Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/NEU-ZHA/legal-ai-skillsnpx agentmods add skills/neu-zha/legal-ai-skills/pkulaw-mcp-installerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/neu-zha/legal-ai-skills/pkulaw-mcp-installer)<a href="https://agentmods.dev/skills/neu-zha/legal-ai-skills/pkulaw-mcp-installer"><img src="https://agentmods.dev/badge/skills/neu-zha/legal-ai-skills/pkulaw-mcp-installer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/neu-zha/legal-ai-skills/pkulaw-mcp-installer"><img src="https://agentmods.dev/badge/skills/neu-zha/legal-ai-skills/pkulaw-mcp-installer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00116 | $0.02116 |
| Opus 5 | $0.00058 | $0.01058 |
| Sonnet 5 | $0.00023 | $0.00423 |
| Haiku 4.5 | $0.00012 | $0.00212 |
Grade A, and why
pkulaw-mcp-installer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 143 lines — stays where its author put it; the contents beside it link to each section on GitHub.
北大法宝 MCP 一键安装技能
概述
此技能用于一键将北大法宝 MCP 服务配置写入目标 MCP 配置文件,免去手动逐个添加的繁琐操作。适用于团队内部推广、新设备配置、给同事/朋友安装北大法宝法律检索能力等场景。
统一积分模式
北大法宝 MCP 现在使用统一积分:服务可以在控制台按需开启,真正调用时才扣积分。安装能力与调用成本是两件事:建议把控制台已经开启的服务全部配置到 AI,但执行任务时必须先选成本最低且足够完成任务的服务,不能把 10 项逐个调用一遍。
| 分类 | 服务名 | 控制台能力 | 约积分/次 | 默认策略 |
|---|---|---|---|---|
| 法规法条 | pkulaw-fatiao |
精准查找法条-关键词 | 25 | 已知法规名和条号时首选 |
| 法规法条 | pkulaw-law-keyword |
检索法律法规-关键词 | 25 | 普通法规研究首选 |
| 法规法条 | pkulaw-law-search |
检索法律法规-语义 | 125 | 两轮合理关键词仍不足时升级 |
| 司法案例 | pkulaw-case |
检索司法案例-关键词 | 25 | 普通类案检索首选 |
| 司法案例 | pkulaw-case-search |
检索司法案例-语义 | 125 | 关键词难以表达事实相似性时升级 |
| 引用溯源 | pkulaw-recognition |
法条识别与溯源 | 125 | 仅用于从非结构化文本识别法条 |
| 引用溯源 | pkulaw-hyperlink |
法宝超链 | 125 | 仅在依据已经核验后补链接 |
| 引用溯源 | pkulaw-citation |
修正生成幻觉-法条 | 125 | 仅在任务明确要求引用核验时调用 |
| 引用溯源 | pkulaw-case-number |
案号识别与溯源 | 125 | 精确案号关键词检索失败或批量提取时调用 |
| 综合检索 | pkulaw-nl-sql |
法律智能检索 | 125 | 无法拆分的跨库复杂问题最后使用 |
成本规则:
- 明确法规词、法条或案由时,先用 25 积分服务。
- 先改写一次关键词再考虑升级;不要因第一次无结果立即切换 125 积分服务。
- 引用核验、法条识别、补超链等专门任务可以直接调用对应 125 积分服务,但只调用完成任务所需的那一项。
- 跨法规与案例的研究先拆成两次 25 积分检索;确实无法拆分或仍有关键缺口时才用综合检索。
触发场景
当用户提出以下需求时使用此技能:
- "帮我安装北大法宝MCP"
- "配置pkulaw MCP"
- "给新设备装北大法宝"
- "我也要用北大法宝检索"
- "怎么配置北大法宝MCP"
- "pkulaw setup"
工作流程
步骤一:获取 Authorization Token
向用户确认北大法宝 API 的 Bearer Token。该 Token 是敏感凭证。
获取方式:
- 用户已有 Token → 优先让用户通过环境变量
PKULAW_AUTH_TOKEN、终端交互或本机私有配置提供,不要让用户把真实 Token 写进仓库文件、示例、模板、截图或 Issue - 用户没有 Token → 引导用户进入北大法宝 MCP 控制台,在“获取 Token”页面新建 Token、开启需要的服务并复制接入配置。用户可以开启全部 10 项,成本由实际调用决定。
步骤二:确认控制台已开启服务
询问用户:
请确认“获取 Token”页面显示已开启多少项服务。可以提供服务列表文字或截图,但不要展示 Token 明文。我会按控制台已开启项配置,并使用节省积分的调用顺序。
映射规则:
- 如果用户说“法规关键词检索”或页面显示
mcp-law,安装pkulaw-law-keyword。 - 如果用户说“精准法条查找/法条检索”或页面显示
mcp-fatiao,安装pkulaw-fatiao。 - 如果用户说“司法案例关键词检索/案例检索”或页面显示
mcp-case,安装pkulaw-case。 - 控制台显示
10/10 已开时,安装全部 10 项。 - 只开启部分服务时,按上表映射为
--services参数;不要配置控制台未开启的服务。 - 截图无法判断时,可以让用户直接复制服务名称,不要求用户发送 Token 明文。
步骤三:执行安装脚本
控制台已开启全部 10 项时,直接运行:
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 143 lines · 116 tokens per session scan A b07ca71271d4
pkulaw-mcp-installer is a skill published in the GitHub repository NEU-ZHA/legal-ai-skills (64 stars, last pushed 23d ago), licensed MIT. It adds 116 tokens to every session and 2,116 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…