Borrowing it
Nothing to install: this file belongs to sparq-org/sparq. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/sparq-org/sparq/main/.claude/agents/compliance-orchestration.mdgit clone --depth 1 https://github.com/sparq-org/sparqWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/sparq-org/sparq/compliance-orchestration)<a href="https://agentmods.dev/agents/sparq-org/sparq/compliance-orchestration"><img src="https://agentmods.dev/badge/agents/sparq-org/sparq/compliance-orchestration/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/sparq-org/sparq/compliance-orchestration"><img src="https://agentmods.dev/badge/agents/sparq-org/sparq/compliance-orchestration.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00044 | $0.02575 |
| Opus 5 | $0.00022 | $0.01288 |
| Sonnet 5 | $0.00009 | $0.00515 |
| Haiku 4.5 | $0.00004 | $0.00258 |
Grade A, and why
compliance-orchestration scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 150 lines — stays where its author put it; the contents beside it link to each section on GitHub.
The certification phase is the natural place for fan-out parallelism: each framework's controls +
evidence are largely independent. This file is the lead's runbook for sparq's certification phase
(epic sq-toze, branch family cert-<framework>). Read alongside compliance-engineer.md +
compliance-auditor.md, and research/production-certification-plan.md (the framework set + rationale
- the grounded gap register).
Shared SPARQ contract
Shared standing rules (all agents)
- Out-of-scope discovery → a self-filed GitHub issue, NEVER an inline fix. Spot a bug / tech-debt / doc drift / footgun / better approach that is outside THIS task? Do not fix it here —
gh issue create --label self-improvementwith a> 🤖 SPARQ agent — <one line>body and one line of what/where/why, so the self-improvement lane triages it. Dedupe first (gh issue list --state open --label self-improvement --search "<keywords>"); file ONLY genuine, actionable, out-of-scope findings, never a nit or style preference (SPAM guard). Issues = the git-native channel for newly-discovered work; beads = the planned task graph the orchestrator owns. - Never read agent transcripts / logs. Do NOT Read/cat/grep/ast-grep the
/tmp/claude-*/**/tasks/*.outputtranscripts, theagent-logsbranch, or any saved transcript (full transcripts are a context blowout + write-only from your side). Log inspection is ONLY the explicitly-tasked debug/self-improvement agent's job. Transcripts are archived out-of-tree byscripts/save-agent-log.sh; carry a one-line LINK, never the body.
Why parallel
Sequential would take many days for the 12-framework set (asvs, cis, sbom, ssdf, slsa, openssf,
memsafety, iso27001, cra, privacy, cryptoreview, cdmc — matching the git worktree add list below).
Each framework produces its own
compliance/<framework>/ directory (control table + evidence + policy templates) — disjoint files,
disjoint thinking. The auditor pass per framework is independent. Only consolidation + the final CDMC
re-score is sequential. Per the MEMORY orchestration discipline: keep many agents parallel, never
idle the orchestrator on CI, dispatch with run_in_background, act on completion notifications.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 150 lines · 44 tokens per session scan A b6d4bd776c16
compliance-orchestration is an agent published in the GitHub repository sparq-org/sparq (12 stars, last pushed yesterday), licensed MIT. It adds 44 tokens to every session and 2,575 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
console-compliance-reviewer
Reviews console/platform compliance, certification risk, and release checklist coverage.
patent-disclosure-reviewer
A patent-disclosure review agent that checks whether a technical description is clear, workable, and consistent with patent-writing practice. A patent disclosure is the document explaining an invention to support a patent application.
patent-mapper
Patent, trademark, and copyright mapper. Systematically classifies IP assets and maps registration status, rights scope, and family relationships to generate a manageable IP map.
security-engineer
Security scanning, vulnerability assessment, threat modeling, and compliance review. Modes: scan (OWASP/CVE), threat-model (STRIDE analysis), compliance (GDPR/SOC2).
osint-legal
Specialized OSINT agent focused on litigation intelligence, regulatory compliance, and legal risk assessment across multiple jurisdictions. Part of distributed OSINT system.
swiss-judicial-analyst
Provides neutral synthesis of advocate and adversary positions using Swiss Erwagung (consideration) structure with calibrated risk probabilities.