COMPLETE PLUGIN
View an example
Example installation for product-skills
Example session using the verified commands above.
This skill should be used when the user asks to "collect SOC 2 evidence", "build an evidence register", "prepare evidence for the auditor", "what artifacts do we need", "organize our control evidence", "respond to an auditor request list", or mentions evidence gathering, control artifacts, audit requests, screenshots, exports, or testing records for SOC 2.

Install the complete plugin to include its agents, hooks, commands, and runtime context.
Fastest path: hand this line to the coding agent doing the setup. It reads this page and installs the product-skills plugin, which ships this skill with everything it relies on.
Click anywhere on the prompt to copy.
Choose a runtime, then follow its setup steps. This installs the complete product-skills plugin.
COMPLETE PLUGIN
Example session using the verified commands above.
The portable SKILL.md on its own, without the plugin’s hooks, agents, commands, and companion skills. Use it only when you intentionally want the narrower path.
No required companion skills are declared.

Operational and runtime security agent. Use this agent when the user asks to "scan our dependencies for CVEs", "check for leaked secrets", "is this OWASP compliant", "audit our Vercel security posture", or "run a supply chain audit". Covers Vercel Security Dashboard triage, incident response, and SOC 2 technical control validation. Not for code-level audits (use code-auditor) or architectural review (use architecture-reviewer).

Expert in legal compliance, privacy regulations, terms of service, data protection, DPAs, SOC 2 readiness, and US crypto-law research for startup operations. Use this agent when the user asks for privacy policies, terms, data processing agreements, vendor security/legal review, SOC 2 work such as gap analysis, evidence preparation, policy drafting, trust center language, audit readiness, or crypto-law issues such as stablecoin issuance, the GENIUS Act, CLARITY/FIT21 status, token classification, Howey analysis, FinCEN/MSB or Travel Rule questions, exchange or ATS exposure, 1099-DA broker reporting, tokenized securities, UCC Article 8 / Article 12 mechanics, DAO liability, or digital-asset entity structuring. <example> Context: User needs SOC 2 readiness help user: "Can you run a SOC 2 gap analysis and tell me what controls we're missing?" assistant: "I'll use the legal agent to scope the review, map the control gaps, and frame the remediation work." <commentary> SOC 2 scoping and compliance framing should route here first, even if security-ops may join for technical validation. </commentary> </example> <example> Context: User needs auditor-facing documentation user: "Draft our access control policy and help organize the evidence for the auditor." assistant: "I'll use the legal agent to draft the policy and structure the evidence request." <commentary> Policy drafting and evidence organization are core legal/compliance workflows handled by Anthony with the SOC 2 skills. </commentary> </example> <example> Context: User is evaluating a stablecoin or digital-asset product user: "What licenses or registrations might apply if we help design or operate a payment stablecoin?" assistant: "I'll use the legal agent to frame the federal and state-law analysis, including GENIUS, FinCEN/MSB, and money-transmission issues." <commentary> Stablecoin issuance, payment rails, and crypto startup legal analysis should route to Anthony first because they require integrated securities, AML, sanctions, and entity-structure framing. </commentary> </example> <example> Context: User needs token classification or tokenized-securities analysis user: "Is this token a security, a commodity, or just software infrastructure?" assistant: "I'll use the legal agent to structure the Howey analysis, check current SEC/CFTC guidance, and identify the main unresolved points." <commentary> Token classification, exchange/ATS questions, tokenized securities, and DAO/entity issues are core legal-analysis work rather than generic research only. </commentary> </example>
Pass the canonical page to a teammate or keep it close for later.
This skill should be used when the user asks to "prepare for SOC 2", "run a SOC 2 gap analysis", "check our audit readiness", "map our controls", "what controls are missing", "review us for SOC 2 Type I", "review us for SOC 2 Type II", or mentions SOC 2, trust service criteria, control gaps, auditor prep, trust center readiness, or remediation planning.