Use this skill when the user wants an AI governance, legal-risk, privacy, compliance, procurement, or vendor-risk review of an internal AI use case, an AI product feature, an LLM workflow, or a third-party AI vendor. The skill asks intake and clarifying questions first when facts or evidence are missing, identifies required documentation and missing evidence, maps the use case to AI governance frameworks and applicable legal domains, and produces a preliminary or final governance review with scorecards, findings, owners, remediation actions, and follow-up questions.
npx skills add https://github.com/lawve-ai/awesome-legal-skills --skill ai-governance-reviewer-carl-ditzler
Use this skill for draft AI governance reviews involving:
This skill supports governance, privacy, security, procurement, and legal preparation. It does not provide legal advice.
*LEGAL DISCLAIMER*
Always include this disclaimer in the response:
> This review assists with AI governance processes and does not replace a formal AI Governance, legal review or professional legal representation. This output is a draft and may contain errors or omissions. Verify all conclusions against company policies, primary regulatory sources, and with appropriate internal legal, privacy, security, and compliance teams. This is not legal advice.
references/frameworks.md rather than relying on external URLs.references/frameworks.md.Use sources in this order:
references/official/ legal source filesreferences/working/ legal source filesreferences/frameworks.md, references/responsible-ai-practice.md, and the scenario filesDo not let a lower-priority source override a higher-priority one.
Intake first is mandatory. If key facts or material evidence are missing, the first response must ask questions rather than provide a report.Preliminary Review route after the model has already asked the required intake questions and evidence requests and the user:Classify the request as Internal AI Use, Product AI Integration, Third-Party AI Vendor, or Hybrid / Multiple. Load the matching scenario reference file.
Start by asking for the core intake facts. If the user has not already provided them clearly, ask for:
When information is missing, the first response should look like this:
Use direct question wording such as:
What is the use case?Who are the intended users?What is your organization's role?What model or vendor is involved?Do not present the first intake as a long prose paragraph or a dense mixed bullet list.
Do not ask the user to fill in a form, intake form, markdown table, evidence table, scorecard, matrix, or any other structured layout that requires editing the assistant's message.
Every missing item must be asked as an explicit question inside the message so the user can reply directly in plain text.
First-turn sequencing rule:
Core Use Case block.Data and Deployment.Oversight and Testing.Governance Documents and Status.Vendor and Contracting if still relevant.If relevant supporting files already exist, ask for uploads or links in the turn where they become relevant rather than front-loading every document request in the first turn.
See references/example-outputs.md for examples.
The skill should actively question the user and gather information before producing a review. Do not skip this questioning step when material facts are missing.
If the use case is incomplete, the next response should be a short question block for the current topic only and nothing more substantial.
Use the following mandatory clarifying topics where relevant:
System OverviewOrganization RoleModel InformationData Sources and Data TypesDeploymentOversightTesting and MonitoringAI Impact AssessmentPrivacy and Data ProtectionTransparency and User AwarenessAssurance and OperationsBefore any final scorecard, determine:
If the facts are incomplete, ask targeted questions before concluding. Prioritize the gaps that block classification, legal mapping, evidence assessment, or residual-risk analysis.
Batch questions sensibly:
There is no hard maximum question count.
If additional follow-up questions are needed to proceed, then ask them explicitly as questions, rather than dropping them, compressing them into a table, or omitting them.
Topic blocks may include:
Core Use CaseData and DeploymentOversight and TestingGovernance Documents and StatusVendor and ContractingIf evidence is missing, ask for it now before generating a response, report, findings, or AI governance review.
Examples of missing evidence to request before drafting:
When requesting these items, ask the user to provide them by file upload or link and to state whether each item is completed, in progress, not started, or unknown.
Do this in the Governance Documents and Status turn, not in the first intake turn unless the user already asked about document readiness.
If the user cannot provide the evidence after being asked, state that the review will remain preliminary and use Unknown where needed.
Assess the use case across:
Preliminary Review as the first fallback when information is missing.Preliminary Review with Unknown entries instead of a final review.Escalate strongly for legal, privacy, security, or executive review when the use case involves:
references/working/*.md file and a bundled references/official/*.pdf file exist for the same framework, use the working Markdown file for search and drafting efficiency, but treat the official PDF as controlling if there is any mismatch in wording, numbering, or scope.Do not issue a final approval, go-live recommendation, or high-confidence low-risk conclusion unless all of the following are addressed:
Preliminary Review until after the intake-first step has happened and the user cannot or will not provide more information.Final Review only when the output gate is satisfied.Unknown rather than guessing.High confidence when critical facts, testing evidence, approvals, or documentation are missing.Integration with protocols.io API for managing scientific protocols. This skill should be used when working with protocols.io to search, create, update, or publish protocols; manage protocol steps and materials; handle discussions and comments; organize workspaces; upload and manage files; or integrate protocols.io functionality into workflows. Applicable for protocol discovery, collaborative protocol development, experiment tracking, lab protocol management, and scientific documentation.
Analyzes job descriptions and generates tailored resumes that highlight relevant experience, skills, and achievements to maximize interview chances
Generate Excalidraw diagrams from natural language descriptions. Use when asked to "create a diagram", "make a flowchart", "visualize a process", "draw a system architecture", "create a mind map", or "generate an Excalidraw file". Supports flowcharts, relationship diagrams, mind maps, and system architecture diagrams. Outputs .excalidraw JSON files that can be opened directly in Excalidraw.
Build and distribute Expo development clients locally or via TestFlight
Use when you have a written implementation plan to execute in a separate session with review checkpoints
Data structure for annotated matrices in single-cell analysis. Use when working with .h5ad files or integrating with the scverse ecosystem. This is the data format skill—for analysis workflows use scanpy; for probabilistic models use scvi-tools; for population-scale queries use cellxgene-census.
Benchling R&D platform integration. Access registry (DNA, proteins), inventory, ELN entries, workflows via API, build Benchling Apps, query Data Warehouse, for lab data management automation.
Comprehensive molecular biology toolkit. Use for sequence manipulation, file parsing (FASTA/GenBank/PDB), phylogenetics, and programmatic NCBI/PubMed access (Bio.Entrez). Best for batch processing, custom bioinformatics pipelines, BLAST automation. For quick lookups use gget; for multi-service integration use bioservices.
Take lawve-ai/ai-governance-reviewer-carl-ditzler from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.