Oakes proportionality framing to system design with mitigation tracker and DOJ counsel sign-off block.
Create FinOps strategy with cloud cost management, optimization, governance, and forecasting
[COMMUNITY] Assess EU Cyber Resilience Act (CRA, Regulation 2024/2847) compliance obligations for products with digital elements placed on the EU market
[COMMUNITY] Assess SecNumCloud 3.2 qualification compliance for French sovereign cloud procurement and OIV/OSE obligations
Create DevOps strategy with CI/CD pipelines, IaC, container orchestration, and developer experience
[COMMUNITY] Assess Austrian NISG obligations (BGBl. I Nr. 94/2025) — AT transposition of NIS2, BKA (GovCERT) / BMI (SPOC) reporting, KSÖ coordination, and Austrian sectoral rules for Essential/Important entities
[COMMUNITY] Assess Austrian DSG / DSGVO obligations — Datenschutzbehörde patterns, §§12–13 DSG special provisions, image processing (§12 DSG), and Austrian enforcement practice
[COMMUNITY] Assess EU AI Act (Regulation 2024/1689) compliance obligations, risk classification, and conformity requirements for AI systems
Generate comprehensive project story with timeline analysis, traceability, and governance achievements (project)
Assess compliance with architecture principles and generate scorecard with evidence, gaps, and recommendations
Create platform strategy using Platform Design Toolkit (8 canvases for multi-sided ecosystems)
Generate Data Protection Impact Assessment (DPIA) for UK GDPR Article 35 compliance
[COMMUNITY] Generate an Official Languages Act review — Parts IV (services), V (language of work), VI (federal language obligations); service-equivalence matrix EN/FR; bilingual public-facing surface; active offer; Translation Bureau pipeline; OQLF acknowledgement where federal-Quebec overlap applies.
[COMMUNITY] Generate a Canada Security of Information Act handling plan — Special Operational Information (SOI) register, marking and handling matrix, transmission channels, compartments and need-to-know, destruction and sanitisation, CSIS Act §16 and §19 coordination, RCMP NSP liaison, breach response, personnel reliability prerequisites.
[COMMUNITY] Generate UAE Pass integration design (OIDC/OAuth flow, claim mapping, Basic vs Verified profile selection, Service Provider onboarding pack, e-signature audit trail design).
[COMMUNITY] Generate a public algorithm transparency notice complying with Article L311-3-1 CRPA (Loi République Numérique) for French public administration algorithmic decisions
[COMMUNITY] Assess EU Data Act (Regulation 2023/2854) compliance for connected products, data holders, and data processing service providers
[COMMUNITY] Generate a Government of Canada Digital Standards conformance scorecard against the 10 standards — evidence per standard, gap remediation plan, and maturity roadmap.
Research UK government grants, charitable funding, and accelerator programmes with eligibility scoring
[COMMUNITY] Assess NIS2 Directive compliance obligations for EU member state operators of essential services and important entities
[COMMUNITY] Assess EU Digital Services Act (DSA, Regulation 2022/2065) compliance obligations for online intermediary services, platforms, and very large online platforms
[COMMUNITY] Generate a Canada Privacy Impact Assessment per the Privacy Act and TBS Directive on Privacy Impact Assessment — personal-information inventory, lawful authority, necessity and proportionality, OPC notification trigger, and mitigation tracker.
Assess architecture conformance — ADR decision implementation, cross-decision consistency, design-principles alignment, architecture drift, technical debt, and custom constraint rules
[COMMUNITY] Generate a First Nations OCAP® (Ownership, Control, Access, Possession) sovereignty assessment — FNIGC pre-engagement gate, per-dataset OCAP mapping, USAI and ITK considerations, repatriation and co-governance plan. Not a substitute for direct FNIGC and community engagement.
[COMMUNITY] Generate a Canada Algorithmic Impact Assessment per the TBS Directive on Automated Decision-Making — Levels I–IV questionnaire scoring across the six dimensions, transparency notice, peer review trigger, human-in-the-loop design, recourse mechanism.
[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway
[COMMUNITY] Generate GDPR (EU 2016/679) compliance assessment for EU/EEA data processing — legal basis mapping, data subject rights, transfers, DPIA screening, and breach notification across all member states
[COMMUNITY] Generate a federal Canadian procurement strategy — PSPC Supply Manual route selection, Standing Offer / AgileIQ / RFP analysis, Procurement Strategy for Indigenous Business (PSAB 5%), CFTA/CETA threshold mapping, security-clearance prerequisites and lead times.
[COMMUNITY] Assess compliance with ANSSI security recommendations — Guide d'hygiène informatique (42 measures) and cloud security recommendations
[COMMUNITY] Produce an ANSSI-methodology information system cartography across four reading levels — business, application, system, and network
[COMMUNITY] Assess DORA (Digital Operational Resilience Act, EU 2022/2554) compliance for financial sector entities operating in the EU
[COMMUNITY] Generate French public procurement documentation aligned with code de la commande publique, UGAP catalogue, and DINUM digital standards
[COMMUNITY] Conduct an EBIOS Risk Manager risk analysis study following the ANSSI methodology — five workshops from study framing to risk treatment and homologation recommendation
[COMMUNITY] Structure an IRN (Indice de Résilience Numérique) self-assessment following the aDRI framework — 8 resilience pillars × 5 organisational layers, with scoring scaffold and handoff to official aDRI methodology
[COMMUNITY] Assess public code reuse opportunities before building from scratch — search code.gouv.fr, the SILL, and European public code repositories; produce a build-vs-reuse decision matrix
[COMMUNITY] Assess CNIL-specific GDPR obligations for French deployments — cookies, health data (HDS), minors, délibérations CNIL, and French enforcement patterns
[COMMUNITY] Assess compliance with French digital administration standards — RGI, RGAA, RGESN, RGS, and DINUM doctrine cloud de l'État
[COMMUNITY] Generate an Information System Security Policy (PSSI) for French public or private organisations — security objectives, principles, organisational structure, and applicable ANSSI/RGS standards
Governance metrics dashboard — coverage by category, cross-reference density, compliance readiness, and project comparison across all working projects
Analyse the blast radius of a change to a requirement, decision, or design document
Create MLOps strategy with model lifecycle, training pipelines, serving, monitoring, and governance
Create operational readiness pack with support model, runbooks, DR/BCP, on-call, and handover documentation
[COMMUNITY] Generate a three-tier AI autonomy posture (Tier 1 internal-productivity, Tier 2 investor-facing-with-approval, Tier 3 regulated/financial). Captures per-tier guard-rails, approval gates, audit obligations, and tier-promotion criteria.
Generate documentation site with governance dashboard, document viewer, and Mermaid diagram support
[COMMUNITY] Generate a UAE Charter for AI compliance assessment against the 12 principles (human-machine ties, safety, bias mitigation, data privacy, transparency, human oversight, governance/accountability, technological excellence, human commitment, peaceful coexistence, inclusive access, lawful compliance).
[COMMUNITY] Generate a Data Sharing Agreement under the UAE Government Services Data Sharing Policy. Captures collect-once mapping, federation/API plan, and PDPL lawful basis per share.
[COMMUNITY] Generate a UAE Smart Data Classification Register for a project, mapping every dataset to Open / Shared / Confidential / Secret / Top Secret with handling rules and declassification schedule. Anchored on the UAE Smart Data Framework.
[COMMUNITY] Assess sovereign cloud residency under the UAE National Cloud Security Policy v2. Validates per-classification residency, names approved CSP options (Core42 / G42 sovereign / Microsoft UAE North + Central, TDRA FedNet, e& Sovereign Launchpad on AWS), and captures shared-responsibility matrix and exit/portability plan.
[COMMUNITY] Generate a Digital Records Plan under the UAE Government Services Digital Records Policy. Captures the source-of-truth register per service, retention schedule, and records-as-official-source designation.
[COMMUNITY] Generate a federal procurement strategy under UAE Federal Decree-Law 11/2023. Produces ITT/RFP packs against the MoF Digital Procurement Platform templates, In-Country Value (ICV) plan, evaluation report structure, and contract register.
[COMMUNITY] Generate a UAE PDPL (Federal Decree-Law 45/2021) compliance assessment including DPIA, lawful-basis register, data-subject-rights procedure, and cross-border transfer log. Anchored on the UAE Data Office statutory framework.
[COMMUNITY] Generate a Service Catalogue review under the UAE Code for Government Services and Zero Bureaucracy. Captures service catalogue mapping, bureaucracy-elimination baseline, and customer-experience KPIs.
[COMMUNITY] Generate a UAE IAS Statement of Applicability against the 188 controls (60 management M1–M6 + 128 technical T1–T9), priority-tiered P1–P4. Anchored on the UAE Cybersecurity Council Information Assurance Standard v2.
Project-level GPS — show coverage against the essential ArcKit baseline, surface DRAFT/stale/orphan artifacts, and recommend the next slash command to run
Analyze strategic play options from Wardley Maps using 60+ gameplay patterns
Initialize ArcKit project structure for enterprise architecture governance
Get oriented with ArcKit — guided project onboarding, workflow selection, and command recommendations
Decompose user needs into value chains for Wardley Mapping
Assess climatic patterns affecting Wardley Map components
Export product backlog to Trello - create board, lists, cards with labels and checklists from backlog JSON
Assess organizational doctrine maturity using Wardley's 4-phase framework
Search across all project artifacts by keyword, document type, or requirement ID