Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Gekkos-tech/agency-os --skill pre-launch-checklistgit clone --depth 1 https://github.com/Gekkos-tech/agency-osWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/gekkos-tech/agency-os/pre-launch-checklist)<a href="https://agentmods.dev/skills/gekkos-tech/agency-os/pre-launch-checklist"><img src="https://agentmods.dev/badge/skills/gekkos-tech/agency-os/pre-launch-checklist/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/gekkos-tech/agency-os/pre-launch-checklist"><img src="https://agentmods.dev/badge/skills/gekkos-tech/agency-os/pre-launch-checklist.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00161 | $0.01419 |
| Opus 5 | $0.00081 | $0.00709 |
| Sonnet 5 | $0.00032 | $0.00284 |
| Haiku 4.5 | $0.00016 | $0.00142 |
Grade A, and why
pre-launch-checklist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 114 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Pre-Launch Checklist
Run this as the last gate before DNS cutover. Two sections: legal (hard
blockers — a German site going live without these creates liability) and
technical. Produce docs/launch-checklist.md with pass/fail + evidence
per item. Anything failing legal = no launch recommendation, stated plainly.
A. Legal (DACH/EU) — hard blockers
Impressum (§ 5 DDG, formerly TMG)
- Impressum page exists, reachable from EVERY page within 2 clicks
- Contains: full legal name + legal form, postal address (no P.O. box), email AND a second fast contact channel (usually phone), authorized representative, commercial register + number (if registered), USt-IdNr. (if assigned), supervisory authority / chamber for regulated professions
- Responsible person for editorial content (§ 18 Abs. 2 MStV) if the site has journalistic/editorial content
Datenschutzerklärung (DSGVO)
- Privacy policy page linked from every page, current, and matching what
the site ACTUALLY does — verify against reality:
- every third-party service found in the code/network tab is listed (fonts, maps, analytics, tag manager, video embeds, forms, CDN, chat)
- legal basis named per processing purpose
- data subject rights, retention, controller contact, Datenschutzbeauftragter (if required)
- Google Fonts are self-hosted (loading from fonts.googleapis.com is an established Abmahnung risk in Germany), same logic for other third-party assets that leak IPs pre-consent
- Forms: only necessary fields, HTTPS submission, no pre-checked marketing checkboxes, double opt-in for newsletters
Cookie-Consent (TDDDG § 25 + DSGVO)
- No non-essential cookies/storage before consent — verify in DevTools with a fresh profile: only technically necessary items pre-consent
- Analytics/marketing tags fire only AFTER opt-in (test both paths)
- Banner: "Reject all" as prominent as "Accept all", granular choices, consent revocable (persistent link/settings), no dark patterns
- If only essential cookies are used: no banner needed — do not add one "for safety"; document it instead
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 114 lines · 161 tokens per session scan A 3552cee077fa
pre-launch-checklist is a skill published in the GitHub repository Gekkos-tech/agency-os (5 stars, last pushed 2mo ago), licensed MIT. It adds 161 tokens to every session and 1,419 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
neo-iso-27001
Use this skill when the user needs to establish, review, or improve an ISO/IEC 27001 ISMS, perform information security risk discovery, define scope, create an evidence matrix, conduct a gap analysis, draft a Statement of Applicability, prepare for an internal audit, or create an improvement plan. Use neo-iso-27701…
neo-iso-27701
Use this skill when the user needs to establish, review, or improve an ISO/IEC 27701 PIMS, inventory PII processing, analyze controller and processor responsibilities, create a privacy risk or evidence matrix, conduct a gap analysis, prepare for an audit, or create an improvement plan. Use neo-iso-27001 when the main…
market-research-workflow
Trigger for: federal acquisition market research; FAR Part 10 reports; refreshing an existing market research report; analyzing commerciality, competition, small-business availability, contract type, consolidation, prior awards, vendors, or market conditions; or preparing supported findings for a Pre-Award Agent. A…
ot-cost-analysis
Trigger for: Other Transaction or OT should-cost, cost estimate, cost-share analysis, milestone pricing, funding profile, proposed-price comparison, prototype price analysis, research OT budget, production follow-on OT estimate, or OT price-reasonableness support under 10 U.S.C. 4021 or 4022. Build auditable…
acquisition-policy-workflow
Trigger for: explaining current FAR, DFARS, or agency-supplement text; determining documented acquisition-policy status for an agency and FAR part; comparing codified text, RFO model text, and agency deviations; tracing acquisition rulemaking; finding procurement comment periods; analyzing public comments; refreshing…
ot-project-description-builder
Trigger for: OT project description, OTA scope, Research OT under 10 U.S.C. 4021, Prototype OT under 10 U.S.C. 4022, follow-on production scope under 10 U.S.C. 4022(f), milestone-based project scope, prototype objective, phase or go/no-go structure, BAA white-paper conversion, SOO conversion, transition planning, or…