Best for
- Produce a structured, attorney-ready intake record for a proposed or in-flight AI/ML use case. The record captures the information legal and compliance teams need to triage, route, and assess the use case — it does not…
zgbrenner/agentcounsel/skills/ai-governance/ai-use-case-intake/SKILL.md
Use when a new or modified AI/ML use case needs to be documented and triaged so legal, compliance, and governance teams can assess risk and route it to the right specialists.
Decision brief
Use when a new or modified AI/ML use case needs to be documented and triaged so legal, compliance, and governance teams can assess risk and route it to the right specialists.
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/zgbrenner/agentcounsel --skill "skills/ai-governance/ai-use-case-intake"Inspect the Agent Skill "AI Use Case Intake" from https://github.com/zgbrenner/agentcounsel/blob/b036d17a23125d51b9714a736481865a87eee226/skills/ai-governance/ai-use-case-intake/SKILL.md at commit b036d17a23125d51b9714a736481865a87eee226. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
1. Confirm inputs. Verify all required inputs are present. If any are missing, stop and request them by name before proceeding.
[ ] All required inputs have been provided and are accurate; nothing has been assumed or fabricated.
Produce a structured, attorney-ready intake record for a proposed or in-flight AI/ML use case. The record captures the information legal and compliance teams need to triage, route, and assess the use case — it does not render a legal conclusion about lawfulness or compliance. Th…
A product, engineering, or business team is proposing a new AI or ML feature, product, or workflow and needs legal sign-off or triage.
If any required input is missing, stop and request it from the requester. Do not fabricate or assume facts about the system, data, or affected individuals.
Permission review
No configured static risk pattern was detected
This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.
Evidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 91/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 17 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Produce a structured, attorney-ready intake record for a proposed or in-flight AI/ML use case. The record captures the information legal and compliance teams need to triage, route, and assess the use case — it does not render a legal conclusion about lawfulness or compliance. The preliminary risk tier is a triage signal only.
If any required input is missing, stop and request it from the requester. Do not fabricate or assume facts about the system, data, or affected individuals.
ai-vendor-terms-review for that.model-risk-triage.employee-ai-policy.core/source-and-citation-discipline.md. Never invent legal authority, citations, quotations, statutes, cases, regulations, filing deadlines, or procedural rules. Label what is a provided source, a user-provided fact, an assumption, a legal inference, or an item requiring attorney verification, and use a citation placeholder such as [Attorney to insert authority] when no source is available.[CONFIRM: ...] placeholders wherever information is uncertain, incomplete, or requires attorney or compliance verification.Confirm inputs. Verify all required inputs are present. If any are missing, stop and request them by name before proceeding.
Capture the business purpose. Summarize the use case in two to four sentences: what it does, why the organization wants it, and what decision or action it supports.
Document the AI system. Record the model(s), provider(s), API or platform, version or snapshot if known, and whether it is a foundation model, fine-tuned model, or custom-trained model.
Document input and training data. Record the data sources (internal, third-party, public), data types (text, images, audio, structured records), whether personal data is involved, any sensitive categories (health, financial, biometric, protected characteristics), and whether any of the data was or will be used to train or fine-tune the model. Flag any gaps in data provenance.
Document outputs and decision use. Record what the system outputs (scores, recommendations, generated text, classifications, etc.), whether outputs are used to make or inform consequential decisions about individuals, and what human review or override mechanisms exist.
Document affected persons. List all groups of people whose data is processed or who are affected by outputs. Note whether any are in protected categories (consumers, employees, minors, patients).
Document human oversight design. Describe the human-in-the-loop design: who reviews outputs, what decisions are fully automated vs. assisted, what escalation or appeal paths exist, and how errors are caught and corrected.
Document deployment markets. List every country, state, and region where the use case will operate or where affected individuals are located.
Document vendor involvement. List all third-party vendors, sub-processors, or API providers, and note which have signed data processing agreements or AI-specific terms.
Assign a preliminary risk tier. Using the information gathered, assign a triage risk tier — Low, Medium, or High — based on the following signals only (this is not a legal conclusion):
Identify routing recommendations. Based on the intake record, flag which specialist skills or teams should review the use case next (see Output Format below).
Assemble the intake record. Compile all sections into the structured output, label it as a draft for attorney review, and include all assumptions and open items.
Deliver the following sections in order:
1. Intake Summary A two-to-four sentence plain-language summary of the use case, system, and key risk signals.
2. Use Case Record
| Field | Detail |
|---|---|
| Business purpose | |
| AI system / model | |
| Provider / platform | |
| Model type | |
| Input data sources | |
| Personal data involved | Yes / No / [CONFIRM] |
| Sensitive data categories | |
| Training data use | [CONFIRM] if unknown |
| Output type | |
| Decision use | |
| Consequential decisions about individuals | Yes / No / [CONFIRM] |
| Human oversight design | |
| Affected persons | |
| Deployment markets | |
| Vendor involvement | |
| Data processing agreements in place | Yes / No / Partial / [CONFIRM] |
3. Preliminary Risk Tier State Low / Medium / High and list the two to five signals that drove the tier. Note that this is a triage signal only, not a legal conclusion.
4. Routing Recommendations Bullet list of recommended next steps and skill or team referrals, for example:
ai-vendor-terms-review — if vendor AI terms have not been reviewed.model-risk-triage — if the model's reliability, bias, or failure modes need deeper assessment.employee-ai-policy — if the use case involves employees using AI tools.5. Open Items and Assumptions
Bullet list of every [CONFIRM: ...] item and assumption recorded during the intake.
6. Attorney Triage Flag A single highlighted note: whether the intake record should be escalated to attorney review before the use case proceeds, and the primary reason.
Label the full document: DRAFT — For Attorney Review — Not Legal Advice.
When the output will be used to brief a non-lawyer business stakeholder — the requesting product owner, business sponsor, AI governance committee, founder, or executive — add a Business Stakeholder Summary as a clearly separated, plainly labeled section, following core/business-stakeholder-communication.md. Produce it only when the user requests it or when the audience is plainly a business decision-maker. It is an addition to the deliverable above — never a replacement for it, and never a substitute for attorney review. It contains:
[CONFIRM: ...] placeholders have been resolved before the use case proceeds.Alternatives
alirezarezvani/claude-skills
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist
wanshuiyin/Auto-claude-code-research-in-sleep
Use it for operations and research tasks; the detail page covers purpose, installation, and practical steps.
dotnet/skills
Migrates .NET test projects from VSTest to Microsoft.Testing.Platform (MTP). Use when user asks to "migrate to MTP", "switch from VSTest", "enable Microsoft.Testing.Platform", "use MTP runner", set OutputType=Exe only for test projects in Directory.Build.props, or mentions EnableMSTestRunner, EnableNUnitRunner, or UseMicrosoftTestingPlatformRunner. USE FOR: MTP behavioral differences vs VSTest (exit code 8, zero tests discovered, --ignore-exit-code, TESTINGPLATFORM_EXITCODE_IGNORE); centralizing
aaron-he-zhu/aaron-marketing-skills
Use when the user asks to "set up my founder social-selling routine", "build a daily engagement block for target accounts", or "turn funding / hiring signals into selling plays"; produces the founder/seller daily operating block — a time-boxed engagement-block spec (substantive value-add comments on target-account posts, never a pitch), warm-touch-before-ask cadence rules, trigger-response plays consuming the social-pulse-monitor B2B trigger watchlist (funding / hiring / launch signals), and a q