Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Gal-Davidzon/public-risk-intelligence-mcp --skill sos-company-researchgit clone --depth 1 https://github.com/Gal-Davidzon/public-risk-intelligence-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/gal-davidzon/public-risk-intelligence-mcp/sos-company-research)<a href="https://agentmods.dev/skills/gal-davidzon/public-risk-intelligence-mcp/sos-company-research"><img src="https://agentmods.dev/badge/skills/gal-davidzon/public-risk-intelligence-mcp/sos-company-research/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/gal-davidzon/public-risk-intelligence-mcp/sos-company-research"><img src="https://agentmods.dev/badge/skills/gal-davidzon/public-risk-intelligence-mcp/sos-company-research.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00071 | $0.00781 |
| Opus 5 | $0.00036 | $0.00391 |
| Sonnet 5 | $0.00014 | $0.00156 |
| Haiku 4.5 | $0.00007 | $0.00078 |
Grade A, and why
sos-company-research scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 38 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Public Risk Intelligence Company Research
Use the public-risk-intelligence MCP server as the state-policy, evidence-normalization, and investigation layer. Existing installations may expose the same compatible tools under a locally assigned sos-research alias. Prefer official sources and report uncertainty explicitly.
Workflow
- Identify the requested state and exact company-name query. If the state is missing, ask for it because US entity names are state-scoped.
- Call
get_state_accessbefore choosing a route. - When a supported official API is available, call
search_businesswithroute: "auto". Do not open a browser merely to duplicate the same result. - Otherwise call
prepare_browser_search, then execute that plan with the host's native browser capability. Use the user's named browser when they specify one. Search only the official registry URL returned by the tool and follow its verified state recipe exactly when present. - Convert visible result rows into
{fields, text, detail_url}records and callfinalize_browser_search. Use the final browser URL assource_url. This validates the official host and returns the same normalized evidence contract as an API search. - If a plan has no verified recipe, call
list_browser_recipe_candidatesfor that state. Treat a candidate as a hint only: validate its visible controls before using it. Once the official page has been searched, callrecord_browser_recipe_observationwith only public structural metadata (search control, submit control, result selector, visible column headings, and a challenge note). Never include search results, personal details, session data, cookies, or credentials in a recipe observation. - If the policy is
blocked, do not automate the interactive search. Explain the official bulk, paid, or manual alternative returned by the tool. - If the page presents a CAPTCHA or human-verification action, do not bypass it. Follow the browser client's confirmation or handoff rules and continue only if permitted.
- Stop after collecting the requested public evidence. Do not submit filings, purchase documents, create accounts, accept paid terms, or alter registry records.
- When the task includes multiple people, companies, or relationships, call
build_investigation_reportwith the normalized evidence. Treatanalysis.correlationsas evidence-backed review leads only: inspect every cited evidence and relationship ID, consider the stated benign alternatives, and never present a correlation as proof of fraud, money laundering, stolen identity, or common control.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 38 lines · 71 tokens per session scan A 392b0d183fa0
sos-company-research is a skill published in the GitHub repository Gal-Davidzon/public-risk-intelligence-mcp (0 stars, last pushed 16d ago), licensed MIT. It adds 71 tokens to every session and 781 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
check-country-risk
Retrieve composite country risk intelligence — Country Instability Index (CII), travel advisory level, and active sanctions exposure — for one country by ISO code. Use when the user asks how risky or unstable a country is right now.
check-sanctions-pressure
Retrieve normalized OFAC sanctions pressure — designation summaries, recent additions, and per-country/per-program aggregates including sanctioned vessels and aircraft. Use when the user asks which countries or programs face sanctions pressure, or what was recently designated.
source-verification
Walks through structured verification of sources, claims, images, video, and documents across five verification modes — visual media, documents, anonymous sources, expert credentials, and social media content — using the SIFT framework, forensic metadata inspection, deepfake indicators, C2PA Content Credentials, and…
Australia — ABR / ASIC Lookup
Live, real-time queries to Australian Business Register (ABR — ABN Lookup) (Australia). Drops the OpenRegistry MCP toolset onto a single-country workflow when the user names ABR / ASIC, the country, or its registry directly. ID format: 11-digit ABN or 9-digit ACN (e.g. ABN 33 123 456 789, ACN 004 028 077 for BHP Group…
Belgium — KBO/BCE Lookup
Live, real-time queries to KBO/BCE — Crossroads Bank for Enterprises (Belgium). Drops the OpenRegistry MCP toolset onto a single-country workflow when the user names KBO/BCE, the country, or its registry directly. ID format: 10-digit Belgian enterprise number (e.g. 0403.201.185 formatted, 0403201185 raw …
Canada (British Columbia) — OrgBook BC Lookup
Live, real-time queries to BC Registries (OrgBook BC) (Canada (British Columbia)). Drops the OpenRegistry MCP toolset onto a single-country workflow when the user names OrgBook BC, the country, or its registry directly. ID format: BC company number (e.g. BC1234567 BC-incorporated, A0099999 extra-provincial). Returns…