Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add guoliang1114-boop/AriaAI --skill internal-audit-annual-plangit clone --depth 1 https://github.com/guoliang1114-boop/AriaAIWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/guoliang1114-boop/ariaai/internal-audit-annual-plan)<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/internal-audit-annual-plan"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/internal-audit-annual-plan/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/internal-audit-annual-plan"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/internal-audit-annual-plan.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00045 | $0.02427 |
| Opus 5 | $0.00023 | $0.01213 |
| Sonnet 5 | $0.00009 | $0.00485 |
| Haiku 4.5 | $0.00005 | $0.00243 |
Grade A, and why
internal-audit-annual-plan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 188 lines — stays where its author put it; the contents beside it link to each section on GitHub.
年度内部审计计划
When To Use
- 每年年初制定或修订年度内部审计计划
- 组织架构、业务环境或风险状况发生重大变化时
- 管理层或审计委员会要求更新审计计划时
- 合并、收购或新业务线启动时重新评估审计范围
Tools
- risk-scoring-matrix: 风险评分矩阵工具
- audit-universe-builder: 审计宇宙构建器
- resource-allocation-calculator: 资源分配计算器
- stakeholder-interview-template: 利益相关方访谈模板
Framework
基于 IIA International Standards for the Professional Practice of Internal Auditing:
Standard 2010 – Planning: Chief audit executive must establish a risk-based plan to determine the priorities of the internal audit activity, consistent with the organization's goals.
Standard 2010.A1: The internal audit activity's plan of engagements must be based on a documented risk assessment, undertaken at least annually.
Standard 2020 – Communication and Approval: The chief audit executive must communicate the internal audit activity's plans and resource requirements to senior management and the board for review and approval.
Standard 2030 – Resource Management: The chief audit executive must ensure that internal audit resources are sufficient and appropriate to fulfill the approved plan.
COSO 2013 Integration: 审计计划应覆盖COSO五要素(控制环境、风险评估、控制活动、信息与沟通、监督活动)及其17项原则。
Workflow
- 收集背景信息 — 审阅组织战略、业务计划、上年审计报告、监管要求
- 构建审计宇宙 — 识别所有可审计单元(业务流程、部门、系统、项目)
- 风险评估与评分 — 使用固有风险和控制风险二维矩阵对每个可审计单元评分
- 固有风险因素:财务影响、运营复杂性、监管环境、变革程度、历史问题
- 控制风险因素:控制成熟度、上次审计时间、管理层关注程度
- 优先级排序 — 综合风险评分排序,确定高/中/低优先级审计领域
- 资源分配 — 根据可用审计资源(人天)匹配高优先级审计项目
- 编制年度计划 — 汇总审计项目清单、时间表、资源需求
- 审批流程 — 提交审计委员会和高级管理层审批
- 沟通与发布 — 向相关部门负责人沟通计划安排
Output Format
# 年度内部审计计划
## 一、计划概述
- 计划年度:[YYYY]
- 编制日期:[YYYY-MM-DD]
- 审计负责人:[姓名]
- 审计委员会审批日期:[YYYY-MM-DD]
## 二、审计宇宙清单
| 序号 | 可审计单元 | 所属部门 | 业务类型 | 上次审计日期 |
|------|-----------|---------|---------|-------------|
| 1 | [单元名称] | [部门] | [类型] | [日期] |
## 三、风险评分矩阵
| 可审计单元 | 财务影响(1-5) | 运营复杂性(1-5) | 监管环境(1-5) | 变革程度(1-5) | 控制成熟度(1-5) | 综合风险评分 | 优先级 |
|-----------|--------------|----------------|--------------|--------------|----------------|-------------|--------|
| [单元] | [评分] | [评分] | [评分] | [评分] | [评分] | [加权总分] | [高/中/低] |
## 四、年度审计项目计划
| 序号 | 审计项目 | 审计类型 | 计划人天 | 计划期间 | 审计目标 | 项目负责人 |
|------|---------|---------|---------|---------|---------|-----------|
| 1 | [项目名] | [类型] | [天数] | [月份] | [目标] | [姓名] |
## 五、资源分配总表
- 总可用人天:[数量]
- 已分配人天:[数量]
- 预留应急人天:[数量]
- 资源利用率:[百分比]
## 六、专项审计/咨询项目
| 项目名称 | 触发原因 | 预计人天 | 时间安排 |
|---------|---------|---------|---------|
| [项目] | [原因] | [天数] | [安排] |
## 七、审批签署
- 审计负责人签署:________ 日期:________
- 审计委员会主席签署:________ 日期:________
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 188 lines · 45 tokens per session scan A 6b82a1193e5b
internal-audit-annual-plan is a skill published in the GitHub repository guoliang1114-boop/AriaAI (37 stars, last pushed today), licensed MIT. It adds 45 tokens to every session and 2,427 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
domain_aml
Guidance for monitoring cross-border payments for money laundering and sanctions risks. It explains terms such as suspicious transactions and watchlists, which can include sanctioned people or politically exposed persons.
domain_ecommerce
Background guidance for working on cross-border online shops, including product classification, service commitments, pricing, taxes, data transfers, and consumer protection.
vibe-legal-batch-redliner
Use when you need to batch redline multiple contracts against a negotiation playbook, apply tracked changes to Word documents programmatically, or run contract review workflows with AI assistance.
legal_contract_expert
A contract-writing and contract-review specialist for agreements, clauses, and other legal documents. It checks required terms, balanced duties, and common legal risks.
generate_fillable_contract_html
Chinese HTML templates for contracts, quotations, and authorization letters with blank fields for later completion or DOCX conversion.
patentradar
A patent-infringement and competitor-analysis skill for patents identified by publication numbers such as CN, US, EP, or JP numbers.