Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ThomasMoreAI/legal-skills-open --skill arckit-ca-fitaagit clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-openWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/thomasmoreai/legal-skills-open/arckit-ca-fitaa)<a href="https://agentmods.dev/skills/thomasmoreai/legal-skills-open/arckit-ca-fitaa"><img src="https://agentmods.dev/badge/skills/thomasmoreai/legal-skills-open/arckit-ca-fitaa/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/thomasmoreai/legal-skills-open/arckit-ca-fitaa"><img src="https://agentmods.dev/badge/skills/thomasmoreai/legal-skills-open/arckit-ca-fitaa.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00058 | $0.01481 |
| Opus 5 | $0.00029 | $0.00740 |
| Sonnet 5 | $0.00012 | $0.00296 |
| Haiku 4.5 | $0.00006 | $0.00148 |
Grade A, and why
arckit-ca-fitaa scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 80 lines — stays where its author put it; the contents beside it link to each section on GitHub.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified Canadian counsel, your departmental ATIP coordinator, ITSEC officer, and (for FITAA matters) the Office of the Commissioner of Foreign Influence Transparency before reliance.
Statutory currency: FITAA was enacted June 2024 with regulations still emerging through 2025–2026. The Commissioner's office is newly stood up and operational guidance will evolve. Verify all citations against the current Justice Laws Website text and Commissioner's published guidance before relying on this output.
User Request
$ARGUMENTS
You are an enterprise architect generating a Canada FITAA Compliance Assessment for a federal entity.
Process
- Read prerequisites:
projects/000-global/ARC-000-PRIN-*.md(federal principles, if present)- The project's REQ, STKE, DR, and DMOD artefacts (if present)
.arckit/templates/_partials/RENDERING.md
- Read the template:
- First, check
.arckit/templates-custom/ca-fitaa-template.md(user override) - Then,
.arckit/templates-custom/ca-fitaa-template.md - Fallback,
.arckit/templates/ca-fitaa-template.md
- First, check
- Use
scripts/bash/generate-document-id.sh <PROJECT_ID> FITAA --filenamefor the artefact filename. - Resolve the
<!-- DOC-CONTROL-HEADER -->marker perRENDERING.md. Use the Canadian classification scheme (UNCLASSIFIED / Protected A / Protected B / Protected C / CONFIDENTIAL / SECRET / TOP SECRET) — replace the standard UK line in the header. - Generate the following sections (the template provides skeletons for each):
- Activity Scoping — statutory triggers (covered arrangements with foreign principals to influence government / political processes / public discourse), excluded categories (journalism, academic research subject to standard exemptions), and a decision tree mapping the project's specific activities. Cite specific FITAA provisions where statute numbering is settled; mark as
<TBC at draft time>where regulations are still pending. - Arrangement Register Design — data fields per registration (registrant identity, foreign principal, activity type, start/end dates, financial flows where required), public-facing fields (transparency objective), protected fields (national-security exemptions), and the 14-day update cadence for material changes.
- Registration Workflow — submission channel (web / paper / both — bilingual per
ca-ola), identity verification approach, acknowledgement and registration ID issuance, material-change update flow. - Public Register vs Protected Investigative Data — data flow diagram (textual or Mermaid), severance rules (cross-reference
ca-atip), withdrawal/correction process. - Commissioner Liaison Protocol — interface with the Office of the Commissioner of Foreign Influence Transparency, reporting cadence (suspected non-registration, suspected falsification), RCMP / CSIS coordination touchpoints (cross-reference
ca-soia). - Charter Risk Register (cross-reference
ca-charter) — s.2(b) freedom of expression chilling-effect mitigations, s.2(d) freedom of association proportionality analysis, mitigation tracker. - Compliance Schedule (registrant-side) — arrangement triggers, the 14-day clock, penalty exposures (cite specific FITAA offence sections where settled; otherwise
<TBC>). - Open Items — explicit list of statutory currency caveats: which regulations may post-date the artefact, which guidance from the Commissioner is still pending.
- Activity Scoping — statutory triggers (covered arrangements with foreign principals to influence government / political processes / public discourse), excluded categories (journalism, academic research subject to standard exemptions), and a decision tree mapping the project's specific activities. Cite specific FITAA provisions where statute numbering is settled; mark as
- Populate the External References section per
.arckit/references/citation-instructions.md. The Foreign Influence Transparency and Accountability Act (Bill C-70, 2024) MUST appear in the Document Register with its primary URL (Justice Laws Website) and the verification date. - Write the artefact via the Write tool to
projects/<project-id>/<filename>. - Show only a summary to the user (one paragraph plus the headline Charter §2 risk findings and any open statutory-currency items).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 80 lines · 58 tokens per session scan A 8a6612a938fa
arckit-ca-fitaa is a skill published in the GitHub repository ThomasMoreAI/legal-skills-open (72 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 58 tokens to every session and 1,481 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
pia-generator
Generate structured privacy impact assessments so Claude can organize project privacy risks, controls, and decision points into a review-ready report.
audit-scope-checklist
Generate a scoped IT audit program with controls mapped to roles and compliance frameworks. Use this skill for audit planning, control checklist generation, and auditprogram.json creation.
compliance-checker
Compare system configuration evidence against common control frameworks and produce a concise compliance assessment with gaps and remediation priorities.
compliance-controls-playbook
Guide Claude through a structured compliance audit workflow covering framework selection, evidence planning, control testing, exception handling, and reporting.
evidence-tracker
Manage audit evidence requests, collection progress, and status reporting so Claude can keep audits organized and identify overdue or blocked evidence items.
consent-checker
Review privacy policy or notice text against common privacy frameworks so Claude can explain coverage gaps, strengths, and compliance priorities.