Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zhou210712/claude-for-legal-ZH --skill cold-start-interviewgit clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZHWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/cold-start-interview)<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/cold-start-interview"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/cold-start-interview/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/cold-start-interview"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/cold-start-interview.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00051 | $0.04389 |
| Opus 5 | $0.00026 | $0.02194 |
| Sonnet 5 | $0.00010 | $0.00878 |
| Haiku 4.5 | $0.00005 | $0.00439 |
Grade A, and why
cold-start-interview scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
75% identical to smart-search — 506 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 457 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/cold-start-interview
- 检查
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md是否已存在。如果存在且用户未传递--redo→ "AI治理实践配置已存在于 [路径]。使用--redo重新运行。" - 运行以下访谈。一次进行一个部分。
- 选项后附
(✓)标注推荐默认值。 - 当所有部分完成后,写入
CLAUDE.md。
/ai-governance-legal:cold-start-interview
/ai-governance-legal:cold-start-interview --redo
AI治理实践配置访谈
此访谈建立你的AI治理实践配置——中国AI法规框架下你是谁、你遵守什么、你如何遵守、以及输出到哪里。一次进行一个部分。始终保持选项后附 (✓) 标注推荐默认值。
第1部分:实践类型
1. 你如何使用AI法律技能?
A. 法务内部——为单一雇主/公司管理AI法律事务 (✓) B. 私人执业——为多个客户处理AI法律事务(独立执业/小型律所/大型律所)
如果A:"了解——你将以实践级上下文工作,无需事务工作区。" 如果B:"了解——事务工作区将被启用,以保持客户上下文隔离。"
2. 你是执业律师吗?
A. 是——执业律师 B. 否——法务/合规专业人士(非法学背景)(✓) C. 否——其他角色
这将影响工作成果标签("律师工作成果/受律师-客户特权保护" vs 非法务角色的标准保密说明)以及发送DSAR类信函前的"是否经律师审阅"闸门。
第2部分:你的AI使用概况
3. 你的组织目前使用AI吗?选择最准确的一项:
A. 积极开发和部署AI系统(作为AI服务提供者)并向公众/客户提供服务 B. 使用第三方AI服务(作为AI服务使用者)用于内部业务或嵌入产品 C. 两者兼有——既开发也使用 (✓) D. 计划使用,但尚未部署 E. 不涉及AI——仅评估AI风险或进行政策审查
4. 你使用的AI技术类型(多选):
☐ 机器学习/深度学习模型 ☐ 大语言模型(LLM)/生成式AI ☐ 计算机视觉 ☐ 自然语言处理(非生成式) ☐ 推荐系统/算法推荐 ☐ 深度合成(Deepfake / 人脸替换等) ☐ 语音识别/合成 ☐ 自动化决策系统(信贷、定价、评估等) ☐ 其他:[填写]
5. 你的AI系统处理什么类型的数据?(多选)
☐ 不涉及个人信息(如公开数据、工业数据)
☐ 普通个人信息
☐ 敏感个人信息(《个人信息保护法》第28条 [法条原文]:生物识别、医疗健康、金融账户、行踪轨迹等)
☐ 未成年人个人信息(受《儿童个人信息网络保护规定》+ 个保法第31条保护 [法条原文])
☐ 重要数据/核心数据(根据《数据安全法》[法条原文])
☐ 国家秘密或安全相关数据
☐ 不确定——需要进一步梳理
6. 你的AI系统面向谁?
☐ 仅内部员工 ☐ 商业客户(B2B) ☐ 公众用户(B2C / 向公众开放) ☐ 未成年人用户
第3部分:监管注册表
7. 哪些AI相关法规适用于你?(多选——根据以上回答推荐)
根据你的AI使用概况,以下法规可能适用:
☐ 《生成式人工智能服务管理办法》 — 如果你向公众提供生成式AI服务 (✓推荐)
☐ 《互联网信息服务算法推荐管理规定》 — 如果你使用算法推荐技术 (✓推荐)
☐ 《互联网信息服务深度合成管理规定》 — 如果你提供深度合成服务
☐ 《科技伦理审查办法(试行)》 [法条原文] — 如果涉及生命健康、社会公共利益等
☐ 《个人信息保护法》 — 如果处理个人信息 (✓推荐)
☐ 《数据安全法》 — 如果涉及重要数据或核心数据
☐ 《网络安全法》 — 基础性网络安全义务
☐ 行业特定AI规定(请说明行业:[金融/医疗/汽车/教育/其他])
☐ 仍在确认中——需要进一步研究
8. 对于每项适用的法规,你的合规进展如何?
对每项标记为:
- ✅ 已完成合规建设,有定期审查机制
- ⚠️ 部分合规,部分义务尚未完成
- ❌ 尚未开始正式合规建设
- ❓ 不确定——需要差距分析
第4部分:算法备案
9. 你是否需要进行算法备案?
A. 是——已完成部分或全部备案 (→ 进入问题10) B. 是——尚未开始,需要尽快完成 C. 否——不适用算法备案要求 D. 不确定——需要进一步评估
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 457 lines · 51 tokens per session scan A 76fb9f47ac73
cold-start-interview is a skill published in the GitHub repository zhou210712/claude-for-legal-ZH (212 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 51 tokens to every session and 4,389 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 75% identical to smart-search, differing in 506 lines, and is treated as a copy.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…