Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zgbrenner/agentcounsel --skill cookie-consent-reviewgit clone --depth 1 https://github.com/zgbrenner/agentcounselWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zgbrenner/agentcounsel/cookie-consent-review)<a href="https://agentmods.dev/skills/zgbrenner/agentcounsel/cookie-consent-review"><img src="https://agentmods.dev/badge/skills/zgbrenner/agentcounsel/cookie-consent-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zgbrenner/agentcounsel/cookie-consent-review"><img src="https://agentmods.dev/badge/skills/zgbrenner/agentcounsel/cookie-consent-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00046 | $0.03315 |
| Opus 5 | $0.00023 | $0.01657 |
| Sonnet 5 | $0.00009 | $0.00663 |
| Haiku 4.5 | $0.00005 | $0.00331 |
Grade A, and why
Cookie Consent Review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 139 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Cookie Consent Review
Purpose
Organize a review of a website or app's cookie and tracking-technology consent implementation into an attorney-ready fact record. The skill inventories the trackers actually present against what the site or app discloses, describes the consent-banner mechanics as implemented, records consent-record-keeping facts, names dark-pattern indicators neutrally, notes the presence of a consent management platform (CMP) or IAB TCF-style framework as a fact (not an endorsement), and flags cross-border divergence. It produces draft legal work product for attorney review — not legal advice.
This skill never concludes that a consent implementation "is compliant," that a banner design "is" or "is not" a dark pattern, or that a given consent record satisfies any law's evidentiary requirements. Those are attorney determinations that vary by jurisdiction, regulator guidance, and the totality of the implementation. The skill organizes the facts so counsel can make that determination.
Use When
- A website or app's cookie banner, tracker inventory, or consent flow needs a first-pass legal/compliance read.
- A privacy or marketing team has run a tracker scan and needs the results compared against the cookie notice or privacy policy.
- The organization is evaluating or has just deployed a consent management platform (CMP) and wants its configuration facts organized for review.
- A regulator inquiry, complaint, or internal audit has raised a question about whether disclosed and actual tracking match, or whether the consent flow gives users a genuine choice.
- The organization operates across multiple markets and needs the site's consent mechanics checked for jurisdiction-specific divergence (for example, prior-consent vs. opt-out models, or reject-parity requirements).
- A redesign of the cookie banner or consent flow is proposed and the current-state facts need to be captured before changes are made.
Required Inputs
- The tracker inventory or scan output — a list of cookies, pixels, SDKs, and other tracking technologies actually present on the site or app, ideally from a scan tool or manual audit, including the technology name, vendor, and stated category (essential, functional, analytics, advertising, etc.), if categorized. Do not proceed on a description of "we use some cookies" alone.
- The cookie/tracking disclosure text — the cookie notice, cookie policy, or the tracking section of the privacy policy, in full.
- A description or screenshots of the consent banner — its timing (does tracking occur before a choice is made), the choices actually offered (accept all, reject all, customize, close/dismiss), the visual layout and prominence of each choice, and any pre-checked boxes or pre-selected categories.
- Consent-record-keeping facts — what the organization logs when a user makes a choice (timestamp, choice made, banner version, user/device identifier), where the record is stored, and the stated retention period for consent records.
- Optional: whether a CMP or IAB TCF-style framework is in use, and which one.
- Optional: the geographies/markets where the site or app operates, so cross-border divergence can be flagged against the actual footprint rather than assumed.
- Optional: the practice group's
practice-profiles/privacy.mdif populated and loaded alongside this skill. If present, use its Standard Positions and Escalation Thresholds to benchmark the review; if absent, proceed without profile benchmarking.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 139 lines · 46 tokens per session scan A 884cb3d60134
Cookie Consent Review is a skill published in the GitHub repository zgbrenner/agentcounsel (19 stars, last pushed 1mo ago), licensed MIT. It adds 46 tokens to every session and 3,315 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
gdpr-privacy
Use when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art. 28 DPA, an SCC transfer mechanism, or a DSAR flow. Drafts for counsel review. NOT internal retention rules (that is data-policy), NOT…
legal-risk-checker
Reviews a story brief, draft article, or broadcast script and flags potential legal risks — including defamation, privacy, contempt of court, and data protection — so you know what to check before publication.
gdpr-data-handling-note
Drafts a plain-language data handling notice for a journalistic or media production project that involves collecting, storing, or processing personal data — structured to meet GDPR transparency requirements while remaining understandable to non-lawyers.
gdpr-note-writer
Drafts a GDPR compliance note for a specific piece of journalistic content or data collection activity — documenting the lawful basis for processing personal data, what data is held, how long it is retained, and who has access.
implementing-gdpr-data-subject-access-request
Automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging. Covers ICO/EDPB guidance compliance, exemption handling, and…
privacy-generator
Generates comprehensive privacy policies by scanning websites for data collection signals including cookies, forms, payment processors, and third-party scripts. Use when launching a website or app that collects user data and needs GDPR/CCPA compliance. Trigger with "/privacy-generator" or "create a privacy policy for…