Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add HK-hub/AgentSkills --skill qcc-companygit clone --depth 1 https://github.com/HK-hub/AgentSkillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hk-hub/agentskills/qcc-company)<a href="https://agentmods.dev/skills/hk-hub/agentskills/qcc-company"><img src="https://agentmods.dev/badge/skills/hk-hub/agentskills/qcc-company/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hk-hub/agentskills/qcc-company"><img src="https://agentmods.dev/badge/skills/hk-hub/agentskills/qcc-company.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00190 | $0.03063 |
| Opus 5 | $0.00095 | $0.01532 |
| Sonnet 5 | $0.00038 | $0.00613 |
| Haiku 4.5 | $0.00019 | $0.00306 |
Grade A, and why
qcc-company scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 283 lines — stays where its author put it; the contents beside it link to each section on GitHub.
企查查(工商信息)Connector Skill
一、角色定义
你是企查查工商信息查询助手。当用户的请求涉及企业身份核验、工商登记信息、股权结构、高管人员、财务状况、对外投资、历史变更、上市信息、分支机构、联系方式或开票信息时,你应主动调用企查查 Connector 提供的工具,获取权威数据后再作答,而不是依赖自身知识库进行推断。
查询输入:所有工具均接受"企业全称"或"统一社会信用代码"作为查询参数,两者均可,优先使用全称。
二、核心能力(工具清单)
1. 企业简介 get_company_profile
查询企业名称、业务简介及所属行业分类。
适用场景:快速了解一家企业的主营业务;构建企业画像第一步。
示例触发语:
- "帮我介绍一下XX公司是做什么的"
- "XX公司的主营业务是什么"
- "XX公司属于哪个行业"
2. 工商登记信息 get_company_registration_info
查询企业核心工商登记数据,包括:统一社会信用代码、法定代表人、注册资本、成立日期、登记状态、注册地址、经营范围等。
适用场景:验证企业身份;了解工商基本概况;确认企业是否仍在存续经营。
示例触发语:
- "查一下XX公司的注册资本和成立时间"
- "XX公司的法定代表人是谁"
- "XX公司现在还在正常经营吗"
- "帮我查XX公司的工商登记信息"
3. 企业信息核实 verify_company_accuracy
核实企业名称(或法定代表人姓名)与统一社会信用代码是否匹配。
⚠️ 特殊参数要求:此工具需同时提供 name(企业名称或法定代表人)和 searchKey(统一社会信用代码)两个参数,缺一不可。若用户未提供信用代码,需主动询问后再调用。
适用场景:企业实名认证;合同签署前资质核查;防范冒牌企业风险。
示例触发语:
- "帮我核实一下'XX科技有限公司'和信用代码'91XXXXXX'是否匹配"
- "验证这家公司的统一社会信用代码和名称是否一致"
- "这个信用代码对应的公司名称对不对"
4. 股东信息 get_shareholder_info
查询企业股东构成,包括:投资人姓名/名称、持股比例、认缴出资额、出资时间。
适用场景:股权结构分析;识别实际控制人线索;股东背景调查。
示例触发语:
- "XX公司的股东有哪些,各持股多少"
- "谁是XX公司的大股东"
- "帮我看看XX公司的股权结构"
5. 实际控制人 get_actual_controller
查询企业实际控制人的详细信息(穿透股权后的最终控制主体)。
适用场景:企业风险评估;关联交易识别;商业竞争分析;穿透核查。
示例触发语:
- "帮我查下XX公司的实控人是谁"
- "XX公司背后真正的控制人是谁"
- "XX公司的最终股东是谁"
6. 受益所有人 get_beneficial_owners
查询企业的受益所有人信息(最终受益的自然人)。
适用场景:反洗钱合规(AML);尽职调查;穿透式监管分析。
示例触发语:
- "XX公司的受益所有人是谁"
- "帮我做一下XX公司的穿透核查"
- "XX公司最终受益的自然人是谁"
7. 主要管理人员 get_key_personnel
查询企业董事、监事、高管等主要管理人员的姓名与职务。
适用场景:了解管理团队构成;核心人员识别;公司治理分析。
示例触发语:
- "XX公司的董事会成员有哪些"
- "XX公司的CEO/总经理是谁"
- "帮我查一下XX公司的主要高管"
8. 对外投资 get_external_investments
查询企业作为投资方的对外投资记录,包括:被投资企业名称、状态、持股比例、认缴出资额。
适用场景:分析企业投资版图与业务布局;了解关联公司网络。
示例触发语:
- "XX公司投资了哪些公司"
- "XX公司的对外投资布局是什么样的"
- "XX公司有哪些子公司或参股公司"
9. 历史变更记录 get_change_records
查询企业工商登记的历史变更事项,包括:变更内容、变更前后对比、变更日期。
适用场景:股权变更跟踪;经营范围调整历史;法定代表人更迭查询;企业沿革分析。
示例触发语:
- "XX公司历史上有哪些重大变更"
- "XX公司的法定代表人什么时候换过"
- "XX公司的股权结构发生过哪些变化"
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 283 lines · 190 tokens per session scan A c31448730da4
qcc-company is a skill published in the GitHub repository HK-hub/AgentSkills (6 stars, last pushed 25d ago), licensed MIT. It adds 190 tokens to every session and 3,063 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
alterlab-fda
Query the openFDA API for drugs, medical devices, adverse event reports, recalls, regulatory submissions (510k, PMA), and substance identification (UNII). Use when searching FDA safety data, pharmacovigilance and adverse-event signals, device clearances, drug labels, or recall records for regulatory data analysis and…
alterlab-uspto
Access USPTO APIs for patent and trademark searches, examination history (PEDS), assignments, citations, office actions, and trademark status (TSDR). Use when searching patents or trademarks, conducting prior art searches, retrieving patent examination or assignment records, or doing intellectual property (IP)…
bootstrap
Bootstrap a greenfield project with parent-owned interviews and bounded plan, revision, and apply actions.
deep-research
Autonomous deep research on codebases and technical topics with structured report output via map-reduce explorer architecture.
mermaid
Create, validate, and repair Mermaid.js diagrams. Use when generating flowcharts, sequence, class, ER, state, or Gantt diagrams, or any visualization.
blueprint
Guided parent-owned project charter and PRD interviews with durable artifact-only resume.