Run a GDPR + EU AI Act compliance audit on an existing dev-flow project (web / mobile / eve agent) and remediate what it finds. Two modes: Audit (scan the codebase and meta.json#stack against a 10-point risk register — DSAR, consent/cookies, EU data residency, retention and PII-scrubbing, AI-transparency Art.50, high-risk Annex III, sub-processors — into a report with severity, evidence and article mapping) and Remediate (apply the safe mechanical mitigations, flag the ones needing a legal decision, never deciding legal basis or high-risk for the user). A pre-deploy gate; run it any time. Triggers: "audit GDPR", "compliance check", "AI Act", "siamo conformi?", "DSAR / cancellazione account / cookie consent / data residency". Not for: legal advice or DPIA sign-off (a DPO confirms), building features, or writing the PRD (use prd-from-idea).
design-md-to-app / module-add / rn-*); it adds only the compliance controls.phase./plugin install dev-flow@dev-flow # the whole suite
./install.sh --platform claude # or drop dist/compliance-audit.skill into Claude Code