Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add guoliang1114-boop/AriaAI --skill group-audit-strategygit clone --depth 1 https://github.com/guoliang1114-boop/AriaAIWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/guoliang1114-boop/ariaai/group-audit-strategy)<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/group-audit-strategy"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/group-audit-strategy/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/group-audit-strategy"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/group-audit-strategy.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00042 | $0.02485 |
| Opus 5 | $0.00021 | $0.01242 |
| Sonnet 5 | $0.00008 | $0.00497 |
| Haiku 4.5 | $0.00004 | $0.00248 |
Grade A, and why
group-audit-strategy scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 205 lines — stays where its author put it; the contents beside it link to each section on GitHub.
集团审计策略制定
When To Use
- 被审计单位包含多个子公司、分支机构或业务板块
- 需要识别和评估集团层面的重大错报风险
- 需要向组成部分审计师分配审计工作
- 需要制定集团层面的重要性和组成部分重要性
- 需要协调多个审计团队的工作并评估合并调整
Tools
search— 搜索集团组织架构、组成部分财务数据、历史审计文件read— 读取风险评估、集团财务报表、组成部分审计报告write— 生成集团审计策略文件edit— 更新组成部分分配、调整重要性水平
Framework
ISA 600核心框架
第一步:了解集团及其环境(ISA 600第11-15条)
- 了解集团结构(股权关系、管理层级、业务板块)
- 识别集团层面的控制环境
- 评估集团财务报告过程和合并流程
- 了解集团管理层对组成部分的监督机制
- 识别集团层面的重大错报风险
第二步:识别组成部分(ISA 600第16-18条)
- 重要组成部分:在集团中具有财务重要性的组成部分
- 判定标准:单个组成部分占集团资产、收入或利润的比例(通常>15%)
- 或因特定性质或情况导致存在重大错报风险
- 非重要组成部分:不具有财务重要性,但需在集团层面实施分析程序
- 特别关注组成部分:因特定风险因素(如复杂交易、管理层凌驾)而需单独审计
第三步:分配重要性水平(ISA 600第19-23条)
- 设定集团层面整体重要性(PM)
- 设定集团层面实际执行的重要性(TE)
- 为每个重要组成部分分配组成部分重要性
- 组成部分重要性应低于集团整体重要性
- 考虑未分配至组成部分的保留金额
第四步:确定组成部分审计工作(ISA 600第24-32条)
- 对重要组成部分:使用组成部分重要性执行审计工作
- 对非重要组成部分:在集团层面实施分析程序
- 对具有特别风险的组成部分:执行针对该风险的审计程序
- 确定集团项目组直接执行或指导组成部分审计师执行的工作
第五步:协调组成部分审计师(ISA 600第33-40条)
- 向组成部分审计师发出集团审计指令
- 明确组成部分审计师需执行的工作范围
- 明确报告时间安排和沟通要求
- 评估组成部分审计师的专业胜任能力
- 参与组成部分审计中的重大判断事项
第六步:评价合并调整和组成部分审计结论(ISA 600第41-48条)
- 评估合并过程中的调整分录
- 评估组成部分审计师报告的结果
- 考虑识别的错报对集团财务报表的影响
- 评估集团层面的审计证据是否充分适当
Workflow
- 获取集团组织架构和财务信息
- 了解集团及其环境,识别重大错报风险
- 识别重要组成部分和非重要组成部分
- 设定集团层面重要性和组成部分重要性
- 确定各组成部分的审计工作范围和方法
- 制定集团审计指令并发送至组成部分审计师
- 协调审计时间表和沟通安排
- 监督组成部分审计工作的执行
- 评价组成部分审计结果和合并调整
- 形成集团审计结论
Output Format
# 集团审计策略 — [集团名称]
## 一、集团概况
| 项目 | 内容 |
|------|------|
| 集团名称 | [名称] |
| 审计期间 | [期间] |
| 组成部分数量 | [数量] |
| 业务性质 | [行业/业务描述] |
| 集团审计项目合伙人 | [姓名] |
| 集团审计项目经理 | [姓名] |
## 二、集团组织架构
[集团架构图或结构表]
| 组成部分名称 | 注册地 | 业务性质 | 持股比例 | 资产占比 | 收入占比 | 利润占比 |
|-------------|--------|----------|----------|----------|----------|----------|
| [公司A] | [地区] | [业务] | [%] | [%] | [%] | [%] |
| [公司B] | [地区] | [业务] | [%] | [%] | [%] | [%] |
## 三、组成部分分类
| 组成部分 | 分类 | 分类理由 | 审计策略 |
|----------|------|----------|----------|
| [公司A] | 重要组成部分 | 资产占比>15% | 使用组成部分重要性执行审计 |
| [公司B] | 非重要组成部分 | 占比均<15% | 集团层面分析程序 |
| [公司C] | 特别关注组成部分 | 存在重大关联交易风险 | 执行针对性审计程序 |
## 四、重要性水平分配
| 项目 | 金额 | 说明 |
|------|------|------|
| 集团整体重要性(PM) | [金额] | [基准 × 比例] |
| 集团实际执行的重要性(TE) | [金额] | [PM × 75%] |
| 组成部分A重要性 | [金额] | [说明分配理由] |
| 组成部分B重要性 | [金额] | [说明分配理由] |
| 未分配保留金额 | [金额] | 集团层面保留 |
## 五、组成部分审计工作分配
### 重要组成部分A
| 项目 | 内容 |
|------|------|
| 审计策略 | 使用组成部分重要性执行全面审计 |
| 组成部分审计师 | [事务所名称/集团项目组] |
| 工作范围 | [具体说明] |
| 报告时间 | [日期] |
| 需关注的风险 | [风险描述] |
### 非重要组成部分B
| 项目 | 内容 |
|------|------|
| 审计策略 | 集团层面分析程序 |
| 执行人 | 集团项目组 |
| 程序内容 | [具体分析程序] |
## 六、集团审计指令要点
1. [需执行的审计工作范围和要求]
2. [报告格式和时间要求]
3. [重大事项的沟通机制]
4. [组成部分审计师需关注的特定风险]
## 七、合并程序关注事项
1. 合并范围的完整性和准确性
2. 内部交易和余额的抵消
3. 少数股东权益的计算
4. 外币折算的准确性
5. 合并调整分录的合理性
## 八、时间安排
| 事项 | 计划时间 | 责任人 |
|------|----------|--------|
| 组成部分审计启动 | [日期] | [姓名] |
| 组成部分审计报告截止 | [日期] | [姓名] |
| 合并及集团层面审计 | [日期] | [姓名] |
| 集团审计报告出具 | [日期] | [姓名] |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 205 lines · 42 tokens per session scan A 411beb382c62
group-audit-strategy is a skill published in the GitHub repository guoliang1114-boop/AriaAI (37 stars, last pushed today), licensed MIT. It adds 42 tokens to every session and 2,485 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
domain_aml
Guidance for monitoring cross-border payments for money laundering and sanctions risks. It explains terms such as suspicious transactions and watchlists, which can include sanctioned people or politically exposed persons.
domain_ecommerce
Background guidance for working on cross-border online shops, including product classification, service commitments, pricing, taxes, data transfers, and consumer protection.
vibe-legal-batch-redliner
Use when you need to batch redline multiple contracts against a negotiation playbook, apply tracked changes to Word documents programmatically, or run contract review workflows with AI assistance.
legal_contract_expert
A contract-writing and contract-review specialist for agreements, clauses, and other legal documents. It checks required terms, balanced duties, and common legal risks.
generate_fillable_contract_html
Chinese HTML templates for contracts, quotations, and authorization letters with blank fields for later completion or DOCX conversion.
patentradar
A patent-infringement and competitor-analysis skill for patents identified by publication numbers such as CN, US, EP, or JP numbers.