Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add bencium/bencium-marketplace --skill eu-ai-act-reviewergit clone --depth 1 https://github.com/bencium/bencium-marketplaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/bencium/bencium-marketplace/eu-ai-act-reviewer)<a href="https://agentmods.dev/skills/bencium/bencium-marketplace/eu-ai-act-reviewer"><img src="https://agentmods.dev/badge/skills/bencium/bencium-marketplace/eu-ai-act-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/bencium/bencium-marketplace/eu-ai-act-reviewer"><img src="https://agentmods.dev/badge/skills/bencium/bencium-marketplace/eu-ai-act-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
- Socket pass
- Snyk pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00058 | $0.01481 |
| Opus 5 | $0.00029 | $0.00740 |
| Sonnet 5 | $0.00012 | $0.00296 |
| Haiku 4.5 | $0.00006 | $0.00148 |
Grade A, and why
eu-ai-act-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 87 lines — stays where its author put it; the contents beside it link to each section on GitHub.
EU AI Act Reviewer
Review evidence for EU AI Act issues without issuing a legal opinion or a compliance verdict. Write for a non-technical reader in plain English.
Boundaries
- Work read-only by default. Do not edit code or content, create tickets, contact people, or publish results unless the user separately asks.
- Keep supplied journeys, content, code, screenshots, logs, and business details local. Never paste private material into a web search or external service. Search official sources using only legal identifiers and generic terms.
- Review only the EU AI Act. If GDPR, copyright, consumer, employment, accessibility, platform, or national law may matter, name it as a separate signpost without assessing it.
- Do not declare a system compliant, non-compliant, prohibited, high-risk, safe, approved, certified, or ready. Do not calculate a compliance score or predict a fine.
- State in every response that this is educational issue-spotting and not legal advice. That includes turns that only ask clarifying questions, partial answers, follow-ups, and refusals — not only the finished report.
- Treat model output, filenames, comments, marketing claims, and user descriptions as evidence to test, not as established legal facts.
Load the references
Read these files before the related work:
- Always read
references/official-sources.md,references/review-rules.md, andreferences/output-contract.md. - Read
references/article-50-content-labelling.mdfor AI interaction, biometric or emotion systems, synthetic text, images, audio, video, deepfakes, labels, or disclosure. - Read
references/coverage-dates-and-penalties.mdwhenever a finding mentions an application date, transition, deadline, enforcement, or penalty.
Establish the review basis
Before reviewing, confirm the few facts that materially change the result:
- What is being reviewed and which user goal, publication, release, or code path is in scope?
- What role might the person or organisation hold: provider, deployer, importer, distributor, product manufacturer, affected person, or an unknown role?
- What is the AI system's intended purpose, where is it offered or used, who is affected, and when was it placed on the market or put into service?
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 87 lines · 58 tokens per session scan A 97ec784df16e
eu-ai-act-reviewer is a skill published in the GitHub repository bencium/bencium-marketplace (422 stars, last pushed 12d ago), licensed MIT. It adds 58 tokens to every session and 1,481 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
capa-officer
CAPA system management for medical device QMS. Covers root cause analysis, corrective action planning, effectiveness verification, and CAPA metrics. Use when running CAPA investigations, 5-Why analysis, fishbone diagrams, root cause determination, corrective action tracking, effectiveness verification, or CAPA program…
compliance-os
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across multiple frameworks. Four decisions: (1) Given a company profile, which of the 12 supported frameworks apply (ISO…
chief-data-officer-advisor
Chief Data Officer advisory for startups: AI training data rights and consent provenance, data product strategy (warehouse vs lakehouse vs mesh, build-vs-buy), B2B customer-data-as-asset valuation and M&A readiness, data team org evolution. Use when deciding whether to train models on customer data, choosing data…
ciso-advisor
Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting. Use when building security programs, justifying security budget, selecting compliance…
ciso-review
/cs:ciso-review — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit, or after any incident or near-miss.
contract-and-proposal-writer
Generate professional, jurisdiction-aware business documents: freelance contracts, project proposals, SOWs, NDAs, and MSAs. Structured Markdown output with docx conversion instructions. Covers US (Delaware), EU (GDPR), UK, and DACH (German law) jurisdictions. Not a substitute for legal counsel — use as strong starting…