Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add jeffreytse/grimoire-core --skill apply-enforcement-timinggit clone --depth 1 https://github.com/jeffreytse/grimoire-coreWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jeffreytse/grimoire-core/apply-enforcement-timing)<a href="https://agentmods.dev/skills/jeffreytse/grimoire-core/apply-enforcement-timing"><img src="https://agentmods.dev/badge/skills/jeffreytse/grimoire-core/apply-enforcement-timing/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/jeffreytse/grimoire-core/apply-enforcement-timing"><img src="https://agentmods.dev/badge/skills/jeffreytse/grimoire-core/apply-enforcement-timing.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00064 | $0.03092 |
| Opus 5 | $0.00032 | $0.01546 |
| Sonnet 5 | $0.00013 | $0.00618 |
| Haiku 4.5 | $0.00006 | $0.00309 |
Grade A, and why
apply-enforcement-timing scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 97 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Apply Enforcement Timing
When misconduct has been detected but evidence is incomplete or the subject is powerful, deliberate delay of enforcement action until the case is overwhelming and procedurally unassailable is strategically superior to immediate action.
Why This Is Best Practice
左传 隐公元年 (722 BC, first entry of 左传) — 郑伯克段于鄢:
公曰:姜氏欲之,焉辟害?对曰:姜氏何厌之有!不如早为之所,无使滋蔓,蔓难图也。蔓草犹不可除,况君之宠弟乎?
The first entry of 左传 describes how Zheng Zhuanggong (郑庄公) handled his brother Gong Shu Duan (共叔段), who was granted territory and systematically violated the boundaries of his granted domain, built unauthorized fortifications, and amassed an army — all preparatory to rebellion. Officials repeatedly warned Zhuanggong to intervene early. Zhuanggong repeatedly declined. When Gong Shu Duan finally launched his rebellion, Zhuanggong acted decisively and crushed it. The 左传 commentary evaluates this episode with precision: Zhuanggong was criticized for allowing the wrongdoing to develop (feeding it until it was manifest), but the result was a case of rebellion so unambiguous that no one could dispute the justice of the response. The 公羊传 commentary asks directly: "Why did he not act sooner?" and answers: "Because he waited until the case was complete."
Why best: The strategic insight: enforcement against a powerful bad actor with incomplete evidence produces three outcomes simultaneously — a weakened case (the subject can contest the evidence), procedural exposure (the enforcer can be accused of overreach or premature judgment), and a rallying point for the subject's defenders. Enforcement with overwhelming, uncontestable evidence produces a different outcome: the case is closed, the subject's defenders cannot credibly claim overreach, and the enforcement has lasting moral authority.
DOJ Federal Prosecution Manual §9-27.220 — Strength of Evidence Standard: The US Department of Justice's internal prosecution guidelines establish that federal prosecutors should not file charges unless they believe the evidence at trial will be sufficient to sustain a conviction beyond a reasonable doubt. The explicit rationale: charging before the evidentiary standard is met does not achieve accountability — it produces acquittals, emboldens the subject, and damages the credibility of future enforcement. The DOJ's practice of building airtight cases before indictment — including multi-year grand jury investigations before charges — reflects the institutional finding that case strength at filing is the primary predictor of enforcement outcome. Standard across all US federal prosecutorial practice; adopted as model in UK Crown Prosecution Service and EU enforcement agencies.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 97 lines · 64 tokens per session scan A 4f7dda77fba9
apply-enforcement-timing is a skill published in the GitHub repository jeffreytse/grimoire-core (4 stars, last pushed 20d ago), licensed MIT. It adds 64 tokens to every session and 3,092 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
counseling-psychology
Therapeutic frameworks, assessment, ethical practice, and client documentation for counselors and psychologists.
achieving-cmmc-level-2-compliance
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when…
compliance
Use when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or standing up the cadence that keeps it audit-ready. NOT drafting privacy-policy/ROPA/DPA or ToS text (that is gdpr-privacy, terms-conditions)…
hr-payroll
Help HR operations specialists, payroll administrators, and compensation teams understand, design, and run payroll processing, compliance, and payroll-related HR operations. Use when asked to set up a payroll process, run a payroll compliance audit, design a payroll calendar, handle a payroll discrepancy, build a…
hr-agentic-ai
Help HR leaders, HR technology teams, and People Ops professionals understand, evaluate, and govern agentic AI systems deployed in HR contexts, including autonomous HR agents, multi-agent workflows, and AI-driven HR process automation. Use when asked to use AI agents for HR, build an HR automation agent, govern…
hr-ai-ethics
Help HR and compliance teams govern the ethical use of AI in HR processes, including algorithmic fairness in hiring, bias auditing, AI transparency, accountability frameworks, and ethical AI policy design. Use when asked to audit AI bias in hiring, design ethical AI guidelines for HR, assess algorithmic fairness…