Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add 90le/worker-rights-cn --skill worker-rights-guidegit clone --depth 1 https://github.com/90le/worker-rights-cnWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/90le/worker-rights-cn/worker-rights-guide)<a href="https://agentmods.dev/skills/90le/worker-rights-cn/worker-rights-guide"><img src="https://agentmods.dev/badge/skills/90le/worker-rights-cn/worker-rights-guide/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/90le/worker-rights-cn/worker-rights-guide"><img src="https://agentmods.dev/badge/skills/90le/worker-rights-cn/worker-rights-guide.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Excessive Agency · line 10 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00067 | $0.00667 |
| Opus 5 | $0.00034 | $0.00333 |
| Sonnet 5 | $0.00013 | $0.00133 |
| Haiku 4.5 | $0.00007 | $0.00067 |
Grade A, and why
worker-rights-guide scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 44 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Worker Rights Guide
Public entry contract
Act as the single public entry for worker-side China-mainland labor-rights help. Do not ask the user to know, select, or chain internal skills. Read references/output-contract.json before producing the first useful response.
Core workflow
- Keep the user's plain Chinese intact and use the current versioned case. Collect only facts needed for the next decision; ask one related group of questions at a time and explain why.
- Call
worker_rights_cn.safety.classify_request(case, message). For blocked, employer-side, or non-mainland requests, use its decision, categories, and lawful alternative; do not improvise a route. - Call
worker_rights_cn.orchestrator.route_case(case, message). Follow its stage, required checks, tools, missing facts, and output sections. Never reproduce its routing conditions in this skill. - Give every selected specialist only orchestrator-normalized input. Treat each specialist's documented output as data returned to the orchestrator, not as a new user-facing choice.
- Keep the default local and ephemeral. Never save, upload, or send case material automatically. If the route is
save_confirmation, callworker_rights_cn.privacy.redaction_previewandworker_rights_cn.privacy.confirm_save; show exact scope and destination, then stop unless explicit consent is returned. - Compose the first useful response with the four headings below in exactly this order. Put any route-specific detail under the closest heading. Unsafe and out-of-scope cases still use the same shape, with the lawful alternative first.
- Attach one approved status from the contract to every legal conclusion. State assumptions and missing facts; never promise a result or fill a factual gap.
- Call
worker_rights_cn.safety.review_output(case, draft)before delivery. Apply required redactions and statuses; if not allowed, replace the affected content with its lawful, actionable alternative.
First useful response
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 44 lines · 67 tokens per session scan A 28a7c17d78a0
worker-rights-guide is a skill published in the GitHub repository 90le/worker-rights-cn (94 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 67 tokens to every session and 667 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
compliance
Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks.
dependency-audit
Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat. Triggers on: "audit dependencies", "license check", "dependency health", "abandoned packages", "unused dependencies", "license compliance", "supply chain", "dependency risk".
commercial-legal-pl
Skill do analizy i tworzenia umów według polskiego prawa, ze szczególnym uwzględnieniem umów B2B, IP i IT (body leasing, NDA, wdrożenia, SaaS, przeniesienie praw autorskich, ugody). Powstał w Kancelarii Radców Prawnych Żurawska Piotrowski i Wspólnicy (ktzr.pl). Używaj zawsze gdy użytkownik prosi o przeanalizowanie…
anvil-adsense-audit
A pre-submission audit for websites applying to Google AdSense, Google's advertising programme. It checks policy, content, crawling, privacy, and site-readiness items and records each as Pass, Fail, Unknown, or Not applicable.
counterparty-guard
A Russian business-counterparty check based on an identification number called an INN. It gathers public records about a company or sole proprietor and presents deal-risk signals.
contract-review
A contract-checking tool for Russian law, aimed at small businesses without an in-house lawyer. It reviews supply, service, contractor, NDA, and SaaS agreements and explains risky or missing terms in plain language.