Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add kylin985ti/china-accounting-skills --skill risk-assessmentgit clone --depth 1 https://github.com/kylin985ti/china-accounting-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/kylin985ti/china-accounting-skills/risk-assessment)<a href="https://agentmods.dev/skills/kylin985ti/china-accounting-skills/risk-assessment"><img src="https://agentmods.dev/badge/skills/kylin985ti/china-accounting-skills/risk-assessment/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/kylin985ti/china-accounting-skills/risk-assessment"><img src="https://agentmods.dev/badge/skills/kylin985ti/china-accounting-skills/risk-assessment.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00061 | $0.01741 |
| Opus 5 | $0.00030 | $0.00870 |
| Sonnet 5 | $0.00012 | $0.00348 |
| Haiku 4.5 | $0.00006 | $0.00174 |
Grade A, and why
risk-assessment scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 155 lines — stays where its author put it; the contents beside it link to each section on GitHub.
风险评估
概述
依据 CAS 1211 — 重大错报风险的识别和评估(2022修订版),系统性地了解被审计单位并识别风险。风险评估是审计的起点,决定了后续实质性程序的深度和范围。
CAS 1211 要求了解的六个方面
| 方面 | 内容 | 小企业审计要点 |
|---|---|---|
| 1. 行业状况、法律和监管环境 | 行业竞争、政策变化、监管要求 | 小型微利企业门槛(300万/300人/5000万)是否可能突破? |
| 2. 被审计单位的性质 | 所有权结构、治理结构、经营活动 | 一人公司?夫妻店?还是有多股东? |
| 3. 会计政策的选择和运用 | 适用准则、收入确认、折旧方法 | 小企业准则还是企业准则?有无随意变更? |
| 4. 目标、战略和相关经营风险 | 业务目标、竞争压力、资金需求 | 是否为融资/贷款而美化报表? |
| 5. 财务业绩的衡量和评价 | KPI、预算、考核指标 | 老板是否以利润为唯一考核?有无业绩压力? |
| 6. 内部控制 | 控制环境、风险评估、信息系统、控制活动、监督 | 小企业内控通常薄弱→跳过控制测试 |
风险评估程序
CAS 1211 要求至少执行以下程序:
| 程序 | 怎么做 | 小企业做法 |
|---|---|---|
| 询问 (Inquiry) | 询问管理层和关键人员 | 核心手段——小企业人少,直接问老板和财务 |
| 分析程序 (Analytical) | 比较财务数据关系 | 毛利率波动、费用率变化、应收账款周转 |
| 观察 (Observation) | 观察经营活动 | 实地看看——存货堆放、人员工作状态 |
| 检查 (Inspection) | 检查文件记录 | 合同、银行流水、发票 |
风险评估工作底稿
A. 了解被审计单位及其环境
📋 了解被审计单位及其环境程序表
索引号:AB-1
════════════════════════════════════
1. 行业状况
□ 了解所处行业(制造业/贸易/服务/互联网/其他____)
□ 行业是否处于成长期/成熟期/衰退期
□ 主要竞争对手是谁
□ 是否受到政策重大影响(如教培双减、房地产调控)
2. 法律和监管环境
□ 适用的会计准则(小企业/企业准则)
□ 增值税纳税人类型(小规模/一般纳税人)
□ 是否享受税收优惠(小型微利/高新/软件等)
□ 是否有未决诉讼或行政处罚
3. 所有权和治理结构
□ 实际控制人是谁
□ 是否存在代持/家族关系
□ 股东人数和关系
□ 有无关联方交易
4. 经营活动
□ 主要收入来源(产品销售/服务费/其他)
□ 客户集中度(前5大客户占比____%)
□ 供应商集中度(前5大供应商占比____%)
审计结论:
了解到的重大事项:________________
对审计的影响:________________
B. 了解内部控制
📋 了解内部控制程序表
索引号:AB-2
════════════════════════════════════
1. 控制环境
□ 管理层是否重视财务规范? □ 是 □ 一般 □ 否
□ 有无书面财务制度? □ 有 □ 无
□ 财务人员专业水平:□ 专业 □ 会记账但不懂准则 □ 兼职/外包
2. 职责分离(小企业最常见的薄弱点)
□ 出纳和记账是否同一人? □ 是 ⚠ □ 否
□ 审批和付款是否同一人? □ 是 ⚠ □ 否
□ 是否有独立复核? □ 有 □ 无
3. 信息系统
□ 使用什么记账方式?Excel / 金蝶 / 用友 / 手工
□ 是否有权限控制? □ 有 □ 无
审计结论:
内控缺陷:________________
是否拟信赖控制:□ 是 → 需执行控制测试
□ 否 → 直接实施实质性程序(小企业通常选此项)
C. 风险评估汇总
📋 风险评估汇总表
索引号:AB-3
════════════════════════════════════
一、识别出的重大错报风险
财务报表层面风险:
□ 管理层凌驾于内部控制之上 ← 假定存在(CAS 1141 强制要求)
□ 持续经营存在重大不确定性
□ 为获取融资而粉饰报表
□ 税务稽查风险(两套账)
认定层面风险:
科目 风险描述 风险等级 应对措施
──────────────────────────────────────────────────────────
收入 可能提前确认收入以达标 高 ⚠ 收入截止测试
应收 部分客户已无力偿还 高 ⚠ 账龄分析+坏账测试
存货 年末未盘点 中 监盘+计价测试
二、特别风险(CAS 1211要求单独识别)
☑ 收入确认 — 假定存在舞弊导致的特别风险(CAS 1141)
→ 应对:收入截止测试+分析程序+大额合同检查
□ 关联方交易 — 定价不公允
□ 重大会计估计 — 存在偏向
□ 异常重大交易 — 商业理由不充分
──────────────────────────────────────
风险评估结论:
总体审计风险:□ 低 □ 中 □ 高
是否需要调整审计计划:□ 是 □ 否
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 155 lines · 61 tokens per session scan A a95e7fa61a8d
risk-assessment is a skill published in the GitHub repository kylin985ti/china-accounting-skills (56 stars, last pushed 18d ago), licensed MIT. It adds 61 tokens to every session and 1,741 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
expense-review-policy
Review invoices and contracts against accounts-payable policy before human approval.
kyc-doc-parse
Parse an investor or client onboarding packet into structured KYC fields — identity, ownership, control, source of funds, and document inventory. Use as the first step of KYC screening; output feeds the rules engine.
audit-support
Support SOX 404 compliance with control testing methodology, sample selection, and documentation standards. Use when generating testing workpapers, selecting audit samples, classifying control deficiencies, or preparing for internal or external audits.
fiscaliste
Fiscaliste IA pour la fiscalité personnelle des particuliers français : optimisation et déclaration de l'impôt sur le revenu, IFI, revenus du capital, revenus fonciers, equity salarial, crypto-actifs et PER. Couvre le calcul de l'IR (barème, quotient familial, décote, PAS, CEHR, revenus exceptionnels), la déclaration…
regulatory-analysis
Analyzes documents and processes against FINRA, SEC, Federal Reserve, and CFPB regulatory frameworks. Identifies compliance gaps, classifies findings by severity, and recommends remediation. Use when performing compliance audits, regulatory reviews, gap analyses, or verifying policy adherence to financial regulations.
subcontractor-payment-tracker
Track subcontractor payments, lien waivers, and compliance. Manage payment schedules and documentation.