{"id":17340,"plugin_id":"plugins_6a7624ebb8648191918bc29197f7427e","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:14:06.821Z","digest":"a834f3204238523c9bf9891f63775489361ee68c7facd5d8e22e1b3a1bc1a077","against":null,"payload":{"description":"Review digital evidence for provenance, integrity, acquisition quality, authenticity, metadata, timeline, attribution, and admissibility gaps. Use for devices, images, messages, email, cloud exports, logs, media, or documents.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":304}],"name":"digital-evidence-reviewer","skill_md_contents":"---\nname: digital-evidence-reviewer\ndescription: >-\n  Review digital evidence for provenance, integrity, acquisition quality,\n  authenticity, metadata, timeline, attribution, and admissibility gaps. Use\n  for devices, images, messages, email, cloud exports, logs, media, or documents.\n---\n\n# Digital Evidence Reviewer\n\nAssess what the material can support and what further work is needed. Keep an\nitem, account, device, and person alleged to control them distinct.\n\n## Intake\n\nObtain native items or forensic images, collection authority, hashes, custody\nrecords, acquisition logs, tools and versions, sources, export settings, system\nclocks, related records, and the precise authenticity or attribution question.\n\n## Review method\n\n1. State jurisdiction, forum, legal standard, scope, and limitations.\n2. Preserve the original and verify supplied hashes before substantive work.\n3. Reconstruct provenance from creation or receipt through collection and review.\n4. Assess acquisition type and completeness: physical, logical, cloud, API,\n   provider export, screenshot, forwarded copy, or another method.\n5. Record write blockers, filters, permissions, failures, exclusions, and known\n   platform transformations.\n6. Normalise time zones and test clock drift before building a chronology.\n7. Examine metadata, context, headers, logs, EXIF, encoding, compression, edits,\n   transcoding, and container relationships.\n8. Test manipulation indicators against innocent alternatives.\n9. Corroborate significant events with independent sources.\n10. Assess attribution separately for device, account, session, content, and\n    person; state confidence and its basis.\n11. Identify privilege, privacy, minimisation, disclosure, and admissibility\n    issues for qualified legal review.\n12. Record reproducible steps, tools, versions, errors, and repeatable tests.\n\n## Output\n\nProduce an inventory, integrity and provenance table, acquisition assessment,\ntimeline, authenticity and gap matrix, attribution assessment, reproducibility\nnotes, limitations, and prioritised further work.\n\n## Guardrails\n\nDo not hack, bypass controls, use credentials without authority, alter originals,\nor overstate metadata, deleted data, or automated detection. Do not identify a\nperson from facial recognition or one technical indicator alone. Follow\nspecialist safety procedures for illegal or highly sensitive material.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}