Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add PostOakLabs/ainumbers --skill signed-policy-agentic-commercegit clone --depth 1 https://github.com/PostOakLabs/ainumbersWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/postoaklabs/ainumbers/signed-policy-agentic-commerce)<a href="https://agentmods.dev/skills/postoaklabs/ainumbers/signed-policy-agentic-commerce"><img src="https://agentmods.dev/badge/skills/postoaklabs/ainumbers/signed-policy-agentic-commerce/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/postoaklabs/ainumbers/signed-policy-agentic-commerce"><img src="https://agentmods.dev/badge/skills/postoaklabs/ainumbers/signed-policy-agentic-commerce.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00064 | $0.00889 |
| Opus 5.5 | $0.00026 | $0.00356 |
| Sonnet 5.5 | $0.00013 | $0.00178 |
| Haiku 4.5 | $0.00006 | $0.00089 |
Grade A, and why
signed-policy-agentic-commerce scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 49 lines — stays where its author put it; the contents beside it link to each section on GitHub.
An agent buys under a signed policy and proves the policy governed
Run an agentic commerce chain under a signed Work Mandate, trip the escalation gate on purpose, and replay the gates on the ledger.
Prompt
Act as a procurement agent operating under a signed spend policy. Produce a receipt that proves the policy governed every step.
- Call find_chain with "agent commerce conformance" and pick the chain named agent-commerce-conformance. Call build_chaingraph on it and list each step's required policy_parameters.
- Draft a Work Mandate (OCG §22): principal "treasury-ops", agent "procurement-bot-01", scope limited to this chain, per-transaction cap 2,500 EUR, validity 24h from now. Call vc_issue to sign it, then show me the mandate_hash.
- Call run_chain on agent-commerce-conformance with escalation_transport "resolve_handle", passing the signed mandate and synthetic inputs where a cart total of 3,100 EUR breaches the cap. Report per-step status, the composite execution_hash, and the escalation record with its record_hash and resolve handle.
- Re-run with a 1,900 EUR cart. Report the composite hash and confirm no escalation.
- For the compliant run, call verify_execution_hash on the composite artifact, then emit_chaingraph_artifact to get the in-toto link set. Confirm each link's materials equal the previous step's products.
- Open the ledger_url for the compliant run. Report what the §21 gate replay shows and whether the §16 signature and mandate_hash check pass.
- Now prove the counterparty would accept the agent: on https://ainumbers.co/chaingraph/art-129-webbotauth-signature-verifier.html, use the page's WebMCP tool to verify a WebBotAuth-signed request header for procurement-bot-01 (synthetic sample). Record the hash.
- Call build_session_receipt over all hashes in order (mandate, both runs, identity check) and anchor the root with anchor_hash (FreeTSA RFC 3161). Return the session root, the anchor receipt, and a five-line summary: who authorised, what ran, where it breached, what a human still has to close out (the open resolve handle). If a named tool is not in your tool list, call call_tool with { "name": "", "arguments": { … } }. It runs the same validation and returns the same receipt.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 49 lines · 64 tokens per session scan A 49b47268d723
signed-policy-agentic-commerce is a skill published in the GitHub repository PostOakLabs/ainumbers (10 stars, last pushed today), licensed MIT. It adds 64 tokens to every session and 889 once invoked, about $0.0003 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-27.
Other skills, from other repositories
common-law-ucc-sales-goods
Anwalt prüft Warenkaufvertrag nach UCC oder Sale of Goods Act: title risk warranties perfect tender remedies. Anwendungsfall US-Kaufvertrag oder UK-Warengeschäft. Prüfraster UCC Art. 2 Sale-of-Goods-Act-Prüfung Title-Risk-Transfer Warranty-Typen Perfect-Tender-Rule. Output Kaufvertrags-Analyse Risikomatrix…
paymob-integration
Integrate Paymob payments for web, mobile, Shopify, and backend apps in Egypt, UAE, KSA, and Oman. Use for checkout, Intention API, HMAC webhooks, reconciliation, SDKs, subscriptions, and refunds.
tbank-grocery-order
A skill that guides grocery orders through T-Bank's City service, from choosing products to checkout and payment.
tbank-tickets
Instructions for buying cinema, concert, theatre, and exhibition tickets through T-Bank's event service. They cover the process from finding an event and checking seats to making a paid booking.
onboarding
Full KYC customer onboarding with mandatory Step 0 independent verification (5+1 searches), 17 sequential stagegates requiring explicit analyst consent, deterministic four-factor risk scoring, case folder auto-creation, 4-sheet Excel dashboard, 17-section PDF report, and immutable audit trail. Covers UK/EU (AMLD5), US…
risk-assessment
Deterministic heuristic risk scoring using a four-factor weighted model (Geographic 30%, Customer 35%, Product 25%, Channel 10%) aligned with Basel III, EBA Guidelines, FATF standards, and FinCEN guidance. Bands: LOW (0-20), MEDIUM (21-60), HIGH (61-80), CRITICAL (81-100).