Building with OpenAI, Anthropic, RAG pipelines, or vector DBs? GreatCTO auto-detects the ai-system archetype and ships EU AI Act risk-tier, OWASP LLM Top-10, eval golden-set, and cost-overrun gates from day one.
openai + pinecone →Compliance auto-suggested: eu-ai-act · owasp-llm-top-10. Specialist agents activated:
Outputs ADR-PROMPT-{name}.md with sha256-pinned prompt text, jailbreak resistance test cases, revision history.
tests/eval/EVAL-*.md — citation accuracy, refuse-when-uncertain, output schema, prompt injection, cost-overrun, cross-user isolation.
Prompt injection · output exfiltration · SSRF in tool layer · supply chain · cost runaway · cross-user isolation · model jailbreak · RAG poisoning.
Limited / High / Unacceptable risk classification. Article 9 risk management. Article 13 transparency. Conformity assessment readiness.
Packs auto-attach when CLI detects pack-specific signals (e.g. twilio in deps → voice-pack). Each pack adds its own reviewer agents + human gates on top of the base archetype pipeline.
20 startups in this space. Click for full pack mapping.
Listed companies operate in this space. Inclusion is based on publicly available product descriptions and does not imply endorsement of or by GreatCTO.
$ npx great-cto init