Docs

Quickstart

Three commands to install, then you’re classifying items, screening parties, and producing audit-ready memos — all locally, with zero ExChek telemetry.

No install needed? The hosted MCP (api.exchek.us/mcp) is now the recommended path — point any MCP-capable client at it, no download. This quickstart walks the local plugin, which is still supported but retiring soon.

Step 1 — Install the plugin

Cowork installs from a zip upload, not a marketplace command:

  1. Download the latest release zip: exchekskills v3.6.3 (.zip)
  2. In Cowork: Settings → Plugins → My Uploads → Upload, drop the file in.
  3. Run /plugin config exchekskills to configure (platform tier, optional Trade.gov key, optional audit HMAC key, default report folder). Full details on the Install page.

Step 2 — Classify an item

Use the slash command or just say what you need:

/exchek-classify

# or just:
"Classify this headlight housing unit for export"

The skill collects item details, fetches live regulatory data via the local MCP (eCFR Parts 774, 738, 740, 742, 744, 746, and 22 CFR 121), runs classification, asks you to confirm jurisdiction and ECCN, and produces an audit-ready Word memo with HMAC-chained audit log entry.

Step 3 — Screen parties (optional)

/exchek-csl

# or just:
"Screen Acme Trading against the CSL"

Live Trade.gov Consolidated Screening List search. Requires a free API key from developer.trade.gov (entered once during /plugin config, stored in your OS keychain). See CSL search skill.

Step 4 — Determine license requirements (optional)

/exchek-license

# or just:
"Do we need a license to ship 5A992 to Germany?"

License-requirement check across Parts 738, 740, 742, 744, 746. See License determination skill.

Step 5 — Run additional skills

20 skills total: jurisdiction (ITAR vs EAR), encryption, country risk, risk triage, red-flag assessment, deemed export, export docs, ECP generation, audit lookback, compliance report card, partner compliance, recordkeeping, document conversion, plus engine-shell skills (onboarding, analytics, orchestrator, setup). See the full slash command list.

Step 6 — Verify the audit log

Every report appends a tamper-evident entry to your local HMAC-chained audit log. Verify the chain any time:

mcp__exchek__audit_verify

The log lives on your machine. ExChek never sees it. The only outbound traffic is to www.ecfr.gov and data.trade.gov when a skill needs them.

Step 7 — Render audit-ready documents (optional)

The skills do the analysis for free. To typeset a determination into a branded, version-stamped, vault-stored PDF, render one of the seven audit-ready documents. The Restricted-Party Screening Certificate renders free; the others are unlimited on a subscription, or pay-per-document at $1 on the free tier. See Pricing for the Free, Starter, Professional, and Enterprise tiers.