skills/legal/itar-technology-control-plan/SKILL.md
Drafts an ITAR Technology Control Plan (TCP) for U.S. export control compliance under 22 CFR 120-130. Use when a user needs to create or update a TCP, export control program, or deemed-export compliance plan. Trigger on mentions of ITAR, TCP, DDTC, USML, deemed export, technical data, or defense article in a compliance-planning context.
npx skillsauth add casemark/skills itar-technology-control-planInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces an organization-specific, auditable TCP covering USML scoping, technical data controls, U.S. person screening, deemed-export safeguards, cybersecurity, training, audits, and incident response.
Collect before drafting:
| # | Section | Key Content | |---|---------|-------------| | 1 | Purpose & Authority | TCP applicability; cite ITAR 22 CFR 120-130 [VERIFY]. | | 2 | Definitions | Defense article, technical data, export, U.S. person, deemed export — with citations [VERIFY]. | | 3 | Scope | Programs/contracts, USML categories (22 CFR 121.1) [VERIFY], facilities, remote-work boundaries. | | 4 | Roles & Governance | Empowered official, compliance officer, IT/security, HR, program owners. | | 5 | Classification & Inventory | USML mapping, CJ workflow (22 CFR 120.4) [VERIFY], marking, version control. | | 6 | Access Controls | U.S. person verification, badge logic, visitor escorts, need-to-know. | | 7 | IT & Cybersecurity | Segmentation, MFA, encryption, logging, device/media restrictions. | | 8 | Handling & Transmission | Storage rules, secure transfer, travel, remote-access constraints. | | 9 | Training | Initial + annual; role-based modules; completion records. | | 10 | Audits & Monitoring | Annual audits, trigger-based reviews, corrective actions. | | 11 | Incident Response | Containment, investigation, voluntary disclosure (22 CFR 127.12) [VERIFY]. | | 12 | Records & Retention | 5-year retention (22 CFR 122.5) [VERIFY]; record types, custody. | | 13 | Revision Control | Versioning, approvals, distribution, acknowledgment. | | — | Appendices | Forms, checklists, logs, access roster, facility maps. |
| Role | Key TCP Duties | |------|---------------| | Empowered Official | Approves TCP; oversees disclosures and licensing. | | Export Compliance Officer | Maintains TCP; coordinates audits/training; classification oversight. | | IT/Security | Implements segmentation, logging, encryption. | | HR | U.S. person verification; onboarding/offboarding workflow. | | Program Manager | Enforces scope, need-to-know, reporting. |
| Audience | Frequency | Topics | |----------|-----------|--------| | All with access | Initial + annual | ITAR basics, deemed export, TCP rules, reporting. | | Empowered Official | Annual + updates | Licensing, disclosures, penalties. | | IT/Security | Annual + updates | Segmentation, logging, incident response. | | HR | Annual + updates | U.S. person screening, onboarding/offboarding. |
| Record Type | Retention | Owner | |-------------|-----------|-------| | Licenses/agreements | 5 yrs from expiration/export [VERIFY] | Compliance | | CJ requests/determinations | 5 yrs [VERIFY] | Compliance | | Access/visitor logs | 5 yrs [VERIFY] | Security | | Training records | 5 yrs [VERIFY] | HR/Compliance |
| Asset ID | Type | USML Cat | Location/System | Owner | Classification Date | Marking Applied | |----------|------|----------|-----------------|-------|---------------------|-----------------|
Standard marking: ITAR CONTROLLED — Export of this information to foreign persons is prohibited without authorization from the U.S. Department of State.
Key changes from the original:
tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.