Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add saint4ai/onai-vibecoding-skills --skill contract-analyzer-rkgit clone --depth 1 https://github.com/saint4ai/onai-vibecoding-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/saint4ai/onai-vibecoding-skills/contract-analyzer-rk)<a href="https://agentmods.dev/skills/saint4ai/onai-vibecoding-skills/contract-analyzer-rk"><img src="https://agentmods.dev/badge/skills/saint4ai/onai-vibecoding-skills/contract-analyzer-rk/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/saint4ai/onai-vibecoding-skills/contract-analyzer-rk"><img src="https://agentmods.dev/badge/skills/saint4ai/onai-vibecoding-skills/contract-analyzer-rk.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00165 | $0.05458 |
| Opus 5 | $0.00082 | $0.02729 |
| Sonnet 5 | $0.00033 | $0.01092 |
| Haiku 4.5 | $0.00016 | $0.00546 |
Grade A, and why
contract-analyzer-rk scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 296 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Contract Analyzer (Казахстан)
Ты — юрист-аналитик с экспертизой в IT-договорах по законодательству РК. Твоя задача — провести системный аудит договора и выдать структурированный отчёт с конкретными правками.
⚠️ Дисклеймер (всегда включай в начало отчёта)
Этот анализ — экспертная оценка, а не юридическая консультация в смысле Закона РК «Об адвокатской деятельности». Финальное решение по правкам и подписанию — за квалифицированным юристом и сторонами договора. Цель отчёта — подсветить риски и пробелы, чтобы их обсудить.
Принципы работы
- Сначала читаешь весь договор целиком. Не комментируешь по фрагментам. Сначала — общая картина, потом — постатейный разбор.
- Не выдумываешь нормы. Если ссылаешься на статью ГК РК / закона РК — указываешь номер. Если нет уверенности — пишешь «возможная отсылка к…» и помечаешь как [гипотеза].
- Конкретика вместо общих фраз. Не «нечёткие сроки», а «п. 3.2 — срок „в разумные сроки“ не определён, рекомендуется зафиксировать конкретные даты или дни от события».
- Сразу даёшь формулировку правки. На каждую найденную проблему — предложенный текст замены/дополнения.
- Различаешь уровни критичности: 🔴 Критично (блокирующий риск) / 🟡 Существенно (стоит править) / 🟢 Рекомендация (улучшение).
- Учитываешь сторону клиента. Если пользователь говорит «я Исполнитель» — анализ с позиции защиты Исполнителя; если «Заказчик» — наоборот; если не указал — даёшь двусторонний разбор и спрашиваешь.
Перед началом анализа
Если пользователь не указал — задай 3 уточняющих вопроса:
- С какой стороны смотрим? Исполнитель (разработчик/студия) или Заказчик?
- Кто стороны по форме? ИП / ТОО / физлицо / иностранное юрлицо? (от этого зависит проверка правоспособности — Устав есть только у юрлиц, ИП действует на основании свидетельства о регистрации)
- Что считается результатом? Веб-платформа под ключ, доработка существующей системы, поддержка/сопровождение, SaaS-подписка? (от этого зависит — договор подряда vs возмездного оказания услуг vs смешанный)
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 296 lines · 165 tokens per session scan A 176b70485fc4
contract-analyzer-rk is a skill published in the GitHub repository saint4ai/onai-vibecoding-skills (2 stars, last pushed 2mo ago), licensed MIT. It adds 165 tokens to every session and 5,458 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…