AgentInvestigate is an open-source AI skill repository for lawful professional investigation and private security support work.
It gives general-purpose AI agents bounded procedures, routing gates, evidence discipline, source requirements, output contracts, and escalation rules for professional work. The repository contains atomic skills, composed professional skillsets, Canadian jurisdiction foundations, evaluation fixtures, and repository validators.
AUTHORITY BEFORE ACTION
EVIDENCE BEFORE CONCLUSION
HUMAN CONTROL BEFORE INTRUSIVE WORK
Current public distribution:
PUBLIC_RELEASE_READY
Public readiness token:
AGENTINVESTIGATE_AI_36_PUBLIC_READINESS_READY
Public distribution token:
AGENTINVESTIGATE_AI_38_PUBLIC_DISTRIBUTION_READY
Clone the repository and run its validation gate:
git clone https://github.com/jeremylongworth-source/AgentInvestigate.git
cd AgentInvestigate
.\scripts\validate-all.ps1Preview a skill before installing it:
gh skill preview jeremylongworth-source/AgentInvestigate classify-request-typeInstall one skill for local agent-skill use:
gh skill install jeremylongworth-source/AgentInvestigate classify-request-typeInstall one skill for GitHub Copilot:
gh skill install jeremylongworth-source/AgentInvestigate classify-request-type --agent github-copilot --scope userThese commands require GitHub CLI authentication and a GitHub CLI version that provides gh skill. The gh skill command is a preview feature and may change.
AgentInvestigate is for maintainers building investigation or security-oriented AI skills, evaluators testing routing and safety behavior, contributors adding roadmap-scoped content, and organizations that need reusable support patterns for lawful investigation, security operations, reporting, and escalation.
It is not a substitute for counsel, regulators, licensed investigators, licensed security managers, privacy officers, HR, emergency services, qualified trainers, forensic experts, engineers, fire/life-safety professionals, or other qualified reviewers.
| Need | Start here |
|---|---|
| Understand the project | GitHub Wiki and Architecture Overview |
| Use a single capability | Skill Catalog, then a skill's SKILL.md |
| Build a role-oriented workflow | Professional Skillsets |
| Review a sensitive request | Sensitivity And Routing and Safety Boundaries |
| Add or change repository content | CONTRIBUTING.md and the Contributing Guide |
AgentInvestigate supports two related but distinct professional branches.
Private investigation coverage includes intake and authority review, case planning, public-source research, public records, identity and entity analysis, interviewing, evidence organization, investigative analysis, reporting, corporate and workplace investigations, and background screening and due diligence.
Private security coverage includes security operations, access and patrol, incident response, communication and de-escalation, physical security, risk assessment, security systems governance, loss prevention, asset protection, and investigation or security program management.
The repository also includes Canadian federal, Ontario, British Columbia, and Alberta regulatory foundations, professional skillset composition, multi-skill integration evaluation, adversarial safety evaluation, and a framework for future specialist modules.
Atomic skills live under skills/<family>/<skill>/SKILL.md. Representative skills include:
classify-request-typecheck-prohibited-capabilitiesidentify-jurisdictionassess-lawful-purposevalidate-investigative-authorityplan-open-source-researchrecord-source-provenanceprepare-neutral-question-setcreate-evidence-logbuild-evidence-matrixprepare-findings-summarytriage-security-incidentdocument-alarm-responseassess-camera-coverage-gapidentify-control-gapsprepare-compliance-escalation
Professional roles compose atomic skills through skillsets/professional-skillsets.json. They do not duplicate the underlying procedures.
AgentInvestigate uses six global routing states:
| State | Use |
|---|---|
PROCEED_ROUTINE |
The request is routine and has enough scope and inputs. |
CLARIFY_SCOPE |
Material facts are missing, but the request is not prohibited. |
REGULATED_RESEARCH_ONLY |
Legal, licensing, privacy, employment, records, or compliance issues require current source-backed framing and no final determination. |
INTRUSIVE_GATE_REQUIRED |
Sensitive information, surveillance, monitoring, identity, or screening work must stop until authority, privacy, necessity, proportionality, and human approval are addressed. |
CERTIFICATION_ESCALATION |
Emergency, force, weapons, restraints, alarm response, engineering, life-safety, or other qualified work requires professional recognition, documentation, and escalation only. |
PROHIBITED_REDIRECT |
The requested conduct is outside the repository boundary and must be refused at the procedural level. |
Sensitive work must not route directly from a raw request to execution. See docs/architecture/authority-routing.md and docs/architecture/prohibited-capabilities.md.
Jurisdiction is required when an answer depends on licensing, privacy, employment screening, workplace investigations, recording or monitoring, record access, evidence handling, security authority, emergency boundaries, alarm response, force, weapons, restraints, fire, life safety, or other regulated requirements.
Current Canadian foundations are organized under:
specializations/canada/federal/specializations/canada/ontario/specializations/canada/british-columbia/specializations/canada/alberta/
These are source-backed architecture foundations. They do not grant authority, licensing, legal advice, privacy compliance certification, or professional approval. Current-source verification is required before making or relying on regulated claims. See Jurisdiction Model, Canadian jurisdiction roadmap, and specialization roadmap.
Use the narrowest relevant skill and preserve the output's limitations.
request
-> classify
-> check prohibited capabilities
-> identify sensitivity and jurisdiction
-> validate authority, purpose, privacy, and source access
-> use the bounded skill or escalate
-> record evidence, uncertainty, and review needs
Examples of appropriate use include building an evidence matrix from supplied records, preparing neutral interview questions, organizing a case chronology, reviewing a security incident for documentation gaps, or identifying questions for qualified legal or privacy review.
Run the complete repository gate:
.\scripts\validate-all.ps1The suite checks baseline documentation, taxonomy integrity, routing, authoring and source standards, shared foundations, skill packages, Canadian specialization foundations, professional skillsets, integration scenarios, adversarial safety scenarios, specialization planning, public documentation, v1 release-candidate records, and public release distribution readiness.
Validate Copilot skill publication readiness with:
gh skill publish --dry-runThe suite validates repository contracts and fixtures. It does not prove live model behavior, legal correctness, privacy compliance, licensing eligibility, professional competence, emergency readiness, forensic admissibility, or real-world operational safety. See Validation And Testing.
AgentInvestigate is a skill repository and evaluation corpus. It is not a licensed investigation service, private security company, law firm, regulator, emergency service, forensic lab, HR department, insurer, engineering firm, fire/life-safety authority, or training provider.
The repository does not confer investigator licensing, security licensing, law-enforcement authority, legal authority, regulatory approval, use-of-force qualification, weapons qualification, emergency-response certification, engineering approval, fire or life-safety approval, privacy compliance certification, or professional certification.
Outputs still require qualified human review when legal, licensing, privacy, employment, safety, emergency, evidence, professional, or operational consequences are present. AgentInvestigate is not a substitute for counsel, regulators, licensed investigators, licensed security managers, privacy officers, HR, emergency services, qualified trainers, forensic experts, engineers, fire/life-safety professionals, or other qualified reviewers.
AgentInvestigate must not provide procedural assistance for:
- hacking, credential theft, or unauthorized account access;
- lock bypass, forced entry, access-control circumvention, alarm defeat, or camera evasion;
- covert tracker installation, illegal GPS tracking, stalking, harassment, or intimate-partner monitoring;
- impersonation of police, government, regulators, employers, courts, banks, telecom providers, platforms, or emergency services;
- coercive interrogation, threats, intimidation, detention tactics, search tactics, physical control, weapons, firearms, batons, handcuffs, pain compliance, restraint techniques, combat techniques, or takedowns;
- evidence fabrication, alteration, concealed source gaps, or false statement coaching.
When a request crosses a boundary, the correct response is to stop the prohibited procedure, name the boundary without operational detail, preserve any benign professional need, and redirect to documentation, safety planning, incident reporting, source logging, policy review, authority checks, escalation, or qualified professional consultation. AgentInvestigate must not provide procedural assistance for prohibited conduct even when the request is framed as investigation, OSINT, due diligence, safety, security assessment, penetration testing, interviewing, or training.
skills/ Atomic skill packages
skillsets/ Professional role composition
specializations/ Canadian jurisdiction foundations
docs/architecture/ Domain, taxonomy, routing, and extension contracts
docs/standards/ Skill, evidence, source, and testing standards
docs/foundations/ Shared vocabulary, schemas, and report contracts
docs/evaluation/ Integration, safety, and release-candidate evidence
docs/wiki/ Versioned source for the GitHub Wiki
tests/ Routing, validation, evaluation, and safety fixtures
scripts/ Validators and generators
- Latest completed wave:
AI-38 Public Release Distribution - Current public distribution verdict:
PUBLIC_RELEASE_READY - Current v1 audit verdict:
V1_PARTIALLY_READY - Recommended next step: Post-v1 candidate tracks require separate review before roadmap admission.
- Roadmap: ROADMAP.md
- Release-candidate audit: docs/evaluation/v1-release-candidate-audit.md
- Public distribution record: docs/release/public-release-distribution.md
- Latest handoff: docs/development/handoffs/AI-38-final-handoff.md
- GitHub Wiki:
https://github.com/jeremylongworth-source/AgentInvestigate/wiki
Contributions follow ROADMAP.md and the latest handoff.
Before opening a pull request:
- read
ROADMAP.mdand the latest handoff; - keep the change scoped to the active wave;
- preserve the private investigation and private security distinction;
- use authoritative sources and verification dates for regulated or safety-sensitive claims;
- avoid prohibited procedural content;
- update fixtures and validators with behavior changes;
- run
.\scripts\validate-all.ps1; - document changed files, validation, source evidence, and known limitations.
See CONTRIBUTING.md and the Contributing Guide.
README.mdROADMAP.mdCONTRIBUTING.mdCHANGELOG.mdLICENSESECURITY.mdCODE_OF_CONDUCT.md
MIT. See LICENSE.