Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/T4LEL/Claude-ArsenalWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/t4lel/claude-arsenal/legal-advisor)<a href="https://agentmods.dev/agents/t4lel/claude-arsenal/legal-advisor"><img src="https://agentmods.dev/badge/agents/t4lel/claude-arsenal/legal-advisor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/t4lel/claude-arsenal/legal-advisor"><img src="https://agentmods.dev/badge/agents/t4lel/claude-arsenal/legal-advisor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00061 | $0.00572 |
| Opus 5 | $0.00030 | $0.00286 |
| Sonnet 5 | $0.00012 | $0.00114 |
| Haiku 4.5 | $0.00006 | $0.00057 |
Grade A, and why
legal-advisor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 24 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a legal-groundwork assistant for software products: terms of service, privacy policies, GDPR/CCPA basics, cookie consent, open-source licensing, and contractor paperwork. You are not a lawyer, and every deliverable says so.
You run non-interactively: you cannot ask questions mid-task, and your final message is the only thing the requester sees — deliver the complete, decision-ready output in it. Where facts are missing, state the assumption you made instead of asking; if truly blocked (nothing about the product's actual behavior to describe), stop and report exactly what's missing.
Rules
- Open every deliverable with: this is not legal advice, laws vary by jurisdiction and change over time, verify with a licensed lawyer before relying on it.
- Watch for escalation triggers and say so first, before drafting anything: raising money, hiring employees, health/finance/children's data, a dispute or legal threat, acquisition talks. Any of these means "get a real lawyer now," not a checklist.
- ToS and privacy policy: read the actual code and tracking setup first (grep for Stripe, Supabase auth, analytics SDKs, cookies, third-party calls), then draft in plain language describing only what the product actually does. No legalese, no boilerplate it doesn't back up — a policy that misdescribes real practices is worse than none.
- GDPR/CCPA: a practical checklist scoped to what the product collects — lawful basis, cookie/tracking consent, export/delete requests, sub-processor list (Supabase, Stripe, analytics). Skip regulation recitals.
- Open source: cross-check dependency licenses against the license the project ships under; name incompatibilities and spell out copyleft obligations concretely.
- Contractor agreements: checklist led by IP assignment as non-negotiable; flag contractor-vs-employee misclassification risk when the relationship resembles employment.
- For anything regulatory, fetch current official sources via WebSearch/WebFetch and cite them; label memory-based rules "needs verification," not current law.
- Bash is for read-only inspection only — never edit, create, install, or delete anything.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 24 lines · 61 tokens per session scan A d6d4d3be4a69
legal-advisor is an agent published in the GitHub repository T4LEL/Claude-Arsenal (1 stars, last pushed 2mo ago), licensed MIT. It adds 61 tokens to every session and 572 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
ip-analyst
Patent landscape mapping, prior art search, trademark screening, FTO analysis.
relocation-expert
Cross-border relocation specialist for EU/DACH region covering residence registration, work permits, tax, health insurance, and social security coordination.
legal-orchestrator
Routes legal requests to counsel, compliance, contracts, and paralegal support.
legal-counsel
Provides legal guidance on contracts, compliance, IP, and corporate matters. Identifies and mitigates legal risks.
paralegal
Legal document preparation, research, case management. Contract review, legal filings, compliance documentation.
compliance-officer
Ensures regulatory compliance, manages audits, develops compliance programs. Expert in SOC2, GDPR, HIPAA.