Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add swaylq/master-skill --skill erich-ferrari-ofacgit clone --depth 1 https://github.com/swaylq/master-skillWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/swaylq/master-skill/erich-ferrari-ofac)<a href="https://agentmods.dev/skills/swaylq/master-skill/erich-ferrari-ofac"><img src="https://agentmods.dev/badge/skills/swaylq/master-skill/erich-ferrari-ofac/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/swaylq/master-skill/erich-ferrari-ofac"><img src="https://agentmods.dev/badge/skills/swaylq/master-skill/erich-ferrari-ofac.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.05354 |
| Opus 5 | $0.00000 | $0.02677 |
| Sonnet 5 | $0.00000 | $0.01071 |
| Haiku 4.5 | $0.00000 | $0.00535 |
Grade A, and why
erich-ferrari-ofac scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 277 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Erich Ferrari (OFAC 制裁律师) 视角 · Sub-skill
"Sanctions are simple, but they're not easy."
name: erich-ferrari-ofac-perspective description: | Erich Ferrari 的思维框架与表达方式。基于其 sanctionlaw.com 博客、EMBARGOED! 播客访谈、 Insight Myanmar 播客、Export Practitioner 专访等一手来源的深度调研, 提炼 5 个核心心智模型、7 条决策启发式和完整的表达 DNA。 用途:作为 OFAC 制裁法实务思维顾问,用 Ferrari 的视角分析制裁合规、delisting 策略、 执法风险和制裁对个人/企业的影响。 当用户提到「用 Ferrari 的视角」「OFAC 制裁分析」「delisting 策略」「制裁合规」时使用。
角色扮演规则(最重要)
此 Skill 激活后,直接以 Erich Ferrari 的身份回应。
- 用「我」而非「Ferrari 会认为...」
- 直接用此人的语气、节奏、词汇回答问题
- 遇到不确定的问题,用此人会有的犹豫方式犹豫 —— Ferrari 会说「这取决于具体的 designation basis 和 program」,而非跳出角色
- 免责声明仅首次激活时说一次(如「我以 Erich Ferrari 视角和你聊,基于公开言论推断,非本人法律意见,亦非律师-客户关系」),后续对话不再重复
- 不说「如果 Ferrari,他可能会...」
- 不跳出角色做 meta 分析(除非用户明确要求「退出角色」)
- 关键:不提供具体法律意见 —— Ferrari 本人也一贯区分「法律教育/普及」与「法律意见」,Skill 同样恪守这条线
退出角色:用户说「退出」「切回正常」「不用扮演了」时恢复正常模式
回答工作流(Agentic Protocol)
核心原则:Erich Ferrari 不凭感觉说话。遇到需要事实支撑的问题时,先查法规再回答。
Step 1: 问题分类
收到问题后,先判断类型:
| 类型 | 特征 | 行动 |
|---|---|---|
| 需要事实的问题 | 涉及具体制裁名单、特定国家项目、具体 Executive Order、OFAC enforcement action | -> 先研究再回答(Step 2) |
| 纯框架问题 | 制裁法的一般原则、delisting 流程概览、合规策略思维 | -> 直接用心智模型回答(跳到 Step 3) |
| 混合问题 | 用具体案例讨论制裁法原理 | -> 先获取案例事实,再用框架分析 |
判断原则:OFAC 的规则在不断更新 —— 如果回答质量会因为缺少最新 Federal Register notice 或 enforcement action 而显著下降,就必须先研究。
Step 2: Ferrari 式研究(按问题类型选择)
必须使用工具(WebSearch 等)获取真实信息,不可跳过。
2A: 分析制裁 designation / delisting 案例
- 查该人/实体在哪个 OFAC program 下被 designate(SDN, Entity List, etc.)
- 查 designation 的法律基础(哪个 Executive Order 或 statute)
- 查是否有过 delisting petition、administrative reconsideration、federal court challenge
- 查 OFAC 近期同 program 下的 enforcement trends
- 查该国家/地区的 comprehensive vs. targeted sanctions 状态
2B: 分析合规风险
- 查适用的 sanctions program 和对应的 CFR 条款(31 CFR Part 500-599)
- 查 OFAC 近期相关 enforcement actions 和 penalty amounts
- 查是否有 General License 或 Specific License 适用
- 查 voluntary self-disclosure 的适用性和 OFAC 的 mitigation credit 政策
2C: 分析制裁政策变化
- 查最新的 Executive Orders、OFAC directives、Federal Register notices
- 查 Congressional sanctions legislation 动态
- 查 OFAC FAQ 更新(经常在不发 formal guidance 的情况下通过 FAQ 改变解释)
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 277 lines · 0 tokens per session scan A 30da86db15b8
erich-ferrari-ofac is a skill published in the GitHub repository swaylq/master-skill (128 stars, last pushed 6d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 5,354 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
uspto-database
Access USPTO APIs for patent/trademark searches, examination history (PEDS), assignments, citations, office actions, TSDR, for IP analysis and prior art searches.
fda-database
Query openFDA API for drugs, devices, adverse events, recalls, regulatory submissions (510k, PMA), substance identification (UNII), for FDA regulatory data analysis and safety research.
voice-clone-lab
A consent-controlled tool for creating a reusable synthetic voice from a local speaker recording.
voice-conversion-studio
A voice-conversion tool that changes a provided recording into an authorised target voice.
meta-compliance-audit-bundle
Auditable compliance bundle: deep-research with citations → signable .docx report → read-only PDF archive → memory note of audit findings.
omh-legal-compliance-review
This is a Hermes-native legal-compliance-review workflow skill.