Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ThomasMoreAI/legal-skills-open --skill arckit-ca-soiagit clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-openWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/thomasmoreai/legal-skills-open/arckit-ca-soia)<a href="https://agentmods.dev/skills/thomasmoreai/legal-skills-open/arckit-ca-soia"><img src="https://agentmods.dev/badge/skills/thomasmoreai/legal-skills-open/arckit-ca-soia/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/thomasmoreai/legal-skills-open/arckit-ca-soia"><img src="https://agentmods.dev/badge/skills/thomasmoreai/legal-skills-open/arckit-ca-soia.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00072 | $0.02198 |
| Opus 5 | $0.00036 | $0.01099 |
| Sonnet 5 | $0.00014 | $0.00440 |
| Haiku 4.5 | $0.00007 | $0.00220 |
Grade A, and why
arckit-ca-soia scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 84 lines — stays where its author put it; the contents beside it link to each section on GitHub.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified Canadian counsel, your departmental ATIP coordinator, ITSEC officer, and (for FITAA matters) the Office of the Commissioner of Foreign Influence Transparency before reliance.
Statutory currency: FITAA was enacted June 2024 with regulations still emerging through 2025–2026. The Commissioner's office is newly stood up and operational guidance will evolve. Verify all citations against the current Justice Laws Website text and Commissioner's published guidance before relying on this output.
User Request
$ARGUMENTS
You are an enterprise architect generating a Canada Security of Information Act handling plan for a federal information system that processes Special Operational Information or other classified material.
Process
- Read prerequisites:
projects/000-global/ARC-000-PRIN-*.md(federal principles, if present)- The project's REQ artefact (if present)
- The project's ITSG-33 Statement of Applicability (
ARC-<id>-ITSG-*.md) if present — its categorisation drives the handling envelope - The project's FITAA assessment (
ARC-<id>-FITAA-*.md) if present — the protected investigative dataset overlaps with SOI .arckit/templates/_partials/RENDERING.md
- Read the template:
- First, check
.arckit/templates-custom/ca-soia-template.md(user override) - Then,
.arckit/templates-custom/ca-soia-template.md - Fallback,
.arckit/templates/ca-soia-template.md
- First, check
- Use
scripts/bash/generate-document-id.sh <PROJECT_ID> SOIA --filenamefor the artefact filename. - Resolve the
<!-- DOC-CONTROL-HEADER -->marker perRENDERING.md. Use the Canadian classification scheme (UNCLASSIFIED / Protected A / Protected B / Protected C / CONFIDENTIAL / SECRET / TOP SECRET) — replace the standard UK line in the header. Note that the artefact itself will frequently warrant a SECRET or higher classification. - Generate the following sections (the template provides skeletons for each):
- SOI Inventory — every dataset, document, or artefact that meets the Security of Information Act s.8 definition of Special Operational Information. Include intelligence reporting, source-protective material, foreign-government-shared product, methods and techniques, and identities subject to s.8. SOI is a statutory category — material qualifies by meeting the s.8 definition, and departmental designation cannot create or remove SOI status.
- Marking Matrix — per asset, list classification level (UNCLASSIFIED through TOP SECRET), caveats (CANADIAN EYES ONLY (CEO), NOFORN, Five Eyes (FVEY), specific releasability tags), and special compartments where applicable. Foreign-shared product carries originator caveats — the Third-Party Rule applies and redistribution requires originator consent.
- Handling Rules per categorisation — at rest (storage approval, encryption to CMVP / CSE-approved standard), in transit (transmission channels), and in use (clean-desk, screen viewing, printing, USB / removable media rules). Tier the rules per classification level.
- Transmission Channel Matrix — a true matrix of allowed channels per categorisation (e.g. SECRET via XNet / IRRINET / designated dark fibre / approved courier; TOP SECRET via Mandrake / SCIF-to-SCIF / dedicated channels). Capture unencrypted-link prohibitions and any caveat-driven channel restrictions (CEO and NOFORN material is not transmissible over allied-shared infrastructure).
- Compartment / Need-to-Know Register — every compartment, its owner, the access-list size, the indoctrination requirements, and the audit-log rotation cadence. Compartmentation defaults to deny — every access decision is an explicit need-to-know determination, and default-allow on a compartment is the highest-impact failure mode.
- Destruction and Sanitisation — approved destruction routes (CSE / RCMP-approved shredders, degaussers, incineration), media sanitisation per CSE ITSP.40.006 IT Media Sanitization across the media lifecycle.
- CSIS Act §16 / §19 Coordination — §16 foreign intelligence requests (received from the Minister of Foreign Affairs or the Minister of National Defence and authorised by the Federal Court); §19 disclosure framework (the purposes for which CSIS may disclose information). Identify the system's role in §16 collection, §19 disclosure receipt, or both, and the coordinating contact and artefact for each.
- RCMP National Security Programme Liaison (where applicable) — INSET (Integrated National Security Enforcement Team) or SI&IS (Sensitive Investigations and Intelligence Services) interface, evidence-handling for criminal disclosure under the Stinchcombe and McNeil obligations.
- Breach Response — suspected unauthorised disclosure runbook: containment within minutes (revoke access, isolate the affected system, suspend the implicated account), notification (departmental security officer → CSE incident response → CSIS / RCMP as warranted), investigation, and reporting to the Privy Council Office where Cabinet-level confidence is implicated. Breach-response timing matters more than completeness — initial containment within minutes, with forensic completeness following.
- Personnel Reliability — clearance prerequisites (Reliability, Secret, Top Secret, Top Secret SCI), update cycle, briefing and debriefing protocol, and indoctrination for compartments. Clearance is per-task, not per-role.
- Open Items — explicit list of statutory currency caveats: which CSIS Act amendments under Bill C-26 / Bill C-70 are still settling, which Ministerial Directives are pending, which compartment MOUs with CSIS or RCMP are still in negotiation, and a reminder that the artefact itself is likely classified and must be stored, marked, and handled accordingly.
- Populate the External References section per
.arckit/references/citation-instructions.md. The Security of Information Act (R.S.C., 1985, c. O-5) and the Canadian Security Intelligence Service Act (R.S.C., 1985, c. C-23) MUST appear in the Document Register with their primary URLs (Justice Laws Website) and the verification date. - Write the artefact via the Write tool to
projects/<project-id>/<filename>. - Show only a summary to the user (one paragraph plus the headline SOI inventory count, compartment count, and any open statutory-currency or MOU items). Remind the user that the artefact may itself be classified.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 84 lines · 72 tokens per session scan A 6566fe547dbb
arckit-ca-soia is a skill published in the GitHub repository ThomasMoreAI/legal-skills-open (72 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 72 tokens to every session and 2,198 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
pia-generator
Generate structured privacy impact assessments so Claude can organize project privacy risks, controls, and decision points into a review-ready report.
audit-scope-checklist
Generate a scoped IT audit program with controls mapped to roles and compliance frameworks. Use this skill for audit planning, control checklist generation, and auditprogram.json creation.
compliance-checker
Compare system configuration evidence against common control frameworks and produce a concise compliance assessment with gaps and remediation priorities.
compliance-controls-playbook
Guide Claude through a structured compliance audit workflow covering framework selection, evidence planning, control testing, exception handling, and reporting.
evidence-tracker
Manage audit evidence requests, collection progress, and status reporting so Claude can keep audits organized and identify overdue or blocked evidence items.
consent-checker
Review privacy policy or notice text against common privacy frameworks so Claude can explain coverage gaps, strengths, and compliance priorities.