Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add alexclowe/awesome-copilot-cowork-plugins --skill regulatory-cautiongit clone --depth 1 https://github.com/alexclowe/awesome-copilot-cowork-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/alexclowe/awesome-copilot-cowork-plugins/regulatory-caution)<a href="https://agentmods.dev/skills/alexclowe/awesome-copilot-cowork-plugins/regulatory-caution"><img src="https://agentmods.dev/badge/skills/alexclowe/awesome-copilot-cowork-plugins/regulatory-caution/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/alexclowe/awesome-copilot-cowork-plugins/regulatory-caution"><img src="https://agentmods.dev/badge/skills/alexclowe/awesome-copilot-cowork-plugins/regulatory-caution.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00042 | $0.00827 |
| Opus 5 | $0.00021 | $0.00413 |
| Sonnet 5 | $0.00008 | $0.00165 |
| Haiku 4.5 | $0.00004 | $0.00083 |
Grade A, and why
regulatory-caution scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 48 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You hold the caution discipline for safety documentation work. When the user is drafting incident reports, audits, hazard analyses, or anything touching regulation, apply these rules automatically and without being asked.
Reporting obligations come before any draft
If the user describes a fatality, an in-patient hospitalization, an amputation, a loss of an eye, or any event that may carry an immediate statutory reporting duty, say so first, before producing any document:
This may be a reportable event. Report it to your regulator on their required timeline — in the US, OSHA requires fatalities within 8 hours and in-patient hospitalization, amputation, or eye loss within 24 hours. [Verify current requirements and your local equivalents.] Do not wait on this draft.
Then continue with the drafting help. The draft assists the paperwork that follows a report; it never sits in front of one. Never phrase a deadline in a way that implies the drafting work is the deadline.
Never certify compliance
You draft documentation. You do not determine whether an employer, a site, or a practice is compliant.
- Never write "this meets OSHA requirements," "this is compliant," "no violation," or any equivalent conclusion
- Never state that a hazard has been adequately controlled — describe the control that was implemented and leave adequacy to the person accountable for it
- Compliance determinations belong to the safety professional, and enforcement determinations belong to the regulator
Cite regulations as pointers, not as authority
Regulations change, differ by jurisdiction, and turn on facts you cannot see.
- When a specific requirement is relevant, name the form or standard and append
[verify current requirements]— for example: "OSHA Form 300A, posted February 1 through April 30 under 29 CFR 1904.32 [verify current requirements]" - Never invent a standard number, a citation, a threshold, an exposure limit, or a deadline. If you are not certain of the number, describe the obligation qualitatively and tell the user what to look up
- Assume nothing about jurisdiction. US OSHA rules do not apply everywhere, state plans differ from federal OSHA, and many sites carry additional customer or contractor requirements. Ask or flag rather than assume
- Industry-specific regimes (construction, maritime, mining, process safety, transport) layer on top of general requirements — flag when one likely applies rather than working around it
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 48 lines · 42 tokens per session scan A 27b5d65956d9
regulatory-caution is a skill published in the GitHub repository alexclowe/awesome-copilot-cowork-plugins (17 stars, last pushed 1mo ago), licensed MIT. It adds 42 tokens to every session and 827 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
general-counsel-reviewer
Reviews a proposal, business case, deck or plan in character as a General Counsel archetype, then saves a structured review document with a verdict, findings that cite the artifact, legal risks and five interrogation questions. Use when the user asks for a legal review, a general counsel pressure-test of a document…
works-council-reviewer
Reviews a proposal, business case, deck or rollout plan in character as a Works Council Representative archetype, then saves a structured review document with a verdict, findings that cite the artifact, employee-impact risks and five interrogation questions. Use when the user asks for a works council review, an…
personal-data-protection
Personal-data-protection compliance reference for engineers building applications subject to Singapore PDPA, Indonesia UU PDP 27/2022, Thailand PDPA B.E. 2562 (2019), Malaysia PDPA 2010 (with the 2024 Amendments), or Philippines DPA (RA 10173). Use when reviewing or modifying code that touches personal data …
eu-ai-act-readiness
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency, high-risk controls, general-purpose AI obligations, governance, and implementation milestones. Use when an organization…
compliance-checklist-generation
Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities. Use when the user needs an internal readiness assessment or control-mapping plan; do not use it to certify compliance or replace an auditor or counsel.
license-analysis
Analyze open-source license compatibility, obligations, and compliance risks across project dependencies. Use when the user requests license analysis or provides relevant inputs for this workflow.