Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add gethouston/houston --skill organizar-mi-bandeja-legalgit clone --depth 1 https://github.com/gethouston/houstonWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/gethouston/houston/organizar-mi-bandeja-legal)<a href="https://agentmods.dev/skills/gethouston/houston/organizar-mi-bandeja-legal"><img src="https://agentmods.dev/badge/skills/gethouston/houston/organizar-mi-bandeja-legal/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/gethouston/houston/organizar-mi-bandeja-legal"><img src="https://agentmods.dev/badge/skills/gethouston/houston/organizar-mi-bandeja-legal.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00068 | $0.01369 |
| Opus 5 | $0.00034 | $0.00685 |
| Sonnet 5 | $0.00014 | $0.00274 |
| Haiku 4.5 | $0.00007 | $0.00137 |
Grade A, and why
organizar-mi-bandeja-legal scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 52 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Organizar mi bandeja legal
Cuándo usarlo
- Explícito: "organiza mi bandeja legal", "revisa lo entrante en busca de contratos", "qué correo legal necesita mi atención", "corre la clasificación".
- Implícito: la primera skill que el usuario ejecuta cuando ve una tarjeta de "Necesita tu atención" y pregunta "¿qué me está esperando?".
- Segura para usar bajo demanda: a diario o varias veces por semana para un fundador solo. Ventana por defecto: últimos 7 días si no se especifica.
Pasos
- Lee el contexto compartido:
context/legal-context.md. Si falta o está vacío, pregunta al usuario en lenguaje sencillo: "Primero necesito unos datos básicos sobre tu empresa. ¿Quieres configurarlos ahora?" Luego ejecutaset-up-my-legal-infosi dice que sí. Detente hasta que eso esté hecho. - Lee la configuración:
config/counterparty-stack.json. Si tu bandeja no está conectada, pregunta al usuario en lenguaje sencillo: "Necesito conectar tu bandeja de entrada para revisarla. ¿Quieres conectar Gmail u Outlook ahora?" Detente hasta que esté conectada. - Descubre la herramienta de bandeja vía Composio. Ejecuta
composio search inboxpara obtener el identificador de la herramienta. Confirma que coincide concounterparty-stack.inboxCategory. - Trae lo entrante. Ventana por defecto: últimos 7 días (o N según el usuario). Consulta la bandeja para mensajes probablemente legales: adjuntos de contrato (.pdf, .docx), dominios de remitente de bufetes, palabras clave en el asunto ("NDA", "MSA", "DPA", "DSR", "citatorio", "resolución de la oficina", "términos", "acuerdo"), hilos que responden a correo legal previo.
- Clasifica cada elemento. Aplica la rúbrica, elige un solo grupo:
- NDA: semáforo. Verde = mutuo, plazo ≤3 años, alcance razonable, no-solicitud estándar (o ninguno), sin residuales inusuales, sin no competencia, ley aplicable de EE. UU. Amarillo = exactamente una desviación (unilateral cuando somos los únicos que revelamos, plazo de 3-5 años, residuales amplios, jurisdicción cercana como Canadá/Reino Unido). Rojo = dos o más desviaciones, o cualquiera de: no competencia, cesión de propiedad intelectual, responsabilidad ilimitada, obligaciones de publicidad / comunicado de prensa, plazo mayor a 5 años o perpetuo, ley aplicable no estándar. Por defecto Rojo si el texto no se puede leer con confianza.
- MSA / formulario de pedido: documento marco o de términos comerciales de cliente/proveedor.
- DPA: adenda de procesamiento de datos o términos de datos independientes.
- DSR: solicitud de titular de datos (GDPR Art. 15, CCPA).
- citatorio / proceso legal: citatorio, requerimiento de preservación, cese y desista, retención por litigio.
- acción de la oficina de marcas: acción de la oficina de USPTO o correspondencia de marca.
- documento de contratista: consultoría / contratista / trabajo por encargo entrante de una contraparte.
- otro: cualquier otra cosa con tinte legal (solicitud de certificado de seguro, consulta de privacidad, cuestionario de seguridad de proveedor).
- Dirige cada elemento. Recomienda uno:
- manejar directamente vía
draft-a-legal-document: solo si el elemento encaja claramente con una plantilla existente (por ejemplo, un NDA Verde con una contraparte conocida). - enviar a
review-a-contract(mode=full): la mayoría de MSA / DPA / formularios de pedido / NDAs Amarillos van aquí. - marcar
attorneyReviewRequired: NDAs Rojos, citatorios, cercano a litigio, cualquier cosa ambigua. - ignorar: spam, boletines, hilos ya resueltos.
- manejar directamente vía
- Escribe el resumen en
intake-summaries/{YYYY-MM-DD}.mdde forma atómica (*.tmp→ renombrar). Estructura: conteos arriba ("7 elementos: 3 NDA, 1 MSA, 1 DSR, 2 otros"), luego una sección por elemento conFrom,Subject,Received,Classification,One-line summary,Recommended route. - Agrega a
outputs.json: lee el arreglo existente, agrega{ id, type: "intake-summary", title, summary, path, status: "draft", createdAt, updatedAt, attorneyReviewRequired }. MarcaattorneyReviewRequired: truesi algún elemento está señalado para revisión por abogado. - Resume para el usuario. Lenguaje sencillo. Un párrafo corto: "Encontré {N} elementos legales. {X} NDAs (con los seguros ya señalados), {Y} contratos de clientes, {Z} que necesitan los ojos de un abogado de verdad. ¿Quieres que redacte respuestas para los seguros, o que revise por completo los contratos de clientes?" Nunca nombres archivos ni rutas.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 52 lines · 68 tokens per session scan A 1661d796a219
organizar-mi-bandeja-legal is a skill published in the GitHub repository gethouston/houston (113 stars, last pushed today), licensed MIT. It adds 68 tokens to every session and 1,369 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…