Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add Buildwise-Studios/claude-for-hk-law/plugin install ai-governance-legalWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/buildwise-studios/claude-for-hk-law/cold-start-interview)<a href="https://agentmods.dev/skills/buildwise-studios/claude-for-hk-law/cold-start-interview"><img src="https://agentmods.dev/badge/skills/buildwise-studios/claude-for-hk-law/cold-start-interview/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/buildwise-studios/claude-for-hk-law/cold-start-interview"><img src="https://agentmods.dev/badge/skills/buildwise-studios/claude-for-hk-law/cold-start-interview.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00099 | $0.10576 |
| Opus 5 | $0.00049 | $0.05288 |
| Sonnet 5 | $0.00020 | $0.02115 |
| Haiku 4.5 | $0.00010 | $0.01058 |
Grade A, and why
cold-start-interview scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
94% identical to cold-start-interview — 34 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 689 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/cold-start-interview
- Check
~/.claude/plugins/config/claude-for-hk-law/ai-governance-legal/CLAUDE.md— if populated and no--redo, confirm before overwriting. - Run the interview using the workflow below (includes Part 0 role + integration check).
- Seed docs: AI/acceptable use policy (URL or file), a prior impact assessment, key vendor AI agreements, model inventory or allowlist/blocklist if they exist. Read all provided.
- Extract: policy commitments and prohibitions, vendor positions (note gaps vs. stated), impact assessment structure, approved/prohibited tool lists.
- Migration: if a populated CLAUDE.md (no
[PLACEHOLDER]markers) exists at~/.claude/plugins/cache/claude-for-hk-law/ai-governance-legal/*/CLAUDE.mdbut not at the config path, copy it to the config path and tell the user what was migrated. - Write
~/.claude/plugins/config/claude-for-hk-law/ai-governance-legal/CLAUDE.md(create parent directories as needed). Show summary. Offer first task.
Flags
--redo— re-run the full interview and overwrite~/.claude/plugins/config/claude-for-hk-law/ai-governance-legal/CLAUDE.md.--check-integrations— re-scan available MCP connectors and refresh the## Available integrationstable in~/.claude/plugins/config/claude-for-hk-law/ai-governance-legal/CLAUDE.mdwithout re-running the full interview. Use after setting up a new connector (Slack, document storage, scheduled-tasks).
When probing: only report ✓ if an MCP tool call actually succeeded. Configured-but-untested connectors should be marked ⚪ with a one-line how-to for confirming. Never report ✓ based on .mcp.json declarations alone — that misleads users into thinking something is wired up when it isn't.
/ai-governance-legal:cold-start-interview
/ai-governance-legal:cold-start-interview --check-integrations
Purpose
Learn how this AI governance team works — what role the company plays in the AI supply chain, which regulations actually apply to them, what their red lines are for AI use cases, and what good impact assessment looks like here. Write it into the plugin config so every other skill reads from the same understanding.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 689 lines · 99 tokens per session scan A 60c97b80f6ce
cold-start-interview is a skill published in the GitHub repository Buildwise-Studios/claude-for-hk-law (5 stars, last pushed 3mo ago), licensed Apache-2.0. It adds 99 tokens to every session and 10,576 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. It is 94% identical to cold-start-interview, differing in 34 lines, and is treated as a copy.
Other skills, from other repositories
c2pa-metadata
Embed a C2PA provenance manifest into an AI-generated marketing asset (PNG, JPG, WebP, GIF, TIFF, MP4, MOV, WebM, MP3, WAV, PDF) via scripts/embed-c2pa.py — produces a signed copy of the file carrying IPTC digital-source-type AI claims, an optional c2pa.ai-disclosure assertion for EU AI Act Article 50 (applicable 2…
privacy-jp
A Japanese-language document generator for services built with Next.js. It creates privacy policies, terms of service, consent dialogs, and cookie banners while considering Japan's personal-information and consumer-protection laws.
revenue-recognition
Determines when and how revenue is recognized — performance obligations, contract terms that change the answer, and the deal structures that create accounting problems. Use this to work out how a contract should be recognized, review a non-standard deal before it is signed, understand deferred revenue, or spot terms…
employment-compliance
Covers the employment rules that carry real penalties — exempt and non-exempt classification, overtime and hours, employee versus contractor status, work authorization and recordkeeping, accommodation requests, and the notices and retention obligations that go with them. Use this to classify a role, review a…
performance-management
Runs performance systems that change behavior — expectations, feedback, review cycles, calibration, and handling underperformance. Use this to design or fix a review process, run calibration, write or coach on feedback, address sustained underperformance, or work out why reviews consume weeks and change nothing.
contract-review
Reviews and negotiates commercial agreements — MSAs, SOWs, order forms, NDAs, vendor and data-processing agreements — identifying material risk, proposing positions, and recommending a path rather than listing issues. Use this to review a contract before signature, prepare a negotiation position, build fallback…