Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Global-mindee/WAY --skill legal-compliancegit clone --depth 1 https://github.com/Global-mindee/WAYWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/global-mindee/way/legal-compliance)<a href="https://agentmods.dev/skills/global-mindee/way/legal-compliance"><img src="https://agentmods.dev/badge/skills/global-mindee/way/legal-compliance/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/global-mindee/way/legal-compliance"><img src="https://agentmods.dev/badge/skills/global-mindee/way/legal-compliance.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00212 | $0.01805 |
| Opus 5 | $0.00106 | $0.00903 |
| Sonnet 5 | $0.00042 | $0.00361 |
| Haiku 4.5 | $0.00021 | $0.00180 |
Grade A, and why
legal-compliance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 107 lines — stays where its author put it; the contents beside it link to each section on GitHub.
legal-compliance skill
언제 활성화되나
법무·compliance·규제 키워드를 감지하면 자동 호출됩니다. 어떤 business 폴더에서 작업하든, 이 skill이 platform/knowledge/wiki/legal/ 중앙 자산을 먼저 참조합니다.
대표 상황:
- 새 서비스의 약관·프라이버시·쿠키 정책 작성
- 결제·환불 정책 설계 (MoR, Stripe, LS 등)
- 지역 규제 대응 (EU/US/Canada/Korea)
- Age gate·COPPA·ToS 갱신
- CEO가 법적 리스크 질문
Central references (first stop)
범용 프레임워크 (지역·법률체계 단위)
- [[platform/knowledge/wiki/legal/frameworks/gdpr-eu]] — EU GDPR 조사·요건 (geoblock 미적용 시)
- [[platform/knowledge/wiki/legal/frameworks/eu-geoblock-legal-analysis]] — EU 32국 차단 법적 근거
- [[platform/knowledge/wiki/legal/frameworks/us-federal]] — FTC·COPPA·CAN-SPAM·Dot Com·Endorsement
- [[platform/knowledge/wiki/legal/frameworks/us-state-matrix]] — 50주 프라이버시·Fortune Telling 매트릭스
- [[platform/knowledge/wiki/legal/frameworks/canada]] — PIPEDA·CASL·Quebec Law 25
- [[platform/knowledge/wiki/legal/frameworks/korea-business-setup]] — 한국 사업자·통신판매·PIPA·외환
- [[platform/knowledge/wiki/legal/frameworks/lemonsqueezy-mor-scope]] — LS MoR 책임 범위 + 포지셔닝 경고
재사용 가능한 policy 조각 (서비스 공통)
- [[platform/knowledge/wiki/legal/components/age-gate-spec]] — 13+/16+ 차단 spec + SQL
- [[platform/knowledge/wiki/legal/components/can-spam-email]] — 이메일 마케팅 (CAN-SPAM+CASL+Quebec)
- [[platform/knowledge/wiki/legal/components/endorsement-influencer]] — 16 CFR 255 인플루언서 계약 템플릿
한국 법령 entities (참조)
- [[platform/knowledge/wiki/legal/entities/개인정보보호법]]
- [[platform/knowledge/wiki/legal/entities/변호사법]]
연결 지식
- 결제 MoR 결정: [[platform/knowledge/playbooks/migration/payment-provider-decision]]
프로젝트 특화 사례 (참고용, 재사용 금지)
- B2C 디지털 서비스 (북미 런칭) 예시: 서비스별 실적용 ToS/Privacy/환불 예시 (예: Delaware 준거법 + LS MoR + 엔터테인먼트 표기 판례)
- 매칭 플랫폼 예시: 플랫폼 법적 체크리스트 (사업자·중개·개인정보)
⚠️ 주의: 프로젝트별 약관·프라이버시 문서는 서비스별 커스텀 조항(브랜드명, 영업 주소, 서비스 특성) 포함. 그대로 복사하지 말고 frameworks/ + components/ 를 재료로 해당 프로젝트용 문서를 생성.
Workflow
1. 도메인 식별
- 지역: EU / US / Canada / Korea / 복수
- 주제: 프라이버시 / ToS / 환불 / 쿠키 / age / 결제 / 마케팅
2. 중앙 자산 로드
해당 지역 frameworks/ + 관련 components/ Read. 전체 로드보다 필요한 섹션만 인용.
What ships with it
5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 107 lines · 212 tokens per session scan A e6c023502308
legal-compliance is a skill published in the GitHub repository Global-mindee/WAY (11 stars, last pushed 4d ago), licensed MIT. It adds 212 tokens to every session and 1,805 once invoked, about $0.0011 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…
clio-webhooks
Receive and verify Clio (Clio Manage) webhooks. Use when setting up Clio webhook handlers, debugging X-Hook-Signature verification, completing the X-Hook-Secret handshake, or handling legal practice events like matter.created, contact.updated, activity.created, or bill events.
hipaa-compliance
HIPAA-specific entrypoint for healthcare privacy and security work. Use when a task is explicitly framed around HIPAA, PHI handling, covered entities, BAAs, breach posture, or US healthcare compliance requirements.