Review digital evidence for provenance, integrity, acquisition quality, authenticity, metadata, timeline, attribution, and admissibility gaps. Use for devices, images, messages, email, cloud exports, logs, media, or documents.
Scanned 9/4/2026
Install to Claude Code
npx -y skills add Cancellationperiplocagraeca503/legal-ai-skills --skill digital-evidence-reviewer --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Digital Evidence Reviewer?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cancellationperiplocagraeca503-digital-evidence-reviewer)More formats (shields.io, HTML) on the badges page.
---
name: digital-evidence-reviewer
description: >-
Review digital evidence for provenance, integrity, acquisition quality,
authenticity, metadata, timeline, attribution, and admissibility gaps. Use
for devices, images, messages, email, cloud exports, logs, media, or documents.
---
# Digital Evidence Reviewer
Assess what the material can support and what further work is needed. Keep an
item, account, device, and person alleged to control them distinct.
## Intake
Obtain native items or forensic images, collection authority, hashes, custody
records, acquisition logs, tools and versions, sources, export settings, system
clocks, related records, and the precise authenticity or attribution question.
## Review method
1. State jurisdiction, forum, legal standard, scope, and limitations.
2. Preserve the original and verify supplied hashes before substantive work.
3. Reconstruct provenance from creation or receipt through collection and review.
4. Assess acquisition type and completeness: physical, logical, cloud, API,
provider export, screenshot, forwarded copy, or another method.
5. Record write blockers, filters, permissions, failures, exclusions, and known
platform transformations.
6. Normalise time zones and test clock drift before building a chronology.
7. Examine metadata, context, headers, logs, EXIF, encoding, compression, edits,
transcoding, and container relationships.
8. Test manipulation indicators against innocent alternatives.
9. Corroborate significant events with independent sources.
10. Assess attribution separately for device, account, session, content, and
person; state confidence and its basis.
11. Identify privilege, privacy, minimisation, disclosure, and admissibility
issues for qualified legal review.
12. Record reproducible steps, tools, versions, errors, and repeatable tests.
## Output
Produce an inventory, integrity and provenance table, acquisition assessment,
timeline, authenticity and gap matrix, attribution assessment, reproducibility
notes, limitations, and prioritised further work.
## Guardrails
Do not hack, bypass controls, use credentials without authority, alter originals,
or overstate metadata, deleted data, or automated detection. Do not identify a
person from facial recognition or one technical indicator alone. Follow
specialist safety procedures for illegal or highly sensitive material.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!