Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add alexclowe/awesome-copilot-cowork-plugins --skill high-risk-classificationgit clone --depth 1 https://github.com/alexclowe/awesome-copilot-cowork-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/alexclowe/awesome-copilot-cowork-plugins/high-risk-classification)<a href="https://agentmods.dev/skills/alexclowe/awesome-copilot-cowork-plugins/high-risk-classification"><img src="https://agentmods.dev/badge/skills/alexclowe/awesome-copilot-cowork-plugins/high-risk-classification/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/alexclowe/awesome-copilot-cowork-plugins/high-risk-classification"><img src="https://agentmods.dev/badge/skills/alexclowe/awesome-copilot-cowork-plugins/high-risk-classification.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00025 | $0.00705 |
| Opus 5 | $0.00013 | $0.00352 |
| Sonnet 5 | $0.00005 | $0.00141 |
| Haiku 4.5 | $0.00003 | $0.00071 |
Grade A, and why
high-risk-classification scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to high-risk-classification — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You have deep expertise in AI-system risk classification under the EU AI Act, US-state AI laws, and sector overlays. When the user is describing or auditing an AI system, apply this knowledge automatically.
Core competencies
EU AI Act Annex III categories:
- Annex III(1) Biometric identification, categorization, and emotion recognition
- Annex III(2) Critical infrastructure (road traffic, water/gas/heating/electricity supply)
- Annex III(3) Education and vocational training (admission, evaluation, proctoring)
- Annex III(4) Employment, worker management, access to self-employment (recruitment, task allocation, performance evaluation, termination)
- Annex III(5) Access to essential private and public services (credit, benefits, emergency response triage, life/health insurance pricing)
- Annex III(6) Law enforcement (risk assessment, polygraph, evidence reliability, profiling)
- Annex III(7) Migration, asylum, and border control management
- Annex III(8) Administration of justice and democratic processes
Prohibited practices (Article 5):
- Subliminal manipulation, exploitation of vulnerabilities
- Social scoring by public authorities
- Real-time remote biometric identification in public spaces (with narrow exceptions)
- Predictive policing based solely on profiling
- Emotion inference in workplace and education (with medical/safety exceptions)
- Untargeted facial-recognition database scraping
US-state and federal overlays:
- Colorado AI Act (SB 24-205) — high-risk AI in consequential decisions, effective Feb 2026
- NYC Local Law 144 — automated employment decision tools, bias audit requirement
- Illinois AI Video Interview Act and BIPA
- California ADMT regulations (CPPA), AB 2013 training-data transparency
- Texas TRAIGA (effective 2026)
- FINRA model risk and 2026 autonomous-agent supervisory framework
- FDA AI/ML-enabled device pathway and post-market monitoring
- HUD AI fair-housing guidance, CFPB algorithmic credit decisioning
Provider vs deployer distinction:
- Provider obligations (Art. 16): conformity assessment, technical documentation, registration, post-market monitoring
- Deployer obligations (Art. 26): human oversight, input data appropriateness, monitoring, fundamental-rights impact assessment for public bodies (Art. 27)
- The same organization can be both — flag mixed status when relevant
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 57 lines · 25 tokens per session scan A 60b3b3fc09f5
high-risk-classification is a skill published in the GitHub repository alexclowe/awesome-copilot-cowork-plugins (17 stars, last pushed 1mo ago), licensed MIT. It adds 25 tokens to every session and 705 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to high-risk-classification, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
general-counsel-reviewer
Reviews a proposal, business case, deck or plan in character as a General Counsel archetype, then saves a structured review document with a verdict, findings that cite the artifact, legal risks and five interrogation questions. Use when the user asks for a legal review, a general counsel pressure-test of a document…
works-council-reviewer
Reviews a proposal, business case, deck or rollout plan in character as a Works Council Representative archetype, then saves a structured review document with a verdict, findings that cite the artifact, employee-impact risks and five interrogation questions. Use when the user asks for a works council review, an…
personal-data-protection
Personal-data-protection compliance reference for engineers building applications subject to Singapore PDPA, Indonesia UU PDP 27/2022, Thailand PDPA B.E. 2562 (2019), Malaysia PDPA 2010 (with the 2024 Amendments), or Philippines DPA (RA 10173). Use when reviewing or modifying code that touches personal data …
eu-ai-act-readiness
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency, high-risk controls, general-purpose AI obligations, governance, and implementation milestones. Use when an organization…
compliance-checklist-generation
Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities. Use when the user needs an internal readiness assessment or control-mapping plan; do not use it to certify compliance or replace an auditor or counsel.
license-analysis
Analyze open-source license compatibility, obligations, and compliance risks across project dependencies. Use when the user requests license analysis or provides relevant inputs for this workflow.