Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add s0912758806p/agentic-sop-to-work --skill alcoa-guardgit clone --depth 1 https://github.com/s0912758806p/agentic-sop-to-workWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/s0912758806p/agentic-sop-to-work/alcoa-guard)<a href="https://agentmods.dev/skills/s0912758806p/agentic-sop-to-work/alcoa-guard"><img src="https://agentmods.dev/badge/skills/s0912758806p/agentic-sop-to-work/alcoa-guard/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/s0912758806p/agentic-sop-to-work/alcoa-guard"><img src="https://agentmods.dev/badge/skills/s0912758806p/agentic-sop-to-work/alcoa-guard.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00177 | $0.00437 |
| Opus 5 | $0.00088 | $0.00218 |
| Sonnet 5 | $0.00035 | $0.00087 |
| Haiku 4.5 | $0.00018 | $0.00044 |
Grade A, and why
alcoa-guard scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
alcoa-guard — ALCOA+ Data-Integrity Linter
You are a deterministic data-integrity checker. You NEVER auto-conclude compliance.
Mode
- A kit run dir (has
run_manifest.json) → FULL:python3 -m alcoaguard.review --run-dir <dir> - A plain record (CSV/JSON) → DEGRADED:
python3 -m alcoaguard.review --record <file> --contract <.alcoa.json>
Steps
- Run the deterministic linter (above). It writes
alcoa_guard.json+alcoa_guard.md. - Present the HARD/SOFT findings verbatim. Do not soften or invent.
- Present the human-judgment checklist — these are NOT auto-verified; a human must assess them.
- STOP. The human owns the verdict; a deterministic GREEN is not "fully compliant".
Iron rules
- Facts only from the record + contract; never fabricate a violation or a value.
- Uncertain (e.g. inferred contract) → human-judgment checklist, never a HARD claim.
- Output is a DRAFT for human review — you never approve or reject.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 24 lines · 177 tokens per session scan A 8137780aebcb
alcoa-guard is a skill published in the GitHub repository s0912758806p/agentic-sop-to-work (208 stars, last pushed 3d ago), licensed MIT. It adds 177 tokens to every session and 437 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
disclosure-gating
Gate every externally-visible sentence through the claim and disclosure register in 00-control/claim-and-disclosure-register.md (CL-####), then derive 06-public/technical-partner-guide.md and 06-public/customer-product-and-trust-guide.md from approved rows only. Use when drafting or editing any public document, when…
usage-policy-writer
Generate a human-facing AI usage policy with approved tools, data classification, risk model explanations, and exception processes — saved to $HOME/.ai-first-kit/. Produces a policy document for HUMANS (not agents) that explains what AI tools are approved, what data can be used with AI, and the reasoning behind each…
especialista-em-gestao-de-saude
Especialista em Gestão de Saúde. Use para gestão de saúde e serviços assistenciais: indicadores de saúde, qualidade assistencial, regulação, saúde populacional e conformidade. Palavras-chave: gestão de saúde, assistencial, indicadores, qualidade, regulação, saúde populacional, LGPD/HIPAA.
domain-expert
Use this skill during /plan (between scope validation and writing the plan artifact) to inject domain-specific context, gap questions, and regulatory concerns into the plan. Triggers automatically when the plan skill evaluates the task and scope.md against the domain registry in domains/index.json using semantic…
clinical-reports
Write comprehensive clinical reports including case reports (CARE guidelines), diagnostic reports (radiology/pathology/lab), clinical trial reports (ICH-E3, SAE, CSR), and patient documentation (SOAP, H&P, discharge summaries). Full support with templates, regulatory compliance (HIPAA, FDA, ICH-GCP), and validation…
fda-database
Query openFDA API for drugs, devices, adverse events, recalls, regulatory submissions (510k, PMA), substance identification (UNII), for FDA regulatory data analysis and safety research.