Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zgbrenner/agentcounsel --skill transaction-monitoring-alert-triagegit clone --depth 1 https://github.com/zgbrenner/agentcounselWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zgbrenner/agentcounsel/transaction-monitoring-alert-triage)<a href="https://agentmods.dev/skills/zgbrenner/agentcounsel/transaction-monitoring-alert-triage"><img src="https://agentmods.dev/badge/skills/zgbrenner/agentcounsel/transaction-monitoring-alert-triage/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zgbrenner/agentcounsel/transaction-monitoring-alert-triage"><img src="https://agentmods.dev/badge/skills/zgbrenner/agentcounsel/transaction-monitoring-alert-triage.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00071 | $0.03581 |
| Opus 5 | $0.00036 | $0.01791 |
| Sonnet 5 | $0.00014 | $0.00716 |
| Haiku 4.5 | $0.00007 | $0.00358 |
Grade A, and why
Transaction Monitoring Alert Triage scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 168 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Transaction Monitoring Alert Triage
Purpose
Produce a structured, review-ready draft triage of a transaction-monitoring alert (or a small batch of alerts) on an existing customer. The skill inventories the alert data and the rule that fired, organizes the customer's profile and expected-activity baseline against the observed activity, structures the escalate / close / request-more-information analysis as explicit questions with the evidence bearing on each, and packages the documentation-of-rationale items a disposition file needs.
This skill provides workflow discipline and analytical structure. It produces draft work product for review by the firm's compliance function and a supervising attorney. This is not legal advice and not an alert disposition. The skill never decides that activity is or is not suspicious — the compliance officer decides. Any decision about whether to file a suspicious activity report, and any drafting of such a report, is outside this skill and belongs to compliance and counsel.
Use When
- A user says "triage this transaction-monitoring alert," "work through these TM alerts," or "help me document this alert review."
- A monitoring rule or scenario has fired on an existing customer and a first-pass, structured review is needed before the compliance officer dispositions the alert.
- An analyst needs the customer's expected-activity baseline organized against observed activity so the disposition rationale can be documented.
- A small batch of related alerts on the same customer needs to be organized into one coherent triage file.
Required Inputs
- The alert record(s): the actual alert data — the alert identifier, the monitoring rule or scenario that fired, its parameters or thresholds as stated in the alert or the firm's rule documentation, the review window, and the triggering transactions. If no alert record is provided, stop and request it.
- The customer profile: the KYC file or a current extract — customer type, current risk rating, the expected-activity or anticipated-transaction baseline recorded at onboarding or last review, and the nature of the relationship. If no profile is provided, stop and request it; expected-versus-observed comparison is the core of the triage.
- Transaction data for the review window: the triggering transactions and enough surrounding activity to give context, with dates, amounts, channels, and counterparties as recorded.
- The firm's alert-triage or investigation procedure: the firm document setting out disposition options, escalation criteria, and documentation requirements. If not provided, stop and request it. Do not apply triage criteria from model background knowledge.
- Prior alerts and dispositions (optional): the customer's alert history, if available.
- Screening results (optional): sanctions, PEP, and adverse-media results for the customer and alert counterparties, if a run has been completed. The skill does not perform live screening.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 168 lines · 71 tokens per session scan A 171a2e4814de
Transaction Monitoring Alert Triage is a skill published in the GitHub repository zgbrenner/agentcounsel (19 stars, last pushed 1mo ago), licensed MIT. It adds 71 tokens to every session and 3,581 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
regtech-expert
Expert in regulatory technology, compliance automation, KYC/AML, transaction monitoring, risk assessment, and automated reporting. Use when the user mentions compliance, KYC, AML, transaction monitoring, risk assessment, or regulatory reporting, or when the task involves KYC/AML Compliance, KYC/AML Program, Regulatory…
historical-cost-analyzer
Analyze historical construction costs for benchmarking, trend analysis, and estimating calibration. Compare projects, track escalation, identify patterns.
cwicr-escalation
Apply price escalation to CWICR estimates over time. Calculate inflation adjustments, material price indices, and labor rate increases.
cwicr-location-factor
Apply geographic location factors to CWICR estimates. Adjust costs for regional labor rates, material prices, and market conditions.
cash-flow-forecaster
Forecast project cash flow based on schedule and cost data. Generate S-curves and payment projections.
auto-estimate-generator
Automatically generate estimates from QTO data. Apply pricing rules to BIM quantities for cost estimates.