Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add eigenlegal/counsel-os/plugin install counsel-osWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/eigenlegal/counsel-os/doctor)<a href="https://agentmods.dev/skills/eigenlegal/counsel-os/doctor"><img src="https://agentmods.dev/badge/skills/eigenlegal/counsel-os/doctor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/eigenlegal/counsel-os/doctor"><img src="https://agentmods.dev/badge/skills/eigenlegal/counsel-os/doctor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00153 | $0.05655 |
| Opus 5 | $0.00077 | $0.02828 |
| Sonnet 5 | $0.00031 | $0.01131 |
| Haiku 4.5 | $0.00015 | $0.00566 |
Grade D, and why
doctor scanned grade D with 3 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
| bun | Reading Word documents outside the runtime (`bun runtime/src/cli.ts docx read`), and building browse from source (the prebuilt binary auto-downloads on first use) | `curl -fsSL https://bun.sh/install \| bash` | Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
2. Read the marketplace clone's catalog: `ls ~/.claude/plugins/marketplaces/` to find the marketplace name, then Read `~/.claude/plugins/marketplaces/{marketplace}/.claude-plugin/marketplace.json` and take the counsel-os Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
| bun | Reading Word documents outside the runtime (`bun runtime/src/cli.ts docx read`), and building browse from source (the prebuilt binary auto-downloads on first use) | `curl -fsSL https://bun.sh/install \| bash` | How it starts
The opening of the file, as written. The whole thing — 290 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Doctor — Install Health Check
The vault checks below (steps 1, 2, 4B, 8, 10, 11) also run in the runtime, read-only:
bun runtime/src/cli.ts doctor,GET /doctor, and Check the vault under Settings › Runtime in the web UI (spec 2026-09-01 §7). The environment checks (pandoc, python, the browse binary, qmd) stay here.
You are running a health check on the user's Counsel OS install. Run every check below, collect the results, and present them as ONE table at the end — do not dump raw command output between checks, and do not narrate each step. Doctor is read-only: it never writes to the vault, the plugin tree, the config, or the home directory. Every non-healthy row gets a one-line fix command instead.
Status meanings:
- ✅ healthy — nothing to do
- ⚠️ degraded or optional capability missing — Counsel OS works, but something is suboptimal or a feature is unavailable
- ❌ broken — core functionality is unavailable until fixed
A check that cannot run in the current runtime is reported with status — and the reason (see Cowork / no-shell runtimes at the end). Never guess a result for a check you could not run.
Step 0: Capabilities and Plugin Root
Resolve the plugin root: ${CLAUDE_PLUGIN_ROOT} is set by Claude Code on every plugin invocation — use it directly in shell commands. If it is unset, the plugin root is the directory containing this skill's parent skills/ directory.
Determine what this session can do: shell access, home-directory reads, network access. Each check below states what it needs; degrade per the Cowork section rather than skipping silently.
Step 1: Legal Root and Config (❌ on failure)
Run the canonical resolver:
bash "${CLAUDE_PLUGIN_ROOT}/scripts/resolve_legal_root.sh"
Exit-code contract: 0 = exactly one marked root, stdout is the path; 1 = none found; 2 = multiple found (candidates on stderr).
- Exit
0→ Read{legal_root}/config.mdand verify two things: it containscounsel-os-config: true, and itslegal_root:value matches the resolved directory. Both good → ✅. Marker present butlegal_root:points elsewhere (stale copied config) → ⚠️, fix:edit {legal_root}/config.md so legal_root: matches its own directory. - Exit
1→ ❌, fix:/counsel-os:setup. - Exit
2→ ⚠️, list the candidates from stderr in the detail, fix:export COUNSEL_OS_LEGAL_ROOT=/path/to/the/right/one(or remove the stray config.md).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago Changed · -3 tokens per session 56ac98b8e3c5
- 12d ago First seen · 290 lines · 156 tokens per session scan D b18766b42cae
doctor is a skill published in the GitHub repository eigenlegal/counsel-os (24 stars, last pushed yesterday), licensed MIT. It adds 153 tokens to every session and 5,655 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it D with 3 findings (downloads and executes remote code, reads agent configuration directories, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…