Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add vivy-yi/finance-skills --skill audit-support-mastergit clone --depth 1 https://github.com/vivy-yi/finance-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/vivy-yi/finance-skills/audit-support-master)<a href="https://agentmods.dev/skills/vivy-yi/finance-skills/audit-support-master"><img src="https://agentmods.dev/badge/skills/vivy-yi/finance-skills/audit-support-master/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/vivy-yi/finance-skills/audit-support-master"><img src="https://agentmods.dev/badge/skills/vivy-yi/finance-skills/audit-support-master.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00097 | $0.02012 |
| Opus 5 | $0.00048 | $0.01006 |
| Sonnet 5 | $0.00019 | $0.00402 |
| Haiku 4.5 | $0.00010 | $0.00201 |
Grade A, and why
audit-support-master scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 262 lines — stays where its author put it; the contents beside it link to each section on GitHub.
加载上下文
首次使用时: 读取 ../../CLAUDE.md 获取场景级配置(审计类型/配合流程/升级矩阵)。
/audit-support-master — 审计配合主流程
完整审计配合流程
Step 1:审计进场准备(进场前 X 天)
→ 确认审计范围和时间
→ 执行 audit-evidence-collection
→ 按时完成资料收集
Step 2:现场配合(审计期间)
→ 执行 confirmation-management
→ 协调函证程序
→ 处理函证异常
Step 3:审计调整审核(审计过程中)
→ 执行 audit-adjustment-review
→ 处理调整分歧
→ 确认最终调整
Step 4:管理层声明
→ 管理层声明书准备
→ 签署确认
Step 5:审计结论沟通
→ 初步审计意见沟通
→ 管理层回应
→ 审计报告出具
第一步:资料收集情况
执行 Skill: audit-evidence-collection
□ 执行状态:[成功/失败/部分成功]
□ 资料完整率:[X%]
□ 缺失资料:[✅ 无 / ⚠️ X 项]
□ 缺失影响:
□ 对报表影响:[低/中/高]
□ 替代方案:[已确认/待确认]
□ 资料交接完成:[✅ 是 / ⚠️ 否]
□ 交接日期:[YYYY-MM-DD]
第二步:函证管理情况
执行 Skill: confirmation-management
□ 执行状态:[成功/失败/部分成功]
□ 发函完成率:[X%]
□ 回函率:[X%]
□ 银行函证:
□ 回函率:[X%]
□ 金额不符:[X] 家
□ 冻结/抵押:[✅ 无 / ⚠️ X 家须关注]
□ 往来函证:
□ 回函率:[X%]
□ 金额不符:[X] 笔
□ 未回函:[X] 笔(替代程序 [✅ 充分 / ⚠️ 不够充分])
第三步:审计调整情况
执行 Skill: audit-adjustment-review
□ 执行状态:[成功/失败/部分成功]
□ 调整分录总数:[X] 笔
□ 调整金额:[±XXX万]
□ 对利润影响:[±XXX万]
□ 是否超过重要性水平:[✅ 是 / ⚠️ 否]
□ 存在争议:[✅ 无 / ⚠️ X 笔须处理]
□ 最终接受:[X] 笔 — 金额 [XXX万]
□ 坚持不接受:[X] 笔 — 金额 [XXX万]
第四步:综合风险评估
跨维度综合分析:
整体审计风险:[✅ 低 / ⚠️ 中 / 🔴 高]
资料风险:
□ 完整性:[✅ 完整 / ⚠️ X 项缺失]
□ 对报表影响:[低/中/高]
函证风险:
□ 回函率:[X%]
□ 替代程序充分性:[✅ 充分 / ⚠️ 不够充分]
□ 差异处理:[已处理/待处理]
调整风险:
□ 调整争议:[✅ 无 / ⚠️ X 笔]
□ 对报表影响:[低/中/高]
□ 非标意见风险:[✅ 低 / ⚠️ 中 / 🔴 高]
综合诊断:
□ 🔴 高风险项:[描述] — 须立即处理
□ ⚠️ 中风险项:[描述] — 须跟进
第五步:生成审计配合综合报告
═══════════════════════════════════════
审计配合报告
审计年度:[YYYY年度]
报告日期:[YYYY-MM-DD]
═══════════════════════════════════════
【核心结论】
整体审计配合风险:[✅ 低 / ⚠️ 中 / 🔴 高]
□ 资料准备:[一句话总结]
□ 函证程序:[一句话总结]
□ 审计调整:[一句话总结]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
【一、审计概况】
□ 审计类型:[年度审计/专项审计]
□ 审计机构:[会计师事务所名称]
□ 审计期间:[YYYY年MM月DD日至YYYY年MM月DD日]
□ 审计团队进场:[YYYY-MM-DD]
□ 预计报告出具:[YYYY-MM-DD]
【二、资料收集情况】
□ 资料完整率:[X%]
□ 缺失资料:[✅ 无 / ⚠️ X 项]
□ 缺失影响:[✅ 低 / ⚠️ 中 / 🔴 高]
□ 资料交接:[✅ 已完成 / ⚠️ 待确认]
□ 交接日期:[YYYY-MM-DD]
【三、函证情况】
□ 银行函证:
□ 发函:[X] 家 — 回函 [X] 家 — 回函率 [X%]
□ 金额不符:[X] 家
□ 冻结/抵押:[✅ 无 / ⚠️ X 家须关注]
□ 往来函证:
□ 发函:[X] 家 — 回函 [X] 家 — 回函率 [X%]
□ 确认相符:[X] 家
□ 金额不符:[X] 笔
□ 未回函:[X] 笔(替代程序 [✅ 充分 / ⚠️ 不够充分])
□ 函证整体可依赖度:[✅ 高 / ⚠️ 中 / 🔴 低]
【四、审计调整情况】
□ 调整分录:[X] 笔
□ 调整金额:[±XXX万]
□ 对利润影响:[±XXX万]
□ 是否超过重要性水平:[✅ 是 / ⚠️ 否]
□ 存在争议:[✅ 无 / ⚠️ X 笔]
□ 最终接受:[X] 笔
□ 坚持不接受:[X] 笔
【五、审计结论预览】
□ 初步审计意见:[无保留/保留/无法表示意见/否定]
□ 非标意见风险:[✅ 低 / ⚠️ 中 / 🔴 高]
□ 主要关注事项:
□ [事项A] — [描述]
□ [事项B] — [描述]
□ 管理层声明书:[✅ 已签署 / ⚠️ 待签署]
【六、风险评估】
□ 资料风险:[✅ 低 / ⚠️ 中 / 🔴 高]
□ 函证风险:[✅ 低 / ⚠️ 中 / 🔴 高]
□ 调整风险:[✅ 低 / ⚠️ 中 / 🔴 高]
□ 非标意见风险:[✅ 低 / ⚠️ 中 / 🔴 高]
□ 整体审计风险:[✅ 低 / ⚠️ 中 / 🔴 高]
【七、待跟进事项】
□ 高优先级:
□ [待办A] — 责任人 [X] — 完成日期 [YYYY-MM-DD]
□ [待办B] — 责任人 [X] — 完成日期 [YYYY-MM-DD]
□ 中优先级:
□ [待办C] — 责任人 [X] — 完成日期 [YYYY-MM-DD]
【八、下阶段工作安排】
□ [YYYY-MM-DD]:初步审计意见沟通
□ [YYYY-MM-DD]:管理层声明书签署
□ [YYYY-MM-DD]:最终审计调整确认
□ [YYYY-MM-DD]:正式审计报告出具
═══════════════════════════════════════
编制人:[财务经理]
审核人:[CFO]
═══════════════════════════════════════
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 262 lines · 97 tokens per session scan A 8b2a237b02e5
audit-support-master is a skill published in the GitHub repository vivy-yi/finance-skills (28 stars, last pushed 2mo ago), licensed MIT. It adds 97 tokens to every session and 2,012 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
wealth-structure
A framework for thinking about wealth through ownership, responsibility, leverage, and avoiding risks that could end your progress.
iso-13485-certification
Comprehensive toolkit for preparing ISO 13485 certification documentation for medical device Quality Management Systems. Use when users need help with ISO 13485 QMS documentation, including (1) conducting gap analysis of existing documentation, (2) creating Quality Manuals, (3) developing required procedures and work…
alpha-vantage
Access real-time and historical stock market data, forex rates, cryptocurrency prices, commodities, economic indicators, and 50+ technical indicators via the Alpha Vantage API. Use when fetching stock prices (OHLCV), company fundamentals (income statement, balance sheet, cash flow), earnings, options data, market…
hedgefundmonitor
Query the OFR (Office of Financial Research) Hedge Fund Monitor API for hedge fund data including SEC Form PF aggregated statistics, CFTC Traders in Financial Futures, FICC Sponsored Repo volumes, and FRB SCOOS dealer financing terms. Access time series data on hedge fund size, leverage, counterparties, liquidity…
edgartools
Python library for accessing, analyzing, and extracting data from SEC EDGAR filings. Use when working with SEC filings, financial statements (income statement, balance sheet, cash flow), XBRL financial data, insider trading (Form 4), institutional holdings (13F), company financials, annual/quarterly reports (10-K…
asc-ppp-pricing
Set territory-specific pricing for subscriptions and in-app purchases using current asc setup, pricing summary, price import, and price schedule commands. Use when adjusting prices by country or implementing localized PPP strategies.