Rohas Legal AI: Investigations
Rohas Nagpal v0.2.1
Publisher description
From the marketplace listing
Seven reusable workflows covering chain of custody, digital evidence, fraud patterns, investigation reports, OSINT, transaction tracing, and whistleblower triage.
Language: English · Automatically detected from descriptions.
Publisher keywords
Search terms declared by the publisher.
Matches for “analysis”
Exact text from the indicated source. A mention alone does not establish support for your task.
Publisher description
Evidence handling, digital review, fraud analysis, OSINT, tracing, reporting, and whistleblower skills.
Files & skills
File archives
Skill instructions
chain-of-custody-documenter2.25 KB
--- name: chain-of-custody-documenter description: >- Build and audit defensible chain-of-custody records for physical and digital evidence. Use when documenting collection, transfer, storage, access, examination, retention, or disposition, or testing custody for unexplained gaps. --- # Chain of Custody Documenter Create a contemporaneous item-level audit trail. Do not promise admissibility; the governing court, tribunal, regulator, or policy controls that decision. ## Gather the record Ask for the jurisdiction and proceeding, collection authority, item and source, collector, date, time zone, location, condition, packaging, seal, identifiers, device or account state, acquisition method, tools, versions, images or exports, hashes, handlers, transfers, access, storage, examinations, and disposition. ## Build the custody trail 1. Assign one stable evidence ID to each item and derivative. 2. Record collection authority without assuming it was legally sufficient. 3. Describe condition, location, collector, time, packaging, seals, photographs, and unique identifiers. 4. Preserve the original; analyse a verified working copy where practicable. 5. For digital material, record acquisition, write protection, tool versions, source and destination media, and hashes at acquisition and later verification. 6. Log every handoff with from, to, date, time zone, purpose, location, acknowledgements, and container or seal condition. 7. Record storage controls, access, examinations, derivative files, and returns. 8. Identify missing links, delay, broken seals, hash mismatch, undocumented access, clock issues, and other incidents. 9. Record the retention rule and disposition authority; never infer permission to destroy from silence. ## Deliverables Provide a master register, per-item custody forms, transfer receipts, digital hash manifest, access and examination log, incident log, and retention or disposition schedule. Mark unknown fields explicitly. ## Guardrails Never backdate, invent a handler, silently close a gap, alter the original, or treat a hash as proof of provenance, authorship, or truth. Minimise personal and privileged data. Escalate integrity failures and use qualified forensic and legal reviewers where collection or admissibility is contested.
Referenced files: 1
digital-evidence-reviewer2.34 KB
---
name: digital-evidence-reviewer
description: >-
Review digital evidence for provenance, integrity, acquisition quality,
authenticity, metadata, timeline, attribution, and admissibility gaps. Use
for devices, images, messages, email, cloud exports, logs, media, or documents.
---
# Digital Evidence Reviewer
Assess what the material can support and what further work is needed. Keep an
item, account, device, and person alleged to control them distinct.
## Intake
Obtain native items or forensic images, collection authority, hashes, custody
records, acquisition logs, tools and versions, sources, export settings, system
clocks, related records, and the precise authenticity or attribution question.
## Review method
1. State jurisdiction, forum, legal standard, scope, and limitations.
2. Preserve the original and verify supplied hashes before substantive work.
3. Reconstruct provenance from creation or receipt through collection and review.
4. Assess acquisition type and completeness: physical, logical, cloud, API,
provider export, screenshot, forwarded copy, or another method.
5. Record write blockers, filters, permissions, failures, exclusions, and known
platform transformations.
6. Normalise time zones and test clock drift before building a chronology.
7. Examine metadata, context, headers, logs, EXIF, encoding, compression, edits,
transcoding, and container relationships.
8. Test manipulation indicators against innocent alternatives.
9. Corroborate significant events with independent sources.
10. Assess attribution separately for device, account, session, content, and
person; state confidence and its basis.
11. Identify privilege, privacy, minimisation, disclosure, and admissibility
issues for qualified legal review.
12. Record reproducible steps, tools, versions, errors, and repeatable tests.
## Output
Produce an inventory, integrity and provenance table, acquisition assessment,
timeline, authenticity and gap matrix, attribution assessment, reproducibility
notes, limitations, and prioritised further work.
## Guardrails
Do not hack, bypass controls, use credentials without authority, alter originals,
or overstate metadata, deleted data, or automated detection. Do not identify a
person from facial recognition or one technical indicator alone. Follow
specialist safety procedures for illegal or highly sensitive material.
Referenced files: 1
fraud-pattern-analyst2.41 KB
---
name: fraud-pattern-analyst
description: >-
Identify, test, and prioritise fraud hypotheses and control failures in
transactional records. Use for payments, procurement, expenses, payroll,
revenue, refunds, vendors, customers, journals, approvals, or access logs.
---
# Fraud Pattern Analyst
Treat a red flag as a lead, not a finding. Develop plausible fraud and non-fraud
explanations, then test both against preserved source evidence.
## Inputs
Obtain the allegation, objective, period, entities, data dictionary, native
exports, ledger and bank records, master data, contracts, invoices, approvals,
access logs, relationships, and control design. Record missing data and filters.
## Analysis method
1. Preserve raw data and create a repeatable working dataset.
2. Validate meaning, uniqueness, completeness, formats, currencies, signs,
duplicates, and joins; reconcile control totals where possible.
3. Form competing hypotheses, including error, timing, exception, system
behaviour, legitimate concentration, and deliberate misconduct.
4. Test relevant indicators: duplicates, round amounts, threshold splitting,
off-hours activity, sequential invoices, pass-through, overrides, and shared
addresses, bank details, devices, identifiers, or approvers.
5. Compare suitable peers, cohorts, seasons, locations, and periods.
6. Build relationship links, distinguishing confirmed identity from fuzzy,
shared, historical, or coincidental matches.
7. Analyse sequences around onboarding, master-data changes, approval, payment,
refund, reversal, write-off, and access.
8. Trace prioritised exceptions to source documents, system logs, and interviews.
9. Quantify exposure as sourced scenarios without false precision.
10. Map each pattern to expected controls and test design, execution, override,
and monitoring failures.
11. Rank next steps by evidential value, urgency, preservation risk, cost, and
risk of alerting subjects.
## Output
Provide a data-quality note, hypothesis matrix, indicator table with innocent
alternatives, linked-party analysis, sample schedule, quantified scenarios,
control-failure analysis, and investigation priorities.
## Guardrails
Do not present suspicion, a score, or a network link as proof. Preserve
exculpatory evidence and apply tests consistently. Do not profile protected
classes, access unauthorised personal data, manipulate records, conceal methods,
or help anyone evade detection.
Referenced files: 1
investigation-report-drafter2.3 KB
--- name: investigation-report-drafter description: >- Draft neutral, evidence-led reports that separate allegations, facts, inferences, findings, limitations, and recommendations. Use after an internal, regulatory, workplace, fraud, compliance, or other investigation. --- # Investigation Report Drafter Write for a reviewer who was not present. Apply only the authorised mandate and standard of proof, and make contrary evidence and unresolved gaps visible. ## Inputs Obtain the mandate, jurisdiction, audience, authority and privilege position, allegations and elements, evidence index, interviews, methodology, applicable standard, procedural correspondence, conflicts, limitations, and reporting duties. ## Drafting method 1. State the commission, scope, exclusions, independence, standard, dates, methodology, and material limitations. 2. Convert each allegation into factual propositions to be tested. 3. Build a sourced chronology before writing narrative conclusions. 4. Cite every material fact to an evidence ID or stable source locator. 5. Assess reliability using provenance, contemporaneity, consistency, corroboration, opportunity to know, and contrary explanations—not stereotype or demeanour alone. 6. Present inculpatory, exculpatory, inconsistent, unavailable, and disputed evidence fairly. 7. Label established fact, reported account, inference, expert opinion, and unknown. 8. Make one finding per allegation under the authorised standard. Do not declare criminal guilt outside the mandate. 9. Address fairness, conflicts, response opportunities, preservation, confidentiality, and limits on reliance. 10. Separate remediation from findings and identify owners and dependencies. 11. Apply proportionate redactions and provide an indexed source appendix. ## Report structure Use: executive summary; mandate and scope; methodology and standard; chronology; evidence overview; allegation analysis and findings; limitations; recommendations; and source, interview, and appendix indexes. ## Guardrails Never fabricate, suppress, selectively quote, retaliate, or promise absolute confidentiality or privilege. Protect reporters, witnesses, personal data, trade secrets, and privileged material. Seek independent review for contested, high-stakes, technically specialised, or externally disclosed findings.
Referenced files: 1
osint-collector2.51 KB
--- name: osint-collector description: >- Plan and document lawful, ethical, reproducible open-source intelligence collection. Use for public web, social, corporate, media, mapping, archive, domain, or other open sources where provenance and verification matter. --- # OSINT Collector Collect only what the authorised objective requires. Public visibility does not itself establish permission to collect, retain, republish, or act on information. ## Scope and safety Obtain the questions, jurisdiction, legal and ethical constraints, identifiers, date cutoff, geography, languages, risk, minimisation rule, delivery format, and stop conditions. Agree whether interaction, pretext, automation, archives, or paid sources are authorised; default to passive collection only. ## Collection method 1. Convert questions into a query and source matrix with alternative names, transliterations, dates, entities, locations, and disconfirming searches. 2. Plan safety for accounts, devices, links, downloads, malware, exposure, subject contact, and investigator identity. 3. Record each URL or stable ID, publisher, UTC timestamp, access path, visible context, query, collector, and method. 4. Preserve screenshots and native downloads where lawful; hash captured files and retain relevant page, header, archive, and platform metadata. 5. Distinguish live source, platform copy, archive, quotation, syndication, and repost; trace significant claims toward the earliest available source. 6. Verify identity with independent attributes. Keep name matches, handles, accounts, organisations, and people separate until linked. 7. Corroborate geolocation, chronolocation, ownership, authorship, and events; state confidence and alternatives. 8. Build a claim-to-source table and assess origin, proximity, incentives, consistency, corroboration, manipulation risk, and gaps. 9. Preserve changed or deleted content only lawfully and distinguish collection, event, and publication times. 10. Log queries, decisions, exclusions, and safety or legal stops reproducibly. ## Output Provide a collection plan, query log, source register, capture and hash manifest, findings matrix, confidence table, gaps, and legal, ethical, and safety notes. ## Guardrails Do not hack, evade controls, abuse credentials, stalk, dox, deceive, contact subjects, or access illicit material without explicit lawful authority and specialist controls. Minimise sensitive data. Never identify a person or allege misconduct from one source, resemblance, or automated match alone.
Referenced files: 1
transaction-tracer2.57 KB
---
name: transaction-tracer
description: >-
Reconstruct flows of funds across bank accounts, ledgers, entities,
instruments, currencies, and blockchains. Use for asset tracing, fraud,
insolvency, sanctions, AML, disputes, or source-linked transaction paths.
---
# Transaction Tracer
Make each funds-flow edge traceable to a source. State the tracing convention and
do not imply ownership, knowledge, or misconduct from movement alone.
## Inputs
Obtain the objective, jurisdiction, accounts, wallets, entities, period,
currencies, native statements, ledger, invoices, contracts, blockchain hashes,
addresses, networks, opening balances, FX sources, relationships, and limitations.
## Tracing method
1. Preserve raw records and build a normalised ledger with stable source IDs,
timestamps, time zones, currencies, signs, counterparties, networks, tokens,
and transaction identifiers.
2. Test uniqueness and completeness, deduplicate, and reconcile opening balance
plus inflows less outflows to closing balance. List differences.
3. Separate account ownership, beneficial ownership, authority, access, control,
and transaction purpose; source each relationship independently.
4. Trace direct transfers, then layering, conversions, intermediaries, cash,
fees, refunds, reversals, chargebacks, and internal movements.
5. Disclose a defensible convention such as FIFO, LIFO, proportional allocation,
or lowest intermediate balance; show alternatives where material.
6. Apply dated, sourced FX rates; retain original amounts and isolate valuation.
7. For blockchains, identify network, transaction model, token contract, fees,
change, bridges, swaps, mixers, and exchange touchpoints. Separate on-chain
observation from third-party attribution.
8. Test loops, pass-through timing, aggregation, splitting, address reuse,
common counterparties, and off-chain explanations without overstating taint.
9. Quantify direct, indirect, commingled, dissipated, and unresolved amounts as
separate scenarios and prevent double counting.
10. Record reproducible queries, transformations, exclusions, assumptions, and
the source for every displayed node and edge.
## Output
Provide a source inventory, reconciliations, chronological ledger, funds-flow
table and map, relationship table, traced scenarios, gaps, and reproducibility
appendix.
## Guardrails
Do not access accounts or wallets, move funds, obtain credentials, or evade legal
process. Do not assume an address belongs to a person, attribution is certain, or
exposure proves control or guilt. Protect financial data and exculpatory paths.
Referenced files: 1
whistleblower-report-analyst2.76 KB
---
name: whistleblower-report-analyst
description: >-
Triage a whistleblower report, preserve confidentiality, assess urgency and
conflicts, and build an investigation and protection plan. Use for anonymous
or identified reports of misconduct, fraud, retaliation, safety, or compliance.
---
# Whistleblower Report Analyst
Assess whether and how to investigate; do not decide truth from intake alone.
Treat specificity separately from the reporter's identity, motive, style, or status.
## Intake
Preserve the original report, channel, date, metadata, attachments, access log,
anonymity or confidentiality preference, allegations, people, entities, periods,
evidence locations, immediate risk, deadlines, prior reports, and conflicts.
## Triage method
1. Acknowledge receipt where possible without promising absolute confidentiality,
a particular outcome, or protection beyond the organisation's authority.
2. Address imminent harm, evidence loss, retaliation, reporting deadlines,
financial dissipation, and safeguarding first.
3. Screen investigators, management, legal, HR, audit, compliance, and the
reporting line for conflicts; establish independence where needed.
4. Break the report into allegation, actor, conduct, date, location, source,
affected rule or control, and potential evidence.
5. Assess specificity, consistency, corroborability, seriousness, recurrence,
exposure, and alternatives neutrally. Anonymous or motivated reporting is not
inherently unreliable.
6. Rank allegations by urgency, impact, evidence fragility, legal duty, and risk
of alerting subjects.
7. Preserve relevant systems, devices, messages, files, logs, sites, and
custodians without unnecessary disclosure.
8. Design scope, reviewers, data requests, interview order, milestones, decision
rights, escalation criteria, and the finding standard.
9. Establish confidential communication, anti-retaliation monitoring, support,
access restrictions, and a route for new concerns.
10. Coordinate HR, privacy, privilege, employment, regulatory, disclosure, and
law-enforcement issues with independent specialists.
11. Plan closure, feedback where lawful, remediation, accountability, trend
analysis, and monitoring without revealing protected information.
## Output
Provide an intake summary, allegation map, urgency and risk matrix, conflict and
independence note, preservation plan, investigation plan, protection plan, and
reporting and escalation calendar.
## Guardrails
Do not unmask an anonymous source except where lawful, necessary, authorised, and
safeguarded. Do not retaliate, pressure, prejudge, run loyalty tests, or use an
agreement to deter lawful reporting. Limit identities and allegations to
need-to-know. Escalate emergencies, obstruction, and compromised independence.
Referenced files: 1
Package details
Publisher declarations from the archived package. These are separate from our research and the live service's terms.
- Package license
- MIT
- Package author
- Rohas Nagpal
- Keywords
- See publisher keywords
Declared capabilities
- Read
- Write
Package observed Oct 5, 2026.
Technical details
- First seen
- Sep 30, 2026 · 22:02 UTC
- Last seen
- Oct 6, 2026 · 18:00 UTC
- Collection status
- Collected
plugins_6a7624ebb8648191918bc29197f7427e
Download plugin data (JSON)Before you connect Rohas Legal AI: Investigations
How do I connect it?
Open the publisher's marketplace listing to check current availability and follow its connection instructions. This directory does not install plugins. Check the requested access and any account requirements before connecting.
Check marketplace availability ↗
Does it require paid access?
We have not established the pricing or subscription requirements for this plugin. An absent price does not mean free access.
Compare researched pricing and access models →
How can I evaluate it?
Check the declared skills and available files, then try a small task whose result you can verify. Our archived descriptions and instructions establish publisher claims, not tested runtime quality. Review sources and coverage limits.