Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/hoavdc/codexkit/codexkit-audit-readiness-checkernpx skills add hoavdc/CodexKit --skill codexkit-audit-readiness-checkergit clone --depth 1 https://github.com/hoavdc/CodexKitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hoavdc/codexkit/codexkit-audit-readiness-checker)<a href="https://agentmods.dev/skills/hoavdc/codexkit/codexkit-audit-readiness-checker"><img src="https://agentmods.dev/badge/skills/hoavdc/codexkit/codexkit-audit-readiness-checker.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00075 | $0.01273 |
| Opus 5 | $0.00037 | $0.00636 |
| Sonnet 5 | $0.00015 | $0.00255 |
| Haiku 4.5 | $0.00007 | $0.00127 |
Grade A, and why
codexkit-audit-readiness-checker scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 146 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Audit Readiness Checker
When to Use
- 60–90 days before a scheduled external audit
- When preparing for SOX compliance for the first time
- After prior audit findings need remediation verification
- When internal audit wants a pre-flight check
Procedure
Step 1 — Map Assertions to Accounts
For each material account balance, map the relevant audit assertions:
| Assertion | What It Tests |
|---|---|
| Existence/Occurrence | Did the transaction/asset actually happen/exist? |
| Completeness | Are all transactions recorded? |
| Valuation/Accuracy | Are amounts recorded correctly? |
| Rights & Obligations | Does the entity own/owe the amounts? |
| Presentation & Disclosure | Is it properly classified and disclosed? |
| Cut-off | Are transactions in the correct period? |
Step 2 — Check Evidence Completeness
For each assertion per account, verify supporting evidence:
- Source documents (invoices, contracts, bank statements)
- Reconciliations (bank, intercompany, sub-ledger to GL)
- Approvals and authorization records
- Third-party confirmations
- Management representations and estimates documentation
Step 3 — Score Readiness
| Score | Criteria |
|---|---|
| 🟢 Green | All evidence available, reconciled, no open items |
| 🟡 Amber | Evidence partially available, minor gaps, reconciliation in progress |
| 🔴 Red | Missing evidence, unreconciled, prior audit finding unresolved |
Step 4 — Generate Remediation Plan
For each 🟡 and 🔴 item:
- Describe the gap
- Assign an owner
- Set a deadline (must be before audit fieldwork)
- Define the evidence deliverable
Inputs
| Input | Required | Format |
|---|---|---|
| Trial balance | Yes | Account list with balances |
| Prior audit findings | Recommended | Management letter or audit report |
| Audit timeline | Yes | Fieldwork start date |
| Supporting schedules | Recommended | Reconciliations, roll-forwards |
Output
## Audit Readiness Scorecard — [Entity] — [Audit Period]
### Overall Score: 🟡 AMBER (72% ready — 12 weeks to fieldwork)
### By Account Area
| Account | Assertion | Evidence | Status | Gap | Owner | Deadline |
|---------|-----------|----------|--------|-----|-------|----------|
| Cash | Existence | Bank confirmations | 🟢 | — | — | — |
| Cash | Completeness | Bank reconciliation | 🟢 | — | — | — |
| AR | Existence | Confirmations | 🟡 | 3 confirmations pending | AR Lead | Week 8 |
| AR | Valuation | Aging + allowance | 🔴 | Allowance model not updated | Controller | Week 6 |
| Revenue | Cut-off | Shipping docs | 🟢 | — | — | — |
| PP&E | Existence | Physical count | 🔴 | Count not scheduled | Ops Mgr | Week 4 |
### Prior Findings Status
| Finding | Year | Status | Remediation |
|---------|------|--------|-------------|
| Inventory count procedures | 2024 | 🟡 In progress | New SOP drafted, testing pending |
| AR confirmation process | 2024 | 🟢 Resolved | Automated via NetSuite |
### Remediation Timeline
| Week | Action | Owner |
|------|--------|-------|
| Week 4 | Schedule PP&E physical count | Ops Manager |
| Week 6 | Update AR allowance model | Controller |
| Week 8 | Complete AR confirmations | AR Lead |
| Week 10 | Final reconciliation review | CFO |
| Week 12 | Audit fieldwork begins | — |
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 146 lines · 75 tokens per session scan A e8212175e60c
codexkit-audit-readiness-checker is a skill published in the GitHub repository hoavdc/CodexKit (21 stars, last pushed 3mo ago), licensed MIT. It adds 75 tokens to every session and 1,273 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
agent-agentic-payments
Agent skill for agentic-payments - invoke with $agent-agentic-payments.
agent-payments
Agent skill for payments - invoke with $agent-payments.
stock-analyzer
A comprehensive stock deep analysis tool that combines real-time quotes, fundamental metrics, technical indicators, and growth analysis into a single professional report. Supports A-share, US stocks, HK stocks. Generates detailed investment recommendations with risk assessment and actionable trading strategies.
stock-explorer
A Yahoo Finance (yfinance) powered financial analysis tool. Get real-time quotes, generate technical indicator reports (RSI/MACD/Bollinger/VWAP/ATR), summarize fundamentals, and run a one-shot report that outputs a text summary.
gmail-trigger
Beta. Act on new Gmail as it arrives: get pinged only for urgent mail, digest newsletters, forward invoices — any standing instruction, across one or several accounts.
bionic-safety-net
Unified survival infrastructure: health, finance, legal safety, circuit breakers, and structural protection against all ruin classes. The last line of defense.