skills/legal/itar-tcp/SKILL.md
Drafts ITAR Technology Control Plans (TCPs) for managing USML defense articles and technical data under 22 CFR Parts 120-130. Covers DDTC registration, classification, access controls, deemed export prevention, secure handling, training, audits, and incident response. Use when creating or updating export control compliance plans, technology control plans, or DDTC submission documents.
npx skillsauth add casemark/skills itar-tcpInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Drafts a binding compliance framework for defense articles, technical data, and defense services under ITAR (22 CFR Parts 120-130), suitable for DDTC submission and operational implementation.
Gather before drafting:
Also extract: facility layouts, foreign national employee records (triggers deemed export analysis), existing policies, CJ determinations from contract SOWs.
[VERIFY]Draft these 10 sections in order:
[VERIFY current amount], criminal imprisonment under AECA, debarmentClassification process:
Inventory tracks: hardware (components, assemblies, USML class), technical documents (drawings, specs — version-controlled), software/source code, manufacturing processes, test data.
Marking: All controlled items must bear: "ITAR CONTROLLED — Export of this information to foreign persons is prohibited without prior approval from the U.S. Department of State."
U.S. Person (§120.62): U.S. citizens, lawful permanent residents (I-551), persons granted asylum/refugee/TPS. Excludes all other foreign nationals regardless of visa. Verify original documentation before granting access.
Physical controls: badge-restricted areas for verified U.S. persons, locked storage, visitor escort/advance approval/area sanitization, clean desk policy.
Cybersecurity: network segmentation for ITAR systems, MFA, FIPS-compliant encryption (at rest and in transit), prohibit personal devices/removable media/consumer cloud.
Deemed export (§120.54): Release to foreign person in U.S. = export to their nationality country. Sanitize workspaces when foreign persons present. Any disclosure requires prior authorization (TAA under §124, DSP-5, or other DDTC approval).
Initial — required before any controlled material access. Refresher — annually minimum.
Core topics (all personnel): ITAR fundamentals, defense article/data identification, deemed export rules, TCP responsibilities, violation consequences, reporting procedures.
Role-specific additions: empowered official (§120.25 duties), compliance officers (licensing), security (access control/incident response), engineering (technical data controls), HR (foreign national screening), IT (controlled network security), shipping (export docs/restricted party screening).
Document: attendance records, signed acknowledgments, competency assessments.
Annual audit scope:
Triggered audits: org changes, new programs/USML categories, incidents, regulatory changes.
KPIs: incident count/severity trends, finding closure timeliness, training completion rates, verification currency, license renewal timeliness.
Reportable: unauthorized foreign person access, inadvertent exports/deemed exports, missing controlled items, ITAR system breaches, unmarked data in unrestricted areas.
Response sequence:
Coordinate VSD between empowered official and legal counsel; submit promptly for maximum mitigation.
[VERIFY] against current CFRKey changes from the original:
tags from frontmatter (not part of the spec's required fields)tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.