Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/global-slice/claude-plugin/compliance-analysisnpx skills add Global-Slice/claude-plugin --skill compliance-analysisgit clone --depth 1 https://github.com/Global-Slice/claude-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/global-slice/claude-plugin/compliance-analysis)<a href="https://agentmods.dev/skills/global-slice/claude-plugin/compliance-analysis"><img src="https://agentmods.dev/badge/skills/global-slice/claude-plugin/compliance-analysis.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00098 | $0.01347 |
| Opus 5 | $0.00049 | $0.00674 |
| Sonnet 5 | $0.00020 | $0.00269 |
| Haiku 4.5 | $0.00010 | $0.00135 |
Grade A, and why
compliance-analysis scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Compliance Analysis
Scope
Use for compliance tickets and posture. Not a substitute for legal advice. For workflow process status without compliance focus, use workflows-analysis. For cap-table totals without compliance tickets, use cap-table-analysis.
Core Principle
Use compliance tools as a compliance-ticket interface, not as a raw data export. Start with the bounded aggregate breakdown, then retrieve full ticket records only for a specific object after identifying that object with the relevant domain tool.
Slice data and compliance tickets are the ground truth for a specific company. Do not replace ticket findings with general legal advice. Use domain knowledge to interpret why a ticket matters, and separate "the ticket says" from "the domain implication is".
Tool Selection
- Use
compliance_get_tickets_breakdownfirst for company-level compliance posture. It returns fixed-size aggregates only: total, active, completed, archived, status counts, severity counts, object type counts, top issue groups capped to 10, and time-sensitive counts. - Use
compliance_get_object_ticketsonly for one known object. It returns full ticket records forobjectIdandobjectType, including status, comments, events,ticketData, due date, and metadata. - Use domain tools to resolve the object before calling object tickets: stakeholder tools for stakeholders, securities tools for grants and shares, equity-pool tools for equity pools, valuation tools for FMV records, cap-table tools for cap-table context, and exercise-request tools when available.
Do not call object-ticket retrieval broadly across many objects unless the user explicitly asks for detailed ticket bodies and the object set is small.
Object Types
compliance_get_object_tickets requires an object ID and one of these ticket object types:
corporateApprovalsexerciseRequestsgrantsstakeholdersvaluationsequityPoolsequityPlansshares
Use the object type that matches the compliance object, not the endpoint family used to discover it. For example, a grant discovered through securities_search still uses objectType: "grants".
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 92 lines · 98 tokens per session scan A 19aeb146545c
compliance-analysis is a skill published in the GitHub repository Global-Slice/claude-plugin (9 stars, last pushed 1mo ago), licensed MIT. It adds 98 tokens to every session and 1,347 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
researchers-legal
Researches court documents, indictments, plea agreements, and sentencing records. Use when the album subject involves legal proceedings or criminal cases.
better-auth
Skill for integrating Better Auth - comprehensive TypeScript authentication framework for Cloudflare D1, Next.js, Nuxt, and 15+ frameworks. Use when adding auth, encountering D1 adapter errors, or implementing OAuth/2FA/RBAC features.
aceternity-ui
100+ animated React components (Aceternity UI) for Next.js with Tailwind. Use for hero sections, parallax, 3D effects, or encountering animation, shadcn CLI integration errors.
auto-animate
AutoAnimate (@formkit/auto-animate) zero-config animations for React. Use for list transitions, accordions, toasts, or encountering SSR errors, animation libraries complexity.
api-design-principles
Master REST and GraphQL API design principles to build intuitive, scalable, and maintainable APIs that delight developers. Use when designing new APIs, reviewing API specifications, or establishing API design standards.
api-testing
HTTP API testing for TypeScript (Supertest) and Python (httpx, pytest). Test REST APIs, GraphQL, request/response validation, authentication, and error handling.