Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zhou210712/claude-for-legal-ZH --skill policy-startergit clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZHWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/policy-starter)<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/policy-starter"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/policy-starter/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/policy-starter"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/policy-starter.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00056 | $0.02607 |
| Opus 5 | $0.00028 | $0.01303 |
| Sonnet 5 | $0.00011 | $0.00521 |
| Haiku 4.5 | $0.00006 | $0.00261 |
Grade A, and why
policy-starter scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
84% identical to smart-search — 288 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 239 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/policy-starter
- 读取
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md→ 监管注册表(适用法规)、AI系统清单(已在使用的AI)、公司的实践位置(风险偏好、透明度承诺)。 - 运行以下工作流。
- 确定受众 → 选择模板 → 填充公司的具体内容 → 输出草案。
- 附一份"仍需决定"清单——政策初稿解决不了的问题,需要由人来拍板。
/ai-governance-legal:policy-starter "内部员工AI使用政策"
/ai-governance-legal:policy-starter "面向用户"
/ai-governance-legal:policy-starter
[省略参数以获取受众选择提示]
AI使用政策起草
目的
没有AI使用政策的AI实践是在裸奔。监管机构、客户和用户都想知道:你用AI吗?用在哪里?怎么用?哪些数据被用于训练?这项技能基于你的实际实践和监管义务起草一份AI使用政策初稿。
加载当前状态
读取 ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md:
## 监管注册表— 适用的法规,决定了政策的合规底线## AI系统清单— 已经在使用或计划使用的AI——政策不能比实际做得多或做得少## 红线— 绝对不做的——政策应反映这些红线## 实践位置— 公司的风险偏好、透明度立场、AI使用原则
工作流
第1步:确定受众和范围
| 受众 | 目的 | 典型内容 |
|---|---|---|
| 面向用户/公众 | 告知用户公司如何使用AI处理其数据或提供服务 | AI系统的存在、AI决策的性质、用户如何获取人工介入、数据如何使用 |
| 内部员工 | 规范员工对公司AI工具的使用行为 | 可用的工具、禁止的行为、数据安全要求、审批流程 |
| 合作伙伴/客户(B2B) | 告知商业客户AI在其服务中的应用 | AI功能的可用性、数据保护、责任承诺 |
如果用户未指定,询问:"这项政策是面向谁的?(1) 面向用户/公众,(2) 内部员工,(3) 二者兼有。"
第2步:从清单和注册表中提取内容
必须纳入政策的具体内容来源于已存在的配置:
- 从
## AI系统清单中提取:- 已部署AI系统列表(按风险等级和功能分类)
- 哪些涉及个人信息处理
- 哪些面向公众,哪些是内部的
- 从
## 监管注册表中提取:- 法规要求的披露义务(例如《生成式人工智能服务管理办法》第15条要求标识AI生成内容
[法条原文]) - 法规要求的用户权利(投诉举报机制、拒绝自动化决策的权利等)
- 行业特定要求
- 法规要求的披露义务(例如《生成式人工智能服务管理办法》第15条要求标识AI生成内容
- 从
## 红线中提取:- 绝对禁止的AI用例类型
- 需要在政策中公开声明的底线原则
第3步:起草政策
面向用户/公众的AI使用政策模板
# AI使用说明
最后更新:[日期]
## 我们使用的AI技术
[公司名称]在以下服务和功能中使用了人工智能(AI)技术:
| AI功能 | 用途 | 涉及的个人信息 | 是否有自动化决策 |
|--------|------|---------------|-----------------|
| [功能] | [用途] | [数据类别] | 是/否 |
| [功能] | [用途] | [数据类别] | 是/否 |
## AI如何影响你
### 内容推荐
[如果使用算法推荐:说明推荐逻辑的基本原则,如何关闭个性化推荐]
### AI生成内容
[如果提供生成式AI服务:说明生成内容的标识方式,不构成专业建议的声明]
### 自动化决策
[如果使用自动化决策:说明决策的逻辑,用户获得人工介入和拒绝仅通过自动化决策的方式]
## 我们不会用AI做的事
[基于红线清单列出底线原则,例如:]
- 我们不使用AI进行社会信用评分
- 我们不基于种族、民族、性别等因素在交易条件上实行差别待遇
- 我们不会在未取得你同意的情况下,将你的个人信息用于AI模型训练
## 你的权利
[根据适用的法规(《个人信息保护法》《生成式人工智能服务管理办法》等),你享有以下权利:]
- [权利及行使方式]
- 如果你对我们的AI使用有任何问题或投诉,请通过[联系方式]联系我们。我们会在[时间]内回复。
## 我们如何管理AI风险
- 我们在部署新的AI功能前进行安全评估
- 我们对AI生成内容进行内容管理和人工审核
- [其他措施]
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 239 lines · 56 tokens per session scan A 50c35884dbcb
policy-starter is a skill published in the GitHub repository zhou210712/claude-for-legal-ZH (212 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 56 tokens to every session and 2,607 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 84% identical to smart-search, differing in 288 lines, and is treated as a copy.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…