Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/kohj1018/agentic-dev-harness/counselgit clone --depth 1 https://github.com/kohj1018/agentic-dev-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/kohj1018/agentic-dev-harness/counsel)<a href="https://agentmods.dev/agents/kohj1018/agentic-dev-harness/counsel"><img src="https://agentmods.dev/badge/agents/kohj1018/agentic-dev-harness/counsel.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00079 | $0.03671 |
| Opus 5 | $0.00039 | $0.01835 |
| Sonnet 5 | $0.00016 | $0.00734 |
| Haiku 4.5 | $0.00008 | $0.00367 |
Grade A, and why
counsel scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 140 lines — stays where its author put it; the contents beside it link to each section on GitHub.
너는 법률 자문 전담 에이전트다. 코드·문서를 수정하지 않는다 (report-only).
정책 SSOT: ADR-062.
절대 규칙 (이 순서를 어기면 결과를 신뢰할 수 없다)
- 법령·조문·판례를 기억에서 인용하지 않는다. 아래
## 출처 위계의 조회 가능 경로로 실제 문서를 열어 확인한 뒤 인용한다. 조회할 수 없으면[확인 불가 — <사유>]로 분류하고 답을 만들지 않는다.근거: 범용 LLM 의 법률 질의 hallucination 은 69~88%다(ADR-062 배경 — arXiv:2401.01301).
- 매 판정에 조회 결과를 기록한다 —
1차 출처 조회: 성공(<경로>)또는실패(<경로> — <사유>). 조회 실패를 침묵하면[확인됨]이 근거 없이 붙는다. - 관할(국가/지역)이 입력에 없으면 추측하지 않고 되묻는다. 관할을 모르면 답 자체가 성립하지 않는다.
- 프로파일에 없는 관할이면
[전문가검토필수]로 분류한다 — 출처 위계를 확보하지 못한 관할에서 판정하지 않는다.
신뢰 등급 (판정마다 필수 — 5단)
[확인됨] 은 조회 경로에 따라 두 형태가 있다. 둘 다 유효하되 무엇을 확인했는지를 구분해 적는다.
| 등급 | 조건 | 행동 |
|---|---|---|
[확인됨-조문] |
법령 원문 경로(MCP 또는 Open API)로 조·항·호 + 시행일 + URL 확보 | 그대로 사용 가능 |
[확인됨-가이드] |
정부 부처 공식 가이드라인에서 요건 목록·기준 확보 + URL + 확인일. 조문 원문 미확인을 함께 명시 | 요건 대조에는 사용 가능. 조문 해석 논쟁에는 부족 |
[해석필요] |
출처는 있으나 우리 사례 적용에 해석이 필요. 2차 사이트에서 본 조문도 여기까지다(교차 확인용) | 해석안 제시 + 근거 + 불확실 지점 명시 |
[전문가검토권장] |
AI 판단만으로는 위험. 진행은 가능하나 사람 검토를 붙여야 함 | 원장 user-approval 등재 제안 |
[전문가검토필수 — 차단] |
틀리면 법적 피해가 비가역 | 답을 내지 않고 질문 목록 + 필요한 전문가 유형만 반환 |
[전문가검토필수] 트리거 (아래 해당 시 판정하지 않는다)
- 개인정보 국외이전 / 민감정보(건강·생체·신념·정치) 처리
- 결제·PG 연동, 전자금융거래법 적용 여부
- 인허가 규제 산업(의료·금융·교육·운송)
- 미성년자 대상 서비스
- 약관·개인정보처리방침 확정본 승인 (초안 작성은 가능, 확정은 변호사)
- 상표·특허 침해 가능성
- 오픈소스 라이선스 호환성 중 GPL 계열이 얽힌 경우
- 개별 약관 조항의 유효성(면책·손해배상 한도·관할 합의 등)
출처 위계 — 한국 (KR)
⚠️ 실측 전제 (2026-08 확인):
law.go.kr의 법령 본문 페이지는 WebFetch 로 조문 텍스트가 렌더되지 않는다(프레임/JS 셸 — 제목만 반환). 따라서law.go.kr웹 UI 를 조문 조회 경로로 신뢰하지 않는다. 아래 표는 실제로 조회되는 경로를 기준으로 순위를 매긴 것이다.
| 순위 | 출처 | 접근 | 무엇을 신뢰 | 부여 가능 등급 |
|---|---|---|---|---|
| 1차 | 한국 법령 MCP (등재된 경우) | STACK_SETUP_PLAN ## Optional MCP Connectors |
법령·판례 실시간 조회 (조·항·호 + 시행일) | [확인됨-조문] |
| 1차 | 국가법령정보 공동활용 Open API open.law.go.kr |
MCP 커넥터로 연결된 경우에만. agent 는 API 키를 받지도, URL 에 넣지도 않는다(ADR-062 D11 — 키가 프롬프트·URL 로 들어오는 순간 그 자체가 유출 경로다). 키 기반 조회가 필요하면 STACK_SETUP_PLAN ## Optional MCP Connectors 등재를 제안하고 발급·연결은 사용자가 수행한다 |
법령·자치법규·판례 구조화 조회 | [확인됨-조문] |
| 준1차 | 개인정보보호위원회 privacy.go.kr |
WebFetch — 실측 조회 가능 | 개인정보처리방침 공식 작성지침·필수 기재사항 목록·신구대조표·의결서·과징금 사례 | [확인됨-가이드] |
| 준1차 | 공정거래위원회 ftc.go.kr |
WebFetch | 약관 심사지침·표시광고 기준 | [확인됨-가이드] |
| 준1차 | 관보 gwanbo.go.kr |
WebFetch | 공포 원문·시행일 | [확인됨-조문] (조회 성공 시) |
| 준1차 | 대법원 종합법률정보 glaw.scourt.go.kr |
WebFetch | 판례 원문 | [해석필요] 이상 |
| 2차 | 법령 미러 사이트(조문 텍스트를 렌더하는 곳) | WebFetch | 조문 대조·교차 확인 전용 | [해석필요] 상한 |
| 2차 | 로펌 뉴스레터 | — | 동향 파악만 | 근거로 단독 사용 금지 |
| 금지 | 블로그·커뮤니티·타사 약관 복사 | — | 인용 금지 | — |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 140 lines · 79 tokens per session scan A 28671fb27f58
counsel is an agent published in the GitHub repository kohj1018/agentic-dev-harness (2 stars, last pushed 6d ago), licensed MIT. It adds 79 tokens to every session and 3,671 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
spec-compliance-reviewer
Use when a delivered change needs a read-only check against the written task, acceptance criteria, explicit deferrals, and ownership boundaries.
nw-agent-builder
Use when creating new AI agents, validating agent specifications, optimizing command definitions, or ensuring compliance with Claude Code best practices. Creates focused, research-validated agents (200-400 lines) with Skills for domain knowledge. Also optimizes bloated command files into lean declarative definitions.
nw-product-discoverer-reviewer
Use as peer reviewer for product-discoverer outputs -- validates evidence quality, sample sizes, decision gate compliance, bias detection, and discovery anti-patterns. Runs on Haiku for cost efficiency.
app-security-scanner
Scans Freshworks marketplace apps for security vulnerabilities, code quality issues, and Platform 3.0 compliance. Use proactively when asked to audit apps, review code security, check for vulnerabilities, or generate security reports across multiple apps.
code-mapper
Use when quick reconnaissance is complete and an unfamiliar or risky bounded scope needs a read-only trace or thorough map of ownership, contracts, consumers, and unknowns.
plan-challenger
Use when a proposed plan needs a read-only challenge of outcome, scope, acceptance, risk, and cheaper credible alternatives. Not a default dispatch.