Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add guoliang1114-boop/AriaAI --skill audit-substantive-proceduresgit clone --depth 1 https://github.com/guoliang1114-boop/AriaAIWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/guoliang1114-boop/ariaai/audit-substantive-procedures)<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/audit-substantive-procedures"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/audit-substantive-procedures/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/audit-substantive-procedures"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/audit-substantive-procedures.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00046 | $0.02451 |
| Opus 5 | $0.00023 | $0.01226 |
| Sonnet 5 | $0.00009 | $0.00490 |
| Haiku 4.5 | $0.00005 | $0.00245 |
Grade A, and why
audit-substantive-procedures scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 195 lines — stays where its author put it; the contents beside it link to each section on GitHub.
实质性审计程序设计与执行
When To Use
- 需要针对已评估的认定层次重大错报风险设计审计应对程序
- 执行实质性程序以获取充分、适当的审计证据
- 对账户余额、交易类别和披露实施细节测试
- 执行实质性分析程序以验证财务数据的合理性
- 设计函证程序并评估回函结果
Tools
search— 搜索被审计单位财务数据、账户明细、历史审计工作底稿read— 读取风险评估结果、控制测试结论、重要性水平设定write— 生成实质性程序工作底稿edit— 修改程序设计、更新测试结果
Framework
NTE框架(Nature, Timing, Extent)
基于ISA 330第6-12条,审计师应从性质、时间安排和范围三个维度设计实质性程序:
-
性质(Nature) — 选择程序类型
- 细节测试:针对重大交易、余额和披露的测试
- 实质性分析程序:当预期关系稳定且可预测时使用
- 函证:针对应收账款、银行存款、法律事项等第三方确认
- 重新计算:验证会计估计和计算的准确性
-
时间安排(Timing) — 确定执行时点
- 期中测试 + 期后覆盖:对期中余额执行程序,并覆盖剩余期间
- 期末测试:针对重大风险或期中测试不可行的情况
- 期后事项审查:关注资产负债表日后的事项
-
范围(Extent) — 确定样本量和覆盖范围
- 考虑评估的重大错报风险水平
- 考虑已获取的其他审计证据的说服力
- 考虑审计抽样方法的适当性
细节测试实施步骤(ISA 330第18-21条)
- 识别需要测试的认定(存在、完整性、准确性、截止、分类、计价)
- 选取测试项目(全部测试/选取特定项目/审计抽样)
- 设计审计程序并记录预期结果
- 执行程序并记录实际结果
- 评估差异是否构成错报
实质性分析程序(ISA 520)
- 确定预期值的精确度要求
- 建立数据间预期关系(趋势分析、比率分析、合理性测试)
- 评估预期值的可靠性
- 确定可接受差异额
- 调查并核实不可接受的差异
函证程序(ISA 505)
- 确定函证范围和对象
- 设计询证函格式(积极式/消极式)
- 控制函证的发送和收回
- 评估回函结果和替代程序
审计抽样(ISA 530)
- 确定抽样总体和抽样单元
- 选择抽样方法(统计抽样/非统计抽样)
- 确定样本量(考虑可容忍错报、预计总体错报、置信水平)
- 评价样本结果并推断总体
Workflow
- 从风险评估程序获取已识别的重大错报风险
- 运用NTE框架确定实质性程序的性质、时间安排和范围
- 针对每个重要账户和认定设计具体程序
- 执行细节测试、分析程序和函证程序
- 记录测试结果,识别和评价错报
- 汇总发现的错报并与管理层沟通
- 评估获取的审计证据是否充分、适当
Output Format
# 实质性程序工作底稿 — [账户名称]
## 一、基本信息
| 项目 | 内容 |
|------|------|
| 被审计单位 | [公司名称] |
| 审计期间 | [期间] |
| 账户/认定 | [账户名称] / [相关认定] |
| 执行人/日期 | [姓名] / [日期] |
| 复核人/日期 | [姓名] / [日期] |
## 二、风险评估结果
- 已识别的重大错报风险:[描述]
- 风险水平:[高/中]
- 相关认定:[存在/完整性/准确性/截止/计价]
## 三、NTE设计决策
| 维度 | 决策 | 理由 |
|------|------|------|
| 性质 | [细节测试/分析程序/函证] | [理由] |
| 时间安排 | [期中+期后/期末] | [理由] |
| 范围 | [样本量/覆盖比例] | [理由] |
## 四、审计程序及结果
| 序号 | 审计程序 | 预期结果 | 实际结果 | 差异 | 结论 |
|------|----------|----------|----------|------|------|
| 1 | [程序描述] | [预期] | [实际] | [差异额] | [结论] |
## 五、函证程序(如适用)
| 函证对象 | 金额 | 函证方式 | 回函情况 | 差异及原因 |
|----------|------|----------|----------|------------|
| [单位] | [金额] | [积极/消极] | [相符/不符/未回] | [说明] |
## 六、抽样结果(如适用)
| 项目 | 数值 |
|------|------|
| 总体规模 | [数量] |
| 样本量 | [数量] |
| 样本错报额 | [金额] |
| 推断总体错报 | [金额] |
| 可容忍错报 | [金额] |
## 七、结论
- [ ] 获取了充分、适当的审计证据
- 识别的错报汇总:[金额]
- 是否需要调整:[是/否]
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 195 lines · 46 tokens per session scan A 48d8d89c8563
audit-substantive-procedures is a skill published in the GitHub repository guoliang1114-boop/AriaAI (37 stars, last pushed 4d ago), licensed MIT. It adds 46 tokens to every session and 2,451 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
billing-stripe
Work with Stripe billing — subscriptions, plans/prices, the Customer Portal, credits, usage metering, invoices, and webhook events. Use when changing plans, handling a new Stripe webhook, debugging a payment/subscription flow, or touching credit balances and usage.
xlsx
Create polished Excel workbooks for budgets, trackers, tables, and explicit .xlsx spreadsheet requests.
globalpercent
GlobalPercent — build a global-macro-probability panel for an investment research system. Merges public probability data from prediction markets (Polymarket + Kalshi), classifies every market into macro modules (monetary policy / macro economy / AI / etc.), and shows the whole market's expected-probability state at a…
quantoracle
63 deterministic quantitative finance calculators + 10 composite workflows via MCP. Options pricing, Greeks, exotic derivatives, risk metrics, portfolio optimization, Monte Carlo, statistics, crypto/DeFi, FX/macro, TVM, strategy backtesting, rebalance planning, options strategy selection, hedging. 1,000 free…
domain_aml
Guidance for monitoring cross-border payments for money laundering and sanctions risks. It explains terms such as suspicious transactions and watchlists, which can include sanctioned people or politically exposed persons.
business
Business analysis prompts — financial impact, market analysis, and performance analysis for a given topic. Use when an operator-facing business module needs a structured first-pass analysis.