Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add guoliang1114-boop/AriaAI --skill audit-risk-assessmentgit clone --depth 1 https://github.com/guoliang1114-boop/AriaAIWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/guoliang1114-boop/ariaai/audit-risk-assessment)<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/audit-risk-assessment"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/audit-risk-assessment/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/audit-risk-assessment"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/audit-risk-assessment.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00088 | $0.02873 |
| Opus 5 | $0.00044 | $0.01437 |
| Sonnet 5 | $0.00018 | $0.00575 |
| Haiku 4.5 | $0.00009 | $0.00287 |
Grade A, and why
audit-risk-assessment scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 240 lines — stays where its author put it; the contents beside it link to each section on GitHub.
审计计划与风险评估
基于国际审计准则 ISA 315 (Revised 2019) 框架,执行审计计划阶段的系统性风险评估。
When To Use
- 用户需要为客户制定审计计划
- 用户需要识别和评估重大错报风险(RMM)
- 用户需要了解被审计单位的内部控制
- 用户需要确定重要性水平
- 用户需要设计审计策略和审计程序的总体方向
Tools
| Tool | Purpose |
|---|---|
update_project_markdown_document |
保存风险评估文档到项目空间 |
write_project_office_document |
生成风险评估报告(Word/PDF) |
Framework: ISA 315 (Revised 2019)
核心概念
- 固有风险 (Inherent Risk, IR):在考虑相关控制之前,某项认定存在重大错报的可能性。ISA 315 要求在认定层面评估固有风险。
- 控制风险 (Control Risk, CR):某项重大错报未被实体的内部控制及时防止或发现并纠正的可能性。
- 检查风险 (Detection Risk, DR):审计师的程序未能发现存在的重大错报的风险。审计师的责任是控制检查风险。
- 重大错报风险 (Risk of Material Misstatement, RMM):固有风险与控制风险的组合。RMM = IR × CR。
- 重大账户 (Significant Accounts):存在合理可能性包含重大错报的账户。
- 认定 (Assertions):存在/发生、完整性、计价/分摊、权利和义务、列报和披露。
五步风险评估流程
Step 1:了解被审计单位及其环境
| 维度 | 了解内容 |
|---|---|
| 行业因素 | 行业竞争格局、监管要求、技术变革、市场趋势 |
| 所有权与治理 | 股权结构、董事会构成、管理层激励机制 |
| 经营模式 | 主要业务流程、收入来源、成本结构、关键资产 |
| 会计政策 | 重大会计估计、会计政策变更、复杂交易处理 |
| 财务业绩 | 收入增长率、毛利率趋势、现金流与利润匹配度 |
Step 2:了解内部控制(COSO 五要素)
| 要素 | 关键问题 |
|---|---|
| 控制环境 | 管理层诚信度、治理监督、权责分配、员工胜任能力 |
| 风险评估过程 | 管理层如何识别和应对经营风险 |
| 信息系统与沟通 | 财务报告相关的信息系统、内部控制沟通机制 |
| 控制活动 | 审批授权、核对复核、资产保护、职责分离 |
| 对控制的监督 | 持续监控、独立评估、缺陷报告机制 |
Step 3:识别重大账户、披露和相关认定
对每个账户评估以下风险因素:
- 账户规模和构成
- 因错误或舞弊导致错报的敏感性
- 交易量、复杂性和同质性
- 账户性质
- 会计和报告复杂性
- 损失风险
- 重大或有负债的可能性
- 关联方交易的存在
- 与前期的变化
Step 4:识别可能的错报来源(WCGW 分析)
对每个重大账户/认定,回答:
- What Could Go Wrong? 在交易的发起、授权、处理、记录环节中,哪些环节可能出现错报?
- 管理层已实施了哪些控制?
- 需要执行哪些穿行测试?
Step 5:评估重大错报风险
- 在认定层面评估每个重大账户的 RMM
- 确定哪些风险是显著风险(需要特别审计关注)
- 识别因舞弊导致的重大错报风险(ISA 240 联动)
- 确定显著风险是否需要测试控制
Workflow
1. 收集 → 获取客户行业、经营、财务、内控基本信息
2. 了解 → 按 Step 1-2 系统了解被审计单位和内控
3. 识别 → 按 Step 3-4 识别重大账户和 WCGW
4. 评估 → 按 Step 5 在认定层面评估 RMM
5. 重要性 → 计算整体重要性和实际执行的重要性
6. 策略 → 基于风险评估设计审计策略
7. 输出 → 生成结构化风险评估文档
Output Format
# 审计计划与风险评估报告
## 一、被审计单位概况
| 项目 | 内容 |
|------|------|
| 客户名称 | [名称] |
| 行业 | [行业] |
| 审计期间 | [期间] |
| 主要业务 | [描述] |
## 二、重要性水平
| 项目 | 金额 | 计算基础 | 比例 |
|------|------|---------|------|
| 整体重要性 | [金额] | [基准] | [比例] |
| 实际执行的重要性 | [金额] | [整体重要性] | 50%-75% |
| 明显微小错报临界值 | [金额] | — | — |
## 三、重大账户与认定识别
| 科目 | 金额 | 占比 | 相关认定 | 是否重大 |
|------|------|------|---------|---------|
| 收入 | ... | ... | 发生/完整性/截止 | ✅ |
| 应收账款 | ... | ... | 存在/计价 | ✅ |
| 存货 | ... | ... | 存在/计价/完整性 | ✅ |
| ... | ... | ... | ... | ... |
## 四、内部控制了解与评估
### 4.1 控制环境评价
| 维度 | 评价 | 风险等级 |
|------|------|---------|
| 管理层诚信 | [描述] | 🟢/🟡/🔴 |
| 治理监督 | [描述] | 🟢/🟡/🔴 |
| 权责分配 | [描述] | 🟢/🟡/🔴 |
| 员工胜任能力 | [描述] | 🟢/🟡/🔴 |
### 4.2 关键业务流程控制
| 流程 | 关键控制点 | 设计评价 | 是否需测试运行有效性 |
|------|-----------|---------|-------------------|
| 销售到收款 | [控制点] | 有效/缺陷 | 是/否 |
| 采购到付款 | [控制点] | 有效/缺陷 | 是/否 |
| ... | ... | ... | ... |
## 五、WCGW 分析与风险评估矩阵
| 科目 | 认定 | WCGW(可能的错报) | 固有风险 | 控制风险 | RMM | 是否显著风险 |
|------|------|-------------------|---------|---------|-----|------------|
| 收入 | 发生 | 虚构销售交易 | 高 | 中 | 高 | ✅ |
| 收入 | 截止 | 收入确认时点错误 | 中 | 中 | 中 | ❌ |
| 应收账款 | 计价 | 坏账准备计提不足 | 高 | 中 | 高 | ✅ |
| 存货 | 存在 | 虚构存货或数量高估 | 中 | 低 | 低 | ❌ |
| ... | ... | ... | ... | ... | ... | ... |
## 六、舞弊风险评估
| 舞弊风险 | 驱动因素 | 影响科目 | 应对措施 |
|---------|---------|---------|---------|
| 收入虚增 | 业绩压力/对赌 | 收入/应收账款 | [措施] |
| 费用资本化 | 利润目标 | 固定资产/开发支出 | [措施] |
| ... | ... | ... | ... |
## 七、审计策略
| 风险领域 | 审计策略 | 审计程序类型 | 时间安排 |
|---------|---------|------------|---------|
| 收入确认 | 增加实质性程序 | 细节测试+分析性复核 | 期末+期后 |
| 关联方交易 | 扩大测试范围 | 函证+细节测试 | 期末 |
| ... | ... | ... | ... |
## 八、未解决事项
| 事项 | 影响 | 待补充资料 | 责任人 |
|------|------|-----------|--------|
| ... | ... | ... | ... |
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 240 lines · 88 tokens per session scan A 54cd14665432
audit-risk-assessment is a skill published in the GitHub repository guoliang1114-boop/AriaAI (37 stars, last pushed today), licensed MIT. It adds 88 tokens to every session and 2,873 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
domain_aml
Guidance for monitoring cross-border payments for money laundering and sanctions risks. It explains terms such as suspicious transactions and watchlists, which can include sanctioned people or politically exposed persons.
fin-audit-support
Support SOX 404 compliance with control testing methodology, sample selection, and documentation standards. Use when generating testing workpapers, selecting audit samples, classifying control deficiencies, or preparing for internal or external audits.
fin-sox-testing
Generate SOX sample selections, testing workpapers, and control assessments. Use when planning quarterly or annual SOX 404 testing, pulling a sample for a control (revenue, P2P, ITGC, close), building a testing workpaper template, or evaluating and classifying a control deficiency.
fin-journal-entry
Prepare journal entries with proper debits, credits, and supporting detail. Use when booking month-end accruals (AP, payroll, prepaid), recording depreciation or amortization, posting revenue recognition or deferred revenue adjustments, or documenting an entry for audit review.
regulatory_filing
Parse and retrieve SEC/FINRA filings for an entity.
expense-review-policy
Review invoices and contracts against accounts-payable policy before human approval.