Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add aAAaqwq/AGI-Super-Team --skill afrexai-compliance-enginegit clone --depth 1 https://github.com/aAAaqwq/AGI-Super-TeamWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/aaaaqwq/agi-super-team/afrexai-compliance-engine)<a href="https://agentmods.dev/skills/aaaaqwq/agi-super-team/afrexai-compliance-engine"><img src="https://agentmods.dev/badge/skills/aaaaqwq/agi-super-team/afrexai-compliance-engine/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/aaaaqwq/agi-super-team/afrexai-compliance-engine"><img src="https://agentmods.dev/badge/skills/aaaaqwq/agi-super-team/afrexai-compliance-engine.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.07491 |
| Opus 5 | $0.00000 | $0.03746 |
| Sonnet 5 | $0.00000 | $0.01498 |
| Haiku 4.5 | $0.00000 | $0.00749 |
Grade A, and why
afrexai-compliance-engine scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 833 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Compliance & Audit Readiness Engine
Your AI compliance officer. Guides startups and scale-ups through SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS — from zero to audit-ready. No consultants needed.
Phase 1 — Compliance Discovery
Framework Selection Matrix
| Framework | Who Needs It | Trigger | Timeline | Cost Range |
|---|---|---|---|---|
| SOC 2 Type I | Any B2B SaaS | Enterprise prospect asks | 3-6 months | $20K-$80K |
| SOC 2 Type II | Established SaaS | After Type I, or direct | 6-12 months | $30K-$100K |
| ISO 27001 | Global/EU-facing SaaS | EU enterprise deals | 6-12 months | $40K-$120K |
| GDPR | Anyone with EU users | Day 1 if EU data | 1-3 months | $5K-$30K |
| HIPAA | Health data handlers | Before first PHI | 3-6 months | $20K-$60K |
| PCI DSS | Payment processors | Before card data | 3-9 months | $15K-$50K |
| SOX | Public companies | IPO prep | 12-18 months | $100K-$500K |
Readiness Assessment Brief
company_profile:
name: ""
industry: ""
employee_count: 0
annual_revenue: ""
data_types_handled:
- PII (names, emails, addresses)
- Financial (payment cards, bank accounts)
- Health (PHI, medical records)
- Children (COPPA scope)
- Biometric
- Government/classified
customer_segments:
- SMB
- Mid-market
- Enterprise
- Government
geographic_scope:
- US only
- US + EU
- Global
current_state:
existing_frameworks: []
security_team_size: 0
has_written_policies: false
has_asset_inventory: false
has_risk_assessment: false
has_incident_response: false
has_vendor_management: false
previous_audits: []
known_gaps: []
drivers:
- Customer requirement
- Board/investor mandate
- Regulatory obligation
- Competitive advantage
- Insurance requirement
target_frameworks: []
target_date: ""
budget_range: ""
Priority Decision Rules
- Customer asking for SOC 2? → Start there (most requested in B2B SaaS)
- EU customers? → GDPR is non-negotiable, do it alongside SOC 2
- Health data? → HIPAA first, then layer SOC 2
- Payment data? → PCI DSS is legally required, do immediately
- Multiple frameworks? → Map common controls (40-60% overlap between SOC 2 and ISO 27001)
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 833 lines · 0 tokens per session scan A 59b7030a4785
afrexai-compliance-engine is a skill published in the GitHub repository aAAaqwq/AGI-Super-Team (91 stars, last pushed today), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 7,491 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
reviewing-data-privacy
Use when reviewing data privacy within security lifecycle boundaries, especially when does the artifact make the owned decision for reviewing data privacy explicit and bounded?.
mission-control
Interact with Mission Control — AI agent orchestration dashboard. Use when registering agents, managing tasks, syncing skills, or querying agent/task status via MC APIs.
clause
Reviewing legal documents for Terms of Service, Privacy Policy, and Tokushoho compliance. Detects clause gaps and flags risks. Not a substitute for legal advice — consult a lawyer.
compliance-notice-generate
Generate NOTICE, ATTRIBUTION, or THIRD-PARTY-NOTICES files from detected dependency licenses to fulfill open-source license obligations.
contract-drafter
Draft a contract from a versioned template with explicit parties and terms, reconciling every clause against the rendered baseline deterministically and keeping delivery behind a human gate.
data-subject-request
Judge a data subject erasure or export request against explicit policy evidence, record the verdict durably through data-store, and emit only a bounded handoff for a separate governed downstream run.