← Plugin catalog
Productivity

Rohas Legal AI: Investigations

Rohas Nagpal v0.2.1

Publisher description

From the marketplace listing

Seven reusable workflows covering chain of custody, digital evidence, fraud patterns, investigation reports, OSINT, transaction tracing, and whistleblower triage.

Language: English · Automatically detected from descriptions.

Publisher keywords

Search terms declared by the publisher.

Files & skills

File archives

Plugin package19 files · 8.83 KBBrowse files →
Skill instructions
chain-of-custody-documenter2.25 KB

View saved version →

---
name: chain-of-custody-documenter
description: >-
  Build and audit defensible chain-of-custody records for physical and digital
  evidence. Use when documenting collection, transfer, storage, access,
  examination, retention, or disposition, or testing custody for unexplained gaps.
---

# Chain of Custody Documenter

Create a contemporaneous item-level audit trail. Do not promise admissibility;
the governing court, tribunal, regulator, or policy controls that decision.

## Gather the record

Ask for the jurisdiction and proceeding, collection authority, item and source,
collector, date, time zone, location, condition, packaging, seal, identifiers,
device or account state, acquisition method, tools, versions, images or exports,
hashes, handlers, transfers, access, storage, examinations, and disposition.

## Build the custody trail

1. Assign one stable evidence ID to each item and derivative.
2. Record collection authority without assuming it was legally sufficient.
3. Describe condition, location, collector, time, packaging, seals, photographs,
   and unique identifiers.
4. Preserve the original; analyse a verified working copy where practicable.
5. For digital material, record acquisition, write protection, tool versions,
   source and destination media, and hashes at acquisition and later verification.
6. Log every handoff with from, to, date, time zone, purpose, location,
   acknowledgements, and container or seal condition.
7. Record storage controls, access, examinations, derivative files, and returns.
8. Identify missing links, delay, broken seals, hash mismatch, undocumented
   access, clock issues, and other incidents.
9. Record the retention rule and disposition authority; never infer permission
   to destroy from silence.

## Deliverables

Provide a master register, per-item custody forms, transfer receipts, digital
hash manifest, access and examination log, incident log, and retention or
disposition schedule. Mark unknown fields explicitly.

## Guardrails

Never backdate, invent a handler, silently close a gap, alter the original, or
treat a hash as proof of provenance, authorship, or truth. Minimise personal and
privileged data. Escalate integrity failures and use qualified forensic and
legal reviewers where collection or admissibility is contested.

Referenced files: 1

digital-evidence-reviewer2.34 KB

View saved version →

---
name: digital-evidence-reviewer
description: >-
  Review digital evidence for provenance, integrity, acquisition quality,
  authenticity, metadata, timeline, attribution, and admissibility gaps. Use
  for devices, images, messages, email, cloud exports, logs, media, or documents.
---

# Digital Evidence Reviewer

Assess what the material can support and what further work is needed. Keep an
item, account, device, and person alleged to control them distinct.

## Intake

Obtain native items or forensic images, collection authority, hashes, custody
records, acquisition logs, tools and versions, sources, export settings, system
clocks, related records, and the precise authenticity or attribution question.

## Review method

1. State jurisdiction, forum, legal standard, scope, and limitations.
2. Preserve the original and verify supplied hashes before substantive work.
3. Reconstruct provenance from creation or receipt through collection and review.
4. Assess acquisition type and completeness: physical, logical, cloud, API,
   provider export, screenshot, forwarded copy, or another method.
5. Record write blockers, filters, permissions, failures, exclusions, and known
   platform transformations.
6. Normalise time zones and test clock drift before building a chronology.
7. Examine metadata, context, headers, logs, EXIF, encoding, compression, edits,
   transcoding, and container relationships.
8. Test manipulation indicators against innocent alternatives.
9. Corroborate significant events with independent sources.
10. Assess attribution separately for device, account, session, content, and
    person; state confidence and its basis.
11. Identify privilege, privacy, minimisation, disclosure, and admissibility
    issues for qualified legal review.
12. Record reproducible steps, tools, versions, errors, and repeatable tests.

## Output

Produce an inventory, integrity and provenance table, acquisition assessment,
timeline, authenticity and gap matrix, attribution assessment, reproducibility
notes, limitations, and prioritised further work.

## Guardrails

Do not hack, bypass controls, use credentials without authority, alter originals,
or overstate metadata, deleted data, or automated detection. Do not identify a
person from facial recognition or one technical indicator alone. Follow
specialist safety procedures for illegal or highly sensitive material.

Referenced files: 1

fraud-pattern-analyst2.41 KB

View saved version →

---
name: fraud-pattern-analyst
description: >-
  Identify, test, and prioritise fraud hypotheses and control failures in
  transactional records. Use for payments, procurement, expenses, payroll,
  revenue, refunds, vendors, customers, journals, approvals, or access logs.
---

# Fraud Pattern Analyst

Treat a red flag as a lead, not a finding. Develop plausible fraud and non-fraud
explanations, then test both against preserved source evidence.

## Inputs

Obtain the allegation, objective, period, entities, data dictionary, native
exports, ledger and bank records, master data, contracts, invoices, approvals,
access logs, relationships, and control design. Record missing data and filters.

## Analysis method

1. Preserve raw data and create a repeatable working dataset.
2. Validate meaning, uniqueness, completeness, formats, currencies, signs,
   duplicates, and joins; reconcile control totals where possible.
3. Form competing hypotheses, including error, timing, exception, system
   behaviour, legitimate concentration, and deliberate misconduct.
4. Test relevant indicators: duplicates, round amounts, threshold splitting,
   off-hours activity, sequential invoices, pass-through, overrides, and shared
   addresses, bank details, devices, identifiers, or approvers.
5. Compare suitable peers, cohorts, seasons, locations, and periods.
6. Build relationship links, distinguishing confirmed identity from fuzzy,
   shared, historical, or coincidental matches.
7. Analyse sequences around onboarding, master-data changes, approval, payment,
   refund, reversal, write-off, and access.
8. Trace prioritised exceptions to source documents, system logs, and interviews.
9. Quantify exposure as sourced scenarios without false precision.
10. Map each pattern to expected controls and test design, execution, override,
    and monitoring failures.
11. Rank next steps by evidential value, urgency, preservation risk, cost, and
    risk of alerting subjects.

## Output

Provide a data-quality note, hypothesis matrix, indicator table with innocent
alternatives, linked-party analysis, sample schedule, quantified scenarios,
control-failure analysis, and investigation priorities.

## Guardrails

Do not present suspicion, a score, or a network link as proof. Preserve
exculpatory evidence and apply tests consistently. Do not profile protected
classes, access unauthorised personal data, manipulate records, conceal methods,
or help anyone evade detection.

Referenced files: 1

investigation-report-drafter2.3 KB

View saved version →

---
name: investigation-report-drafter
description: >-
  Draft neutral, evidence-led reports that separate allegations, facts,
  inferences, findings, limitations, and recommendations. Use after an internal,
  regulatory, workplace, fraud, compliance, or other investigation.
---

# Investigation Report Drafter

Write for a reviewer who was not present. Apply only the authorised mandate and
standard of proof, and make contrary evidence and unresolved gaps visible.

## Inputs

Obtain the mandate, jurisdiction, audience, authority and privilege position,
allegations and elements, evidence index, interviews, methodology, applicable
standard, procedural correspondence, conflicts, limitations, and reporting duties.

## Drafting method

1. State the commission, scope, exclusions, independence, standard, dates,
   methodology, and material limitations.
2. Convert each allegation into factual propositions to be tested.
3. Build a sourced chronology before writing narrative conclusions.
4. Cite every material fact to an evidence ID or stable source locator.
5. Assess reliability using provenance, contemporaneity, consistency,
   corroboration, opportunity to know, and contrary explanations—not stereotype
   or demeanour alone.
6. Present inculpatory, exculpatory, inconsistent, unavailable, and disputed
   evidence fairly.
7. Label established fact, reported account, inference, expert opinion, and unknown.
8. Make one finding per allegation under the authorised standard. Do not declare
   criminal guilt outside the mandate.
9. Address fairness, conflicts, response opportunities, preservation,
   confidentiality, and limits on reliance.
10. Separate remediation from findings and identify owners and dependencies.
11. Apply proportionate redactions and provide an indexed source appendix.

## Report structure

Use: executive summary; mandate and scope; methodology and standard; chronology;
evidence overview; allegation analysis and findings; limitations; recommendations;
and source, interview, and appendix indexes.

## Guardrails

Never fabricate, suppress, selectively quote, retaliate, or promise absolute
confidentiality or privilege. Protect reporters, witnesses, personal data, trade
secrets, and privileged material. Seek independent review for contested,
high-stakes, technically specialised, or externally disclosed findings.

Referenced files: 1

osint-collector2.51 KB

View saved version →

---
name: osint-collector
description: >-
  Plan and document lawful, ethical, reproducible open-source intelligence
  collection. Use for public web, social, corporate, media, mapping, archive,
  domain, or other open sources where provenance and verification matter.
---

# OSINT Collector

Collect only what the authorised objective requires. Public visibility does not
itself establish permission to collect, retain, republish, or act on information.

## Scope and safety

Obtain the questions, jurisdiction, legal and ethical constraints, identifiers,
date cutoff, geography, languages, risk, minimisation rule, delivery format, and
stop conditions. Agree whether interaction, pretext, automation, archives, or
paid sources are authorised; default to passive collection only.

## Collection method

1. Convert questions into a query and source matrix with alternative names,
   transliterations, dates, entities, locations, and disconfirming searches.
2. Plan safety for accounts, devices, links, downloads, malware, exposure,
   subject contact, and investigator identity.
3. Record each URL or stable ID, publisher, UTC timestamp, access path, visible
   context, query, collector, and method.
4. Preserve screenshots and native downloads where lawful; hash captured files
   and retain relevant page, header, archive, and platform metadata.
5. Distinguish live source, platform copy, archive, quotation, syndication, and
   repost; trace significant claims toward the earliest available source.
6. Verify identity with independent attributes. Keep name matches, handles,
   accounts, organisations, and people separate until linked.
7. Corroborate geolocation, chronolocation, ownership, authorship, and events;
   state confidence and alternatives.
8. Build a claim-to-source table and assess origin, proximity, incentives,
   consistency, corroboration, manipulation risk, and gaps.
9. Preserve changed or deleted content only lawfully and distinguish collection,
   event, and publication times.
10. Log queries, decisions, exclusions, and safety or legal stops reproducibly.

## Output

Provide a collection plan, query log, source register, capture and hash manifest,
findings matrix, confidence table, gaps, and legal, ethical, and safety notes.

## Guardrails

Do not hack, evade controls, abuse credentials, stalk, dox, deceive, contact
subjects, or access illicit material without explicit lawful authority and
specialist controls. Minimise sensitive data. Never identify a person or allege
misconduct from one source, resemblance, or automated match alone.

Referenced files: 1

transaction-tracer2.57 KB

View saved version →

---
name: transaction-tracer
description: >-
  Reconstruct flows of funds across bank accounts, ledgers, entities,
  instruments, currencies, and blockchains. Use for asset tracing, fraud,
  insolvency, sanctions, AML, disputes, or source-linked transaction paths.
---

# Transaction Tracer

Make each funds-flow edge traceable to a source. State the tracing convention and
do not imply ownership, knowledge, or misconduct from movement alone.

## Inputs

Obtain the objective, jurisdiction, accounts, wallets, entities, period,
currencies, native statements, ledger, invoices, contracts, blockchain hashes,
addresses, networks, opening balances, FX sources, relationships, and limitations.

## Tracing method

1. Preserve raw records and build a normalised ledger with stable source IDs,
   timestamps, time zones, currencies, signs, counterparties, networks, tokens,
   and transaction identifiers.
2. Test uniqueness and completeness, deduplicate, and reconcile opening balance
   plus inflows less outflows to closing balance. List differences.
3. Separate account ownership, beneficial ownership, authority, access, control,
   and transaction purpose; source each relationship independently.
4. Trace direct transfers, then layering, conversions, intermediaries, cash,
   fees, refunds, reversals, chargebacks, and internal movements.
5. Disclose a defensible convention such as FIFO, LIFO, proportional allocation,
   or lowest intermediate balance; show alternatives where material.
6. Apply dated, sourced FX rates; retain original amounts and isolate valuation.
7. For blockchains, identify network, transaction model, token contract, fees,
   change, bridges, swaps, mixers, and exchange touchpoints. Separate on-chain
   observation from third-party attribution.
8. Test loops, pass-through timing, aggregation, splitting, address reuse,
   common counterparties, and off-chain explanations without overstating taint.
9. Quantify direct, indirect, commingled, dissipated, and unresolved amounts as
   separate scenarios and prevent double counting.
10. Record reproducible queries, transformations, exclusions, assumptions, and
    the source for every displayed node and edge.

## Output

Provide a source inventory, reconciliations, chronological ledger, funds-flow
table and map, relationship table, traced scenarios, gaps, and reproducibility
appendix.

## Guardrails

Do not access accounts or wallets, move funds, obtain credentials, or evade legal
process. Do not assume an address belongs to a person, attribution is certain, or
exposure proves control or guilt. Protect financial data and exculpatory paths.

Referenced files: 1

whistleblower-report-analyst2.76 KB

View saved version →

---
name: whistleblower-report-analyst
description: >-
  Triage a whistleblower report, preserve confidentiality, assess urgency and
  conflicts, and build an investigation and protection plan. Use for anonymous
  or identified reports of misconduct, fraud, retaliation, safety, or compliance.
---

# Whistleblower Report Analyst

Assess whether and how to investigate; do not decide truth from intake alone.
Treat specificity separately from the reporter's identity, motive, style, or status.

## Intake

Preserve the original report, channel, date, metadata, attachments, access log,
anonymity or confidentiality preference, allegations, people, entities, periods,
evidence locations, immediate risk, deadlines, prior reports, and conflicts.

## Triage method

1. Acknowledge receipt where possible without promising absolute confidentiality,
   a particular outcome, or protection beyond the organisation's authority.
2. Address imminent harm, evidence loss, retaliation, reporting deadlines,
   financial dissipation, and safeguarding first.
3. Screen investigators, management, legal, HR, audit, compliance, and the
   reporting line for conflicts; establish independence where needed.
4. Break the report into allegation, actor, conduct, date, location, source,
   affected rule or control, and potential evidence.
5. Assess specificity, consistency, corroborability, seriousness, recurrence,
   exposure, and alternatives neutrally. Anonymous or motivated reporting is not
   inherently unreliable.
6. Rank allegations by urgency, impact, evidence fragility, legal duty, and risk
   of alerting subjects.
7. Preserve relevant systems, devices, messages, files, logs, sites, and
   custodians without unnecessary disclosure.
8. Design scope, reviewers, data requests, interview order, milestones, decision
   rights, escalation criteria, and the finding standard.
9. Establish confidential communication, anti-retaliation monitoring, support,
   access restrictions, and a route for new concerns.
10. Coordinate HR, privacy, privilege, employment, regulatory, disclosure, and
    law-enforcement issues with independent specialists.
11. Plan closure, feedback where lawful, remediation, accountability, trend
    analysis, and monitoring without revealing protected information.

## Output

Provide an intake summary, allegation map, urgency and risk matrix, conflict and
independence note, preservation plan, investigation plan, protection plan, and
reporting and escalation calendar.

## Guardrails

Do not unmask an anonymous source except where lawful, necessary, authorised, and
safeguarded. Do not retaliate, pressure, prejudge, run loyalty tests, or use an
agreement to deter lawful reporting. Limit identities and allegations to
need-to-know. Escalate emergencies, obstruction, and compromised independence.

Referenced files: 1

Package details

Publisher declarations from the archived package. These are separate from our research and the live service's terms.

Package license
MIT
Package author
Rohas Nagpal
Keywords
See publisher keywords

Declared capabilities

  • Read
  • Write

Package observed Oct 5, 2026.

Technical details
First seen
Sep 30, 2026 · 22:02 UTC
Last seen
Oct 6, 2026 · 12:00 UTC
Collection status
Collected

plugins_6a7624ebb8648191918bc29197f7427e

Download plugin data (JSON)

Before you connect Rohas Legal AI: Investigations

How do I connect it?

Open the publisher's marketplace listing to check current availability and follow its connection instructions. This directory does not install plugins. Check the requested access and any account requirements before connecting.

Check marketplace availability ↗

Does it require paid access?

We have not established the pricing or subscription requirements for this plugin. An absent price does not mean free access.

Compare researched pricing and access models →

How can I evaluate it?

Check the declared skills and available files, then try a small task whose result you can verify. Our archived descriptions and instructions establish publisher claims, not tested runtime quality. Review sources and coverage limits.