Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add abk1969/ai-act-skills --skill ai-act-compliancegit clone --depth 1 https://github.com/abk1969/ai-act-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/abk1969/ai-act-skills/ai-act-compliance)<a href="https://agentmods.dev/skills/abk1969/ai-act-skills/ai-act-compliance"><img src="https://agentmods.dev/badge/skills/abk1969/ai-act-skills/ai-act-compliance/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/abk1969/ai-act-skills/ai-act-compliance"><img src="https://agentmods.dev/badge/skills/abk1969/ai-act-skills/ai-act-compliance.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00243 | $0.08315 |
| Opus 5 | $0.00121 | $0.04158 |
| Sonnet 5 | $0.00049 | $0.01663 |
| Haiku 4.5 | $0.00024 | $0.00831 |
Grade A, and why
ai-act-compliance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 344 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AI Act Compliance — EU Regulation 2024/1689
What this skill does
Codifies actionable EU AI Act compliance expertise. Every output is traceable to one or more of:
- Regulation (EU) 2024/1689 — the AI Act — the legally binding source.
- ISO/IEC 42001:2023 — Artificial Intelligence Management System (AIMS), the certifiable management standard for AI providers and deployers.
- ISO/IEC 27090:2025 — Cybersecurity guidance for AI systems (the depth standard for AI Act art. 15 cybersecurity).
- Companion ISO standards: 23894 (AI risk management), 23053 (ML framework), 5338 (AI lifecycle), 5259-* (data quality), 24029-2 (robustness), 42005 (impact assessment), 42006 (audit & certification).
- CEN-CENELEC JTC 21 harmonised standards (under standardization mandate M/593) — the path to art. 40 presumption of conformity.
- GPAI Code of Practice — published 2025-07-10; assessed adequate by the Commission and AI Board on 2025-08-01 — the operative instrument for arts. 53–55 until harmonised standards land.
- AI Omnibus amendment (Digital Omnibus on AI) — adopted by Parliament (2026-06-16) and Council (2026-06-29); amends the AI Act's timeline and art. 5 prohibitions. See the timeline below.
This skill is decision-support, not legal advice. Always recommend the user consult qualified counsel for binding interpretation, and a notified body for conformity assessment of high-risk AI systems.
Scheduling at a glance — SSL machine view
This skill is paired with a machine-readable manifest at ssl.json, built per the Scheduling-Structural-Logical (SSL) representation introduced by Liang et al., From Skill Text to Skill Structure (arXiv:2604.24026, 2026). The manifest exposes the skill's invocation interface, scene graph, and atomic action evidence so registries, routers, and reviewers do not need to re-parse this document. The table below is the human-readable scheduling view; ssl.json is the authoritative typed version.
What ships with it
21 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- AGENTS.md 1.6 KB
- GEMINI.md 1.5 KB
- LICENSE 1.4 KB
- package.json 2.2 KB
- README.md 16 KB
- references/01-risk-classification.md 19 KB
- references/02-high-risk-obligations.md 27 KB
- references/03-iso-42001-aims.md 25 KB
- references/04-iso-27090-ai-security.md 26 KB
- references/05-crosswalk-aiact-iso.md 15 KB
- references/06-techdoc-annex-iv.md 16 KB
- references/07-fria-art27.md 18 KB
- references/08-transparency-art50.md 14 KB
- references/09-post-market-art72-73.md 19 KB
- references/10-gpai-and-timeline.md 20 KB
- references/11-art4-ai-literacy.md 11 KB
- references/12-art25-substantial-modification.md 13 KB
- references/13-sandboxes-and-real-world-testing.md 13 KB
- references/14-codes-and-right-to-explanation.md 15 KB
- references/15-platform-compatibility.md 9.5 KB
- ssl.json 28 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 344 lines · 243 tokens per session scan A 39f8ebba6a74
ai-act-compliance is a skill published in the GitHub repository abk1969/ai-act-skills (4 stars, last pushed 2mo ago), licensed MIT. It adds 243 tokens to every session and 8,315 once invoked, about $0.0012 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
eu-ai-act-art50-check
Check whether an AI model's PUBLIC artifacts meet EU AI Act Article 50 transparency signals (license declared, task declared, model card present) and get back a deterministic, signable result. Use this instead of reasoning about Article 50 obligations from memory — it returns observed facts from the public model-info…
vaara-governed-tool-call
Put an EU AI Act Article 14 human-oversight checkpoint and an Article 12 auditable record in front of a high-risk tool call. Use before an agent runs a consequential or irreversible action (writing to a clinical/genomic database, submitting a record to a regulator, moving money, deleting data, anything a human should…
policy
Define and enforce decision policies, compliance rules, and exceptions over Semantica graphs. Uses ContextGraph.checkdecisionrules/enforcedecisionpolicy and context.PolicyEngine.
dispute-respond
Prepare and explicitly file an evidence-bound payment dispute response using native receipt proof, approval, provider execution, and independent readback.
vuln-disclosure
Prepare an evidence-bound vulnerability publication and publish the exact approved advisory through any compatible provider binding with independent readback.
sign-receipt
Bind an off-runtime action claim to opaque evidence references in a signed Runx receipt without pretending Runx verified the external action.