Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add sutchan/Agent-Skills-Hub --skill compliancegit clone --depth 1 https://github.com/sutchan/Agent-Skills-HubWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/sutchan/agent-skills-hub/compliance)<a href="https://agentmods.dev/skills/sutchan/agent-skills-hub/compliance"><img src="https://agentmods.dev/badge/skills/sutchan/agent-skills-hub/compliance/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/sutchan/agent-skills-hub/compliance"><img src="https://agentmods.dev/badge/skills/sutchan/agent-skills-hub/compliance.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00045 | $0.04203 |
| Opus 5 | $0.00023 | $0.02101 |
| Sonnet 5 | $0.00009 | $0.00841 |
| Haiku 4.5 | $0.00005 | $0.00420 |
Grade A, and why
compliance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 800 lines — stays where its author put it; the contents beside it link to each section on GitHub.
合规运营 (Compliance)
概述
合规运营的核心原则:了解规则、遵守规则、主动合规、长期主义。
小红书平台有严格的社区规范和内容规则。合规运营不是被动的"不违规",而是主动理解平台规则导向,将规则内化为创作准则,实现长期稳定发展。
使用场景
需要本技能的典型情况:
- 新账号起步,需要了解平台规则
- 内容被限流或违规处罚
- 不确定内容是否合规
- 希望避免账号风险
- 需要申诉违规处罚
- 想要了解平台最新规则
违规类型分类:
- 内容违规:虚假宣传、低质内容、抄袭搬运
- 营销违规:过度营销、导流行为、虚假交易
- 行为违规:刷数据、恶意举报、骚扰用户
- 法律违规:违法内容、侵权行为、不当言论
核心模式
❌ 被动应对思维
不知道规则
↓
无意违规
↓
被处罚
↓
临时整改
↓
再次违规
↓
账号风险累积
✅ 主动合规思维
学习规则
↓
理解规则导向
↓
内化规则为创作准则
↓
主动合规
↓
长期稳定发展
↓
账号健康度提升
关键差异:
- 被动:不知道规则,违规后才学习
- 主动:先学习规则,避免违规
快速参考
| 违规类型 | 严重程度 | 处罚措施 | 预防方法 |
|---|---|---|---|
| 虚假宣传 | 高 | 限流/降权/封号 | 真实宣传,证据留存 |
| 过度营销 | 中 | 限流/警告 | 价值优先,营销其次 |
| 抄袭搬运 | 高 | 内容下架/扣分 | 原创内容,授权使用 |
| 导流行为 | 中 | 警告/限流 | 遵守平台规则 |
| 刷数据 | 高 | 扣分/封号 | 真实数据,诚信经营 |
实施步骤
第1步:学习平台规则
核心逻辑:不了解规则就无法合规。系统学习是第一步。
1.1 核心规则文档
**必读规则文档:**
**1. 小红书社区规范:**
位置:小红书官网 → 社区规范
核心内容:
- 禁止内容类型
- 违规行为定义
- 处罚措施说明
- 申诉流程
重要性:⭐⭐⭐⭐⭐
**2. 内容创作规范:**
核心内容:
- 内容质量标准
- 禁止内容类型
- 推荐机制说明
- 限流风险因素
重要性:⭐⭐⭐⭐⭐
**3. 商业行为规范:**
核心内容:
- 广告标识要求
- 交易规范
- 评测规范
- 退货维权规范
重要性:⭐⭐⭐⭐
**4. 知识产权规范:**
核心内容:
- 版权保护
- 商标使用
- 肖像权
- 侵权处理
重要性:⭐⭐⭐⭐
1.2 规则解读
**关键规则解读:**
**虚假宣传:**
定义:
- 夸大产品效果
- 虚构使用体验
- 不实承诺
- 假冒伪劣
示例: ❌ "用一次就年轻10岁" ❌ "100%有效" ❌ "完全无副作用" ✅ "亲测有效,效果因人而异" ✅ "90%用户反馈有效"
**过度营销:**
定义:
- 频繁硬广
- 纯推销内容
- 无价值输出
- 引导站外交易
示例: ❌ 每篇都是产品推销 ❌ 直接留微信号/手机号 ❌ 评论区引导私信购买 ✅ 80%价值+20%营销 ✅ 平台内完成交易
**内容低质:**
定义:
- 内容空洞
- 信息量少
- 无实际价值
- 重复单调
示例: ❌ 纯图片无文字 ❌ "好物分享"无详细说明 ❌ 抄袭他人内容 ✅ 详细说明和价值输出 ✅ 原创内容
1.3 规则更新追踪
**保持规则更新:**
**官方渠道:**
-
小红书官方公告
- 定期查看
- 重点关注规则更新
-
创作者中心
- 规则提醒
- 违规通知
-
官方社群/活动
- 规则培训
- 案例分享
**学习习惯:**
- 每月查看规则更新
- 关注官方公告
- 参加官方培训
- 加入创作者社群
第2步:内容合规检查
核心逻辑:发布前主动检查,避免违规。
2.1 发布前检查清单
**内容合规清单:**
**内容真实性:**
✓ 产品体验真实 ✓ 效果描述客观 ✓ 不夸大承诺 ✓ 数据有来源
检查:
- 是否有夸大宣传?
- 是否有不实承诺?
- 效果描述是否客观?
- 有无虚构成分?
**广告标识:**
✓ 商业内容明确标注 ✓ 合作内容说明 ✓ 广告内容标识 ✓ 赠品说明
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 800 lines · 45 tokens per session scan A 7f46f3deeafe
compliance is a skill published in the GitHub repository sutchan/Agent-Skills-Hub (2 stars, last pushed yesterday), licensed MIT. It adds 45 tokens to every session and 4,203 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.
Other skills, from other repositories
iflytek-contract-intelligence-review
A contract-review workflow for scanned or digital agreements. It can recognize document text, examine clauses, detect risks, check compliance, and create translation summaries; its output is for review and is not formal legal advice.
compliance-gdpr-privacy-expert
Expert guide for Data Privacy, GDPR, CCPA, and PDPA compliance. Covers consent management, data retention, privacy-by-design, and audit trails / Panduan kepatuhan Privasi Data, GDPR, dan PDPA.
customs-trade-compliance
Codified expertise for customs documentation, tariff classification, duty optimization, restricted-party screening, and regulatory compliance across US/EU/UK/APAC jurisdictions, including HS classification logic, Incoterms application, FTA utilization, and penalty mitigation. Use when classifying goods, preparing…
data-retention-and-privacy-by-design
Use when the user asks to "design a new data model that stores personal data", "add a retention policy", "figure out how long to keep guest data", "handle a data deletion request", "design for GDPR compliance", or is adding any field/table that captures a name, email, phone, ID document, or payment detail. Guides…
dependency-and-license-policy
Use when the user asks to "add a dependency", "vet a license", "check if this package is safe to use", "can we use this library", "add this to go.mod/package.json", or is preparing a proprietary/closed-source product that bundles open-source code. Guides license-compatibility review before a dependency is pulled in…
receiving-code-review
Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable - requires technical rigor and verification, not performative agreement or blind implementation.