Communitygithub.com

SamuelChien/mega-skills-collection

/cs:ai-act-readiness <system> — EU AI Act 6-question forcing interrogation. Use during AI-system intake, before EU deployment, or during annual compliance refresh as Article 113 obligations phase in (2025-02-02 / 2025-08-02 / 2026-08-02 / 2027-08-02).

Qu'est-ce que mega-skills-collection ?

mega-skills-collection is a Claude Code agent skill that /cs:ai-act-readiness <system> — EU AI Act 6-question forcing interrogation. Use during AI-system intake, before EU deployment, or during annual compliance refresh as Article 113 obligations phase in (2025-02-02 / 2025-08-02 / 2026-08-02 / 2027-08-02).

Compatible avec✓Claude Code~Codex CLI~Cursor
npx skills add https://github.com/SamuelChien/mega-skills-collection/tree/HEAD/ai-act-readiness

Demander à votre IA préférée

Ouvre une nouvelle conversation avec cette compétence d'agent déjà préchargée.

Documentation

/cs:ai-act-readiness — EU AI Act Forcing Questions

Command: /cs:ai-act-readiness <system>

The EU AI Act compliance operator pressure-tests any AI system before EU deployment. Six Article-cited questions before any EU placement, conformity assessment, or annual compliance refresh.

When to Run

  • During AI-system intake review (per new system or material change)
  • Before placing an AI system on the EU market
  • Before signing the EU declaration of conformity (Article 47)
  • During annual compliance refresh (Article 113 phasing brings new obligations)
  • When the organization's role changes (deployer becomes provider via Article 25(1) substantial modification)
  • When training compute approaches 10^25 FLOPs (Article 51 systemic-risk threshold)

The Six EU AI Act Questions

1. Article 5: Is this a prohibited AI practice?

Penalty: up to 35M EUR or 7% worldwide turnover.

  • 8 categories: subliminal manipulation, exploitation of vulnerabilities, social scoring, predictive policing, untargeted facial scraping, emotion recognition in workplace/education, biometric categorisation by sensitive attributes, real-time public biometric ID by law enforcement
  • Run ai_system_risk_classifier.py
  • If yes → STOP. Cannot place on EU market. No exceptions outside Article 5(2) carve-outs.

2. Article 6 + Annex III: Is this high-risk?

Annex III triggers high-risk; Article 6(3) carve-out conditional.

  • 8 categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice
  • Carve-out applies only if Article 6(3)(a)-(d) AND no profiling of natural persons
  • Profiling overrides carve-out (Article 6(3) last sentence)
  • Run ai_system_risk_classifier.py

3. Article 43: For high-risk, Module A or Module H?

Biometrics → Module H (notified body) by default; others → Module A if harmonised standards applied.

  • Run conformity_assessment_planner.py
  • Module A (Annex VI): internal control with presumption of conformity if Article 40 harmonised standards applied
  • Module H (Annex VII): full QMS + notified body for biometrics or where standards lacking
  • Annex IV technical documentation: 8 items required before placing on market

4. Article 25: What role does the company play?

Provider obligations are heaviest; substantial modification turns deployer into provider.

  • Provider (Article 3(3)): placed on market; full Title III + Article 73 reporting
  • Deployer (Article 3(4)): Article 26 obligations + Article 27 FRIA if public sector
  • Importer (Article 3(6)): Article 23 verification of conformity
  • Distributor (Article 3(7)): Article 24 CE marking verification
  • Authorized representative (Article 22): non-EU providers must appoint
  • Run ai_act_obligation_tracker.py

5. Article 50: Are transparency obligations satisfied?

In force 2 Aug 2025.

  • Article 50(1): disclose AI interaction to natural persons (chatbots, virtual agents)
  • Article 50(2): mark synthetic content as AI-generated
  • Article 50(3): disclose emotion recognition / biometric categorisation (outside Article 5 prohibitions)
  • Article 50(4): disclose deepfakes (image, audio, video) as AI-generated

6. Articles 51-55: Is this a GPAI? Does it have systemic risk?

GPAI has parallel track; systemic risk above 10^25 FLOPs.

  • Article 3(63): general-purpose AI model definition
  • Article 51: systemic-risk presumption (≥ 10^25 FLOPs training compute) or Commission designation
  • Article 53: all GPAI providers — Annex XI technical docs, Annex XII downstream info, copyright policy, training-data summary
  • Article 55: systemic-risk GPAI additional obligations — model evaluations, adversarial testing, incident reporting, cybersecurity
  • Article 54: non-EU GPAI providers must appoint authorized representative

Workflow

# 1. Risk classification
python ../../ra-qm-team/skills/eu-ai-act-specialist/scripts/ai_system_risk_classifier.py systems.json

# 2. If high-risk: conformity assessment
python ../../ra-qm-team/skills/eu-ai-act-specialist/scripts/conformity_assessment_planner.py system.json

# 3. Per-role obligation matrix
python ../../ra-qm-team/skills/eu-ai-act-specialist/scripts/ai_act_obligation_tracker.py roles.json

# 4. Cross-framework reuse (ISO 42001 etc.)
python ../../skills/compliance-os/scripts/cross_framework_mapper.py program.json

Output Format

# EU AI Act Readiness: <system>
**Date:** YYYY-MM-DD
**Article Citations:** Every verdict below cites the specific Article.

## The Decision Being Made
[classify | conformity-route | obligation-scope | annual-refresh]

## Risk Classification
- Tier: prohibited | high_risk | limited_risk | minimal_risk
- Citation: Article X(Y) + Annex Z if applicable
- Rationale: <Article-cited rationale>
- GPAI: yes/no
- Systemic-risk GPAI: yes/no (per Article 51 10^25 FLOPs threshold)

## Conformity Assessment (if high-risk)
- Module: A | A_with_caveats | H | sectoral
- Citation: Article 43 + Annex VI/VII
- Notified body required: yes | no | optional
- Annex IV pack status: complete | in-progress | not-started

## Obligation Matrix
- Total obligations: N
- By deadline phase: 2025-02-02=A, 2025-08-02=B, 2026-08-02=C, 2027-08-02=D
- Highest-priority unmet obligation: <Article + description>

## Transparency (Article 50)
- 50(1) interaction disclosure: yes | no
- 50(2) synthetic content marking: yes | no | NA
- 50(3) emotion recognition disclosure: yes | no | NA
- 50(4) deepfake disclosure: yes | no | NA

## Cross-Framework Reuse
- ISO 42001 evidence applicable to Article 17 QMS: yes/no
- ISO 27001 evidence applicable to Article 15 cybersecurity: yes/no
- GDPR DPIA usable for Article 27 FRIA: yes/no

## Verdict
🟢 READY-FOR-EU | 🟡 GAPS-IDENTIFIED | 🔴 NOT-READY | 🚫 PROHIBITED

## Top 3 Actions
[3 concrete next steps with owner + Article-tied deadline]

## Legal Review Required
[Article-level ambiguities flagged for outside counsel: novel cases, GPAI threshold disputes, Article 5 boundary cases, Article 25 substantial-modification questions]

Routing

  • /cs:compliance-readiness — for multi-framework view (combine with ISO 42001 + GDPR)
  • /cs:aims-audit — for ISO 42001 deep-dive
  • /cs:caio-review — for executive AI strategy decisions
  • /cs:gc-review — for novel-case legal review (GPAI threshold, Article 5 boundary, substantial-modification)
  • /cs:decide — to log the verdict
  • /cs:freeze 30 — on EU launch commitments (regulatory exposure)

Related


Version: 1.0.0

Individual skills in this repo

This repo contains 20 individual skills — each has its own dedicated page.

SamuelChien/mega-skills-collection

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

SamuelChien/mega-skills-collection

Arquitecto de Soluciones Principal y Consultor Tecnológico de Andru.ia. Diagnostica y traza la hoja de ruta óptima para proyectos de IA en español.

SamuelChien/mega-skills-collection

Ingeniero de Sistemas de Andru.ia. Diseña, redacta y despliega nuevas habilidades (skills) dentro del repositorio siguiendo el Estándar de Diamante.

SamuelChien/mega-skills-collection

Estratega de Inteligencia de Dominio de Andru.ia. Analiza el nicho específico de un proyecto para inyectar conocimientos, regulaciones y estándares únicos del sector. Actívalo tras definir el nicho.

SamuelChien/mega-skills-collection

2D game development principles. Sprites, tilemaps, physics, camera.

SamuelChien/mega-skills-collection

3D game development principles. Rendering, shaders, physics, cameras.

SamuelChien/mega-skills-collection

Expert in building 3D experiences for the web - Three.js, React Three Fiber, Spline, WebGL, and interactive 3D scenes. Covers product configurators, 3D portfolios, immersive websites, and bringing depth to web experiences.

SamuelChien/mega-skills-collection

Accessibility audit skill for scanning, fixing, and verifying WCAG 2.2 Level A and AA compliance across React, Next.js, Vue, Angular, Svelte, and plain HTML codebases. Use when auditing accessibility, fixing a11y violations, checking color contrast, generating compliance reports, or integrating accessibility checks into CI/CD pipelines.

SamuelChien/mega-skills-collection

Ab Test Analyzer - Auto-activating skill for Data Analytics. Triggers on: ab test analyzer, ab test analyzer Part of the Data Analytics skill category.

SamuelChien/mega-skills-collection

A B Test Config Creator - Auto-activating skill for ML Deployment. Triggers on: a b test config creator, a b test config creator Part of the ML Deployment skill category.

SamuelChien/mega-skills-collection

When the user wants to plan, design, or implement an A/B test or experiment. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," "hypothesis," "conversion experiment," "statistical significance," or "test this." For tracking implementation, see analytics-tracking.

SamuelChien/mega-skills-collection

Acceptance Criteria Creator - Auto-activating skill for Enterprise Workflows. Triggers on: acceptance criteria creator, acceptance criteria creator Part of the Enterprise Workflows skill category.

SamuelChien/mega-skills-collection

Use when a coding task should be driven end-to-end from issue intake through implementation, review, deployment, and acceptance verification with minimal human re-intervention.

SamuelChien/mega-skills-collection

Accessibility Audit Runner - Auto-activating skill for Frontend Development. Triggers on: accessibility audit runner, accessibility audit runner Part of the Frontend Development skill category.

SamuelChien/mega-skills-collection

You are an accessibility expert specializing in WCAG compliance, inclusive design, and assistive technology compatibility. Conduct audits, identify barriers, and provide remediation guidance.

SamuelChien/mega-skills-collection

Web accessibility patterns for WCAG 2.2 compliance including ARIA, keyboard navigation, screen readers, and testing

SamuelChien/mega-skills-collection

Manage Discord channel access — approve pairings, edit allowlists, set DM/group policy. Use when the user asks to pair, approve someone, check who's allowed, or change policy for the Discord channel.

SamuelChien/mega-skills-collection

Create unified specification packages across Business, Development, and Design teams. Staged elaboration (L0 Vision → L1 Requirements → L2 Team Detail → L3 Acceptance Criteria) to build shared understanding. Does not write code.

SamuelChien/mega-skills-collection

Research a company or person and get actionable sales intel. Works standalone with web search, supercharged when you connect enrichment tools or your CRM. Trigger with "research [company]", "look up [person]", "intel on [prospect]", "who is [name] at [company]", or "tell me about [company]".

SamuelChien/mega-skills-collection

Validate messaging consistency across website, GitHub repos, and local documentation generating read-only discrepancy reports. Use when checking content alignment or finding mixed messaging. Trigger with phrases like "check consistency", "validate documentation", or "audit messaging".

Skills associés