Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add guoliang1114-boop/AriaAI --skill internal-audit-executiongit clone --depth 1 https://github.com/guoliang1114-boop/AriaAIWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/guoliang1114-boop/ariaai/internal-audit-execution)<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/internal-audit-execution"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/internal-audit-execution/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/internal-audit-execution"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/internal-audit-execution.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00038 | $0.02178 |
| Opus 5 | $0.00019 | $0.01089 |
| Sonnet 5 | $0.00008 | $0.00436 |
| Haiku 4.5 | $0.00004 | $0.00218 |
Grade A, and why
internal-audit-execution scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 185 lines — stays where its author put it; the contents beside it link to each section on GitHub.
内部审计项目执行
When To Use
- 按年度计划启动具体审计项目时
- 执行专项审计或管理层要求的咨询项目时
- 需要编制审计程序和工作底稿时
- 实施审计抽样和实质性测试时
Tools
- audit-program-builder: 审计程序编制器
- sampling-calculator: 抽样计算器
- working-paper-template: 工作底稿模板
- walkthrough-trace-tool: 穿行测试追踪工具
- interview-questionnaire: 访谈问卷生成器
Framework
基于 IIA Performance Standards:
Standard 2200 – Engagement Planning: Internal auditors must develop and document a plan for each engagement, including the objectives, scope, timing, and resource allocations.
Standard 2201 – Engagement Planning Considerations: In planning the engagement, internal auditors must consider:
- The objectives of the activity being reviewed and the means by which the activity controls its performance
- The significant risks to the activity, its objectives, resources, and operations
- The adequacy and effectiveness of the activity's risk management and control processes
Standard 2210 – Engagement Objectives: Objectives must be established for each engagement.
Standard 2220 – Engagement Scope: The scope of the engagement must be sufficient to satisfy the objectives of the engagement.
Standard 2230 – Engagement Resource Allocation: Internal auditors must determine appropriate and sufficient resources to achieve engagement objectives.
Standard 2300 – Performing the Engagement: Internal auditors must identify, analyze, evaluate, and document sufficient information to achieve engagement objectives.
Standard 2310 – Identifying Information: Internal auditors must identify sufficient, reliable, relevant, and useful information to achieve engagement objectives.
Standard 2320 – Analysis and Evaluation: Internal auditors must base conclusions and engagement results on appropriate analyses and evaluations.
ISA 530 Sampling Reference: 审计抽样应遵循国际审计准则530号的统计和非统计抽样方法。
Workflow
- 项目启动 — 发送审计通知书,召开启动会议,确认联络人
- 初步调查 — 了解被审计单位的业务流程、内部控制、风险状况
- 编制审计程序 — 根据审计目标制定详细的审计程序和测试步骤
- 穿行测试 — 选取一笔交易从头到尾追踪,验证对流程的理解
- 控制测试 — 测试关键控制点的设计有效性和运行有效性
- 实质性测试 — 根据风险评估结果执行实质性程序
- 确定抽样方法(属性抽样/变量抽样/MUS)
- 确定样本量(基于置信水平、可容忍偏差率、预期偏差率)
- 执行测试并记录结果
- 分析与评价 — 汇总测试结果,分析异常事项
- 工作底稿编制 — 记录审计程序执行过程和结论
- 质量复核 — 项目负责人复核工作底稿的完整性和准确性
- 结果汇总 — 整理审计发现,准备与管理层沟通
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 185 lines · 38 tokens per session scan A 763cfa4ecc76
internal-audit-execution is a skill published in the GitHub repository guoliang1114-boop/AriaAI (37 stars, last pushed today), licensed MIT. It adds 38 tokens to every session and 2,178 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
domain_aml
Guidance for monitoring cross-border payments for money laundering and sanctions risks. It explains terms such as suspicious transactions and watchlists, which can include sanctioned people or politically exposed persons.
domain_ecommerce
Background guidance for working on cross-border online shops, including product classification, service commitments, pricing, taxes, data transfers, and consumer protection.
vibe-legal-batch-redliner
Use when you need to batch redline multiple contracts against a negotiation playbook, apply tracked changes to Word documents programmatically, or run contract review workflows with AI assistance.
legal_contract_expert
A contract-writing and contract-review specialist for agreements, clauses, and other legal documents. It checks required terms, balanced duties, and common legal risks.
generate_fillable_contract_html
Chinese HTML templates for contracts, quotations, and authorization letters with blank fields for later completion or DOCX conversion.
patentradar
A patent-infringement and competitor-analysis skill for patents identified by publication numbers such as CN, US, EP, or JP numbers.