Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zgbrenner/agentcounsel --skill cross-border-transfer-reviewgit clone --depth 1 https://github.com/zgbrenner/agentcounselWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zgbrenner/agentcounsel/cross-border-transfer-review)<a href="https://agentmods.dev/skills/zgbrenner/agentcounsel/cross-border-transfer-review"><img src="https://agentmods.dev/badge/skills/zgbrenner/agentcounsel/cross-border-transfer-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zgbrenner/agentcounsel/cross-border-transfer-review"><img src="https://agentmods.dev/badge/skills/zgbrenner/agentcounsel/cross-border-transfer-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00083 | $0.04148 |
| Opus 5 | $0.00042 | $0.02074 |
| Sonnet 5 | $0.00017 | $0.00830 |
| Haiku 4.5 | $0.00008 | $0.00415 |
Grade A, and why
Cross-Border Transfer Review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 155 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Cross-Border Transfer Review
Purpose
Produce a structured, attorney-ready review of a proposed or existing cross-border personal-data transfer. The skill inventories the data flows described in the provided materials (who exports, who imports, in what roles, which data, for what purposes), maps the transfer mechanisms the materials claim to rely on, organizes the fact pattern an attorney needs to complete a transfer impact assessment, traces onward transfers and sub-processor chains, and produces a gap list. It produces draft legal work product for attorney review — not legal advice.
This skill never concludes that a transfer is lawful, that a mechanism is valid or sufficient, or that a destination country's legal regime does or does not permit the transfer. Transfer-mechanism validity, adequacy status, derogation availability, and destination-country access-regime analysis are jurisdiction-specific, change over time, and are attorney determinations — every such point in the output is a flagged verification item, described generically and marked [verify current law] or [ATTORNEY TO CONFIRM].
Use When
- A new vendor, hosting arrangement, or support model would move personal data to another country, and counsel needs the flows and claimed mechanisms organized before assessing them.
- An intercompany or intragroup data flow (shared HR systems, centralized CRM, global analytics) crosses borders and needs a structured review.
- A DPA's transfer exhibit, standard-contractual-clauses-style annexes, or an equivalent transfer addendum has been provided and the team needs the flows, roles, and annex completeness inventoried.
- Counsel has asked for the fact pattern for a transfer impact assessment — data categories, destination, importer commitments, supplementary measures — organized for attorney completion.
- An existing transfer is being re-reviewed after a change: a new destination, a new sub-processor, a changed mechanism, or an updated annex.
- Diligence on a vendor or transaction surfaced cross-border flows that need mapping before contract or closing.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 155 lines · 83 tokens per session scan A 56da34e73223
Cross-Border Transfer Review is a skill published in the GitHub repository zgbrenner/agentcounsel (19 stars, last pushed 1mo ago), licensed MIT. It adds 83 tokens to every session and 4,148 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
gdpr-data-handling-note
Drafts a plain-language data handling notice for a journalistic or media production project that involves collecting, storing, or processing personal data — structured to meet GDPR transparency requirements while remaining understandable to non-lawyers.
gdpr-note-writer
Drafts a GDPR compliance note for a specific piece of journalistic content or data collection activity — documenting the lawful basis for processing personal data, what data is held, how long it is retained, and who has access.
implementing-gdpr-data-protection-controls
The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. This skill cover.
gdpr-privacy
Use when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art. 28 DPA, an SCC transfer mechanism, or a DSAR flow. Drafts for counsel review. NOT internal retention rules (that is data-policy), NOT…
gdpr-expert
Expert in GDPR compliance, data protection, privacy by design, consent management, DPO responsibilities, and EU data regulations. Use when the user mentions privacy, data protection, compliance, consent, a DPO, or eu regulation, or when the task involves GDPR Fundamentals, Key Principles, Data Subject Rights, or…
legal-risk-checker
Reviews a story brief, draft article, or broadcast script and flags potential legal risks — including defamation, privacy, contempt of court, and data protection — so you know what to check before publication.