Canon Reference Index
Every reference/ file canon owns, and the condition that makes it worth
reading. canon/SKILL.md keeps only the shared-contract rows and a pointer here.
Read this when you need a reference and the Recipe registry did not already name it, or when scanning what this skill can consult at all.
| Reference | Read this when |
|---|---|
reference/security-standards.md |
Security-standard version selection, canonical sources, OWASP 2025 mapping, and evidence/crosswalk rules. |
reference/compliance-templates.md |
Compliance report template and capability detail. |
reference/anthropic-skill-standards.md |
SKILL.md compliance — frontmatter validation, description quality, progressive disclosure. |
reference/nist-csf.md |
NIST CSF 2.0 functions/categories, Implementation Tiers, Current vs Target Profile, and audit evidence. |
reference/pci-dss.md |
PCI-DSS v4.0.1 requirements, CDE scoping, SAQ type selection, scope minimization. |
reference/gdpr-compliance.md |
GDPR articles, lawful bases, DPIA triggers, 72h breach notification, DPO threshold, Cloak handoff. |
reference/fix-prompt-generation.md |
Authoring ## LLM Fix Prompt — verb choice and suppression rules. |
reference/regulatory-frameworks.md, reference/regulatory-control-mapping.md |
Framework rules, control owners, evidence, and shared-control mapping. |
reference/regulatory-gdpr-eu-ai-act.md, reference/regulatory-vendor-risk-assessment.md |
Privacy/AI regulation and vendor-risk programs. |
reference/regulatory-handoff-formats.md |
Regulatory evidence and implementation handoffs. |
reference/legal-document-checklists.md |
ToS, privacy, Tokushoho, app-store, and advertising-claim clause coverage. |
reference/legal-review-patterns.md, reference/legal-review-examples.md |
Cross-document/pre-launch patterns and jurisdiction-appropriate report examples. |
reference/dpa-review.md, reference/eula-review.md, reference/cookie-consent.md |
DPA, software-license, and cookie-banner/policy deep review mechanics. |
reference/legal-review-handoffs.md |
Legal findings handoffs to Builder, Native, Cloak, Prose, and Scribe. |
reference/autorun-schema.md |
Emitting the AUTORUN _STEP_COMPLETE block — Canon-specific Output/Next schema. |
_common/OPUS_5_AUTHORING.md |
Sizing the report, thinking depth at version pinning, front-loading standard/scope at ASSESS. Critical: P3, P5. |