Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add JAXTech-Labs/claude-code-template --skill review-security-compliancegit clone --depth 1 https://github.com/JAXTech-Labs/claude-code-templateWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jaxtech-labs/claude-code-template/review-security-compliance)<a href="https://agentmods.dev/skills/jaxtech-labs/claude-code-template/review-security-compliance"><img src="https://agentmods.dev/badge/skills/jaxtech-labs/claude-code-template/review-security-compliance.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00133 |
| Opus 5 | $0.00000 | $0.00067 |
| Sonnet 5 | $0.00000 | $0.00027 |
| Haiku 4.5 | $0.00000 | $0.00013 |
Grade A, and why
review-security-compliance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
The source is not reproduced here
No licence file
A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 23 lines · 0 tokens per session scan A 361c139f7f45
review-security-compliance is a skill published in the GitHub repository JAXTech-Labs/claude-code-template (2 stars, last pushed 5mo ago), with no licence file. It costs nothing until one of its globs matches a file; then it loads 133 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
orchardcore-dnc-registry
Skill for configuring national and local do-not-call registry checks in CrestApps Orchard Core including Azure Blob Storage for uploaded local lists. Covers import suppression, provider settings, E.164 normalization, CSV processing, registry extensions, and tenant-aware Azure storage. Use this skill when requests…
orchardcore-audit-trail
Skill for configuring audit trail in Orchard Core. Covers audit event recording, AuditTrailPart for content tracking, event filtering and sorting, audit settings configuration, custom audit event providers, and audit trail feature setup. Use this skill when requests mention Orchard Core Audit Trail, Configure Audit…
cratis-chronicle-compliance
Model personal data in Chronicle with [PII] and [Subject], and erase it through crypto-shredding with IPIIManager. Use when an event or read model carries data about a natural person, when a subject must be identified for erasure, when a right-to-erasure request must be executed, or when redacting a stored event. Do…
dotnet-analyzer-security-deps
Scan .NET projects for security vulnerabilities (OWASP Top 10), NuGet dependency health, CVE exploits, license compliance, and version conflicts using Roslyn and NuGet.org API. Use when the user asks to scan for security vulnerabilities, check for CVE, analyze dependency health, check license compliance, scan NuGet…
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.