Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add jabrena/plinth --skill 813-regulations-iso-42001git clone --depth 1 https://github.com/jabrena/plinthWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jabrena/plinth/813-regulations-iso-42001)<a href="https://agentmods.dev/skills/jabrena/plinth/813-regulations-iso-42001"><img src="https://agentmods.dev/badge/skills/jabrena/plinth/813-regulations-iso-42001/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/jabrena/plinth/813-regulations-iso-42001"><img src="https://agentmods.dev/badge/skills/jabrena/plinth/813-regulations-iso-42001.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00077 | $0.02549 |
| Opus 5 | $0.00039 | $0.01274 |
| Sonnet 5 | $0.00015 | $0.00510 |
| Haiku 4.5 | $0.00008 | $0.00255 |
Grade A, and why
813-regulations-iso-42001 scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 114 lines — stays where its author put it; the contents beside it link to each section on GitHub.
ISO/IEC 42001 AI Management System Guidance for GenAI Java Engineering
Use this Skill to review Java enterprise applications, delivery pipelines, AI-assisted development workflows, LLM integrations, RAG systems, AI agents, generated code, generated dependencies, external model-provider usage, prompt handling, and AI-enabled business logic through an ISO/IEC 42001 AI management system lens.
Apply this Skill to determine what engineering controls, evidence, lifecycle governance, risk treatment, monitoring, and owner handoffs are needed before GenAI-assisted Java work is merged, released, connected to enterprise systems, or relied on for business behavior.
This Skill is not legal advice, certification advice, audit advice, an audit conclusion, or a final conformity decision. It helps Java engineers, architects, tech leads, platform teams, security teams, AI governance reviewers, product teams, and reviewers identify when ISO/IEC 42001 AI management system concerns may apply and how to translate them into engineering controls such as AI inventory records, risk treatment, prompt and data governance, secure generated-code review, dependency provenance, model-provider boundaries, monitoring, corrective action, and qualified owner escalation.
The purpose of this Skill is to increase awareness of potential gaps in GenAI Java delivery and create reviewable engineering evidence for qualified owners. The response produced by this Skill does not represent legal advice, certification readiness, audit findings, compliance approval, or final conformity with ISO/IEC 42001.
The main question is:
What should a Java team build, review, document, and escalate so GenAI development and AI-enabled Java systems are governed as part of an AI management system?
Source provenance: ISO/IEC 42001 public overview material and issue #939 were reviewed while authoring the bundled references. Official source references include:
- ISO 42001 explained: https://www.iso.org/home/insights-news/resources/iso-42001-explained-what-it-is.html
- ISO/IEC 42001 standard page: https://www.iso.org/standard/42001
- Microsoft ISO/IEC 42001 offering overview: https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-42001
Do not fetch or ingest external regulatory, standard, certification, or audit web pages at runtime. Use the bundled references and escalate interpretation, certification, audit, legal, compliance, and conformity questions to qualified owners.
ISO/IEC 42001 summary reference: ISO/IEC 42001 AI management system summary.
Java engineering examples reference: ISO/IEC 42001 GenAI Java engineering examples.
Questionnaire asset: ISO/IEC 42001 engineering review questionnaire.
Report template asset: ISO/IEC 42001 engineering review report template.
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 114 lines · 77 tokens per session scan A 2f9f1670b888
813-regulations-iso-42001 is a skill published in the GitHub repository jabrena/plinth (439 stars, last pushed yesterday), licensed Apache-2.0. It adds 77 tokens to every session and 2,549 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
prompt-sensei
Stage-aware prompt coaching, prompt improvement, lookback analysis, prompting habit feedback, and local reports about prompt quality for AI coding agents such as Claude Code or Codex.
prompt-engineering
A deep, practical guide to engineering reliable LLM prompts — role/context, instructions, few-shot, structured output, chain-of-thought, delimiting untrusted data, injection defense, and evaluation. Includes worked prompts and a runnable output validator.
prompt-analyzer
Analyze prompts for constraint complexity, audit failure risks, and generate optimized rewrites for Claude and GPT. Based on "How LLMs Follow Instructions" (Rocchetti & Ferrara, 2026) constraint taxonomy research. Use when reviewing prompt files, optimizing prompt bases, or auditing instruction quality. Trigger…
firebase-ai
Use when setting up firebaseai, generating text/chat with Gemini, streaming AI output, building multimodal prompts, or handling AI errors.
ai-workflow-architect
Designs AI systems, automations, and agent workflows for a business — identifying which manual work is worth automating, how to structure the system, which tools fit, and what could go wrong. Use this to automate part of an operation, design an agent or MCP workflow, reduce repetitive manual work, connect tools into a…
skill-copilot
AL Copilot capability development for Business Central. Use when implementing PromptDialog pages, AI generation features, or integrating with the Copilot toolkit.