作成者 · guoliang1114-boop
最終更新 · 2026年8月24日
audit-substantive-procedures
设计和执行实质性审计程序,覆盖细节测试、实质性分析程序、函证程序和审计抽样,基于ISA 330框架。
サンドボックス限定
インストール先
Codex インストールプロンプト
Install the "audit-substantive-procedures" agent skill from https://github.com/guoliang1114-boop/AriaAI/tree/main/skills/audit-substantive-procedures. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: 设计和执行实质性审计程序,覆盖细节测试、实质性分析程序、函证程序和审计抽样,基于ISA 330框架。 After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"guoliang1114-boop-audit-substantive-procedures","task":"Install audit-substantive-procedures","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.供給アセットの概要
リサーチとナレッジ作業
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
シナリオ
リサーチ Agent
I need my agent to research a topic, compare sources, and produce a concise report.
Agent 適合
Claude Code + CLI + Codex
Codex、Claude Code、Cursor、CLI、またはカスタム Agent に対応します。
インストール
準備完了
npx skills add guoliang1114-boop/AriaAI --skill audit-substantive-procedures
メンテナンス
新しい
本日プッシュ
リスク
要レビュー
No explicit limitations section delineating when this skill should not be used (e.g., regulatory constraints, data privacy, or non-ISA environments).
GitHub 品質
37
62/100 品質 · 69/100 信頼
対象タグ
レビュー注記
No explicit limitations section delineating when this skill should not be used (e.g., regulatory constraints, data privacy, or non-ISA environments). · The skill relies on tools (search, read, write, edit) but does not specify how to obtain the data sources or handle missing data beyond mentioning 'material gaps' in Aria Context Enrichment.
Agent 導入スコアカード
信頼、監査、インストール準備状況を一目で確認
公開リポジトリのメタデータ、OpenAgentSkill のレビューシグナル、保守の鮮度、インストール準備状況を組み合わせたスコアです。候補選定の目安であり、人によるレビューの代替ではありません。
品質
有望有用な候補ですが、採用前に代替と比較してください。
信頼
サンドボックス限定信頼シグナルが不足または混在する有用な候補です。結果ループがタスク適合を示すまで、隔離されたワークスペースで使用してください。
監査
要レビューインストール準備、安全メタデータ、保守、採用リスクの機械可読なレビュー。
OpenAgentSkill Trust Score v5
インストール前に人のレビュー
実作業で使う前に、サンドボックスでのみ実行し、近い代替と比較してください。
スター
GitHub スター 37
リポジトリ活動
スター 37、フォーク 2
メンテナンス
本日プッシュ
ライセンス
MIT
インストール
npx skills add guoliang1114-boop/AriaAI --skill audit-substantive-procedures
インストール安全性
標準パッケージまたはランタイムのインストールパス
権限範囲
公開メタデータに高リスクな権限範囲はありません
Agent の成果
Agent の成果データはまだありません
ドキュメント
Thin public metadata
リスク概要
本番前にレビュー
- No explicit limitations section delineating when this skill should not be used (e.g., regulatory constraints, data privacy, or non-ISA environments).
- Low GitHub adoption signal
- Quality score needs review
- GitHub adoption: 37 GitHub stars
インストール準備状況
インストールパスを利用可能
- インストールパスを利用できます
- リポジトリの根拠を利用できます
- ライセンスが明示されています
- Agent-Proven の成果エビデンスはまだありません
Agent 可読メタデータ
このスキルの機械可読な判断データ。
このブロックまたは埋め込み JSON を使い、Agent がこのスキルをインストールすべきか、代替を選ぶべきか、先に人のレビューを求めるべきかを判断できます。
View technical data+
Agent 可読メタデータ
このスキルの機械可読な判断データ。
このブロックまたは埋め込み JSON を使い、Agent がこのスキルをインストールすべきか、代替を選ぶべきか、先に人のレビューを求めるべきかを判断できます。
適したタスク
- Content automation ワークフロー
- Claude Code チーム
- builders willing to evaluate younger projects
- Summarize source material
適した Agent
インストール判断
- コマンド
- npx skills add guoliang1114-boop/AriaAI --skill audit-substantive-procedures
- ポリシー
- レビュー
- 人によるレビュー
- はい
信頼とリスク
- 信頼
- 61/100
- 監査
- 76/100
- リスクレベル
- 要レビュー
成果ループ
- エンドポイント
- /api/agent/outcome
- イベント ID
- resolve
- 成果
- 5
インストールコマンド
npx skills add guoliang1114-boop/AriaAI --skill audit-substantive-procedures使わない場合
- ベンダー提供の SLA が必要なチーム
- production agents without a repository review
- Low GitHub adoption signal
- No explicit limitations section delineating when this skill should not be used (e.g., regulatory constraints, data privacy, or non-ISA environments).
- OpenAgentSkill の利用フィードバックはまだありません
Agent セーフティ v2
60/100 · インストール前にレビュー
利用可能な候補ですが、Agent はインストール前に権限と監査メモを提示する必要があります。
実際のワークスペースへインストールする前に人の承認が必要です。
中
ネットワークアクセス
Skill はリモートページ、API、リポジトリ、外部サービスにアクセスする可能性があります。
中
ファイルシステムアクセス
Skill はプロジェクトファイル、ドキュメント、生成物、ローカルワークスペース状態を読み書きする可能性があります。
- No explicit limitations section delineating when this skill should not be used (e.g., regulatory constraints, data privacy, or non-ISA environments).
Agent 解決プラン
インストール前に Agent に適合性を検証させます。
Resolve API は第一候補、代替、安全ポリシー、監査メモ、インストール先、Agent がそのまま使えるプロンプトを返します。
JSON を開く
/api/agent/resolve?task=Use%20audit-substantive-procedures%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve テキスト
/api/agent/resolve?task=Use%20audit-substantive-procedures%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
インストール引き継ぎ
/api/skills/guoliang1114-boop-audit-substantive-procedures/install
Agent が確認すべきこと
- Resolve API でタスク適合と代替を確認。
- 監査・信頼スコアと安全ポリシーの警告を確認。
- Codex、Claude Code、Cursor、CLI のインストール先互換性を確認。
プロンプトをコピー
Task: Use audit-substantive-procedures in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20audit-substantive-procedures%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/guoliang1114-boop-audit-substantive-procedures/install
Install command: npx skills add guoliang1114-boop/AriaAI --skill audit-substantive-procedures
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 引き継ぎ
別のディレクトリではなく、インストール経路を Agent に渡します。
公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。
インストール引き継ぎ
/api/skills/guoliang1114-boop-audit-substantive-procedures/install
LLM テキスト形式
/api/skills/guoliang1114-boop-audit-substantive-procedures/install?format=text
代替を探す
/api/skills/search?q=audit-substantive-procedures&limit=3
Agent プロンプト
Use audit-substantive-procedures for this task. Review https://www.openagentskill.com/api/skills/guoliang1114-boop-audit-substantive-procedures/install, then install with: npx skills add guoliang1114-boop/AriaAI --skill audit-substantive-proceduresRegistry メタデータ
自動スキル選択用の Agent 可読プロファイル。
Registry API 経由で判断、信頼、監査、ユースケース、インストールのシグナルを提供し、UI をスクレイピングせずに Agent が順位付けできます。
Manifest
/api/registry/manifest/guoliang1114-boop-audit-substantive-procedures
LLM テキスト
/api/registry/manifest/guoliang1114-boop-audit-substantive-procedures?format=text
インストール別名
/api/registry/install/guoliang1114-boop-audit-substantive-procedures
推奨
/api/registry/recommend?task=Use%20audit-substantive-procedures%20in%20an%20agent%20workflow&limit=3
Agent 適合
Content automation
プラットフォーム
Claude Code
Agent 判断パネル
Fallback candidate for Content automation
まずこのスキルでプロトタイプを作り、代替候補を用意してください。
スタック内の役割
代替候補
主な適合
Content automation
信頼ラベル
まずプロトタイプ
インストールパス
コマンド準備済み
使う場面
- Content automation ワークフロー
- Claude Code チーム
- builders willing to evaluate younger projects
根拠
- 最近のリポジトリ活動
- インストールコマンドまたは GitHub リポジトリが利用可能
- 品質プロファイル 62/100
先にレビュー
- Low GitHub adoption signal
- No explicit limitations section delineating when this skill should not be used (e.g., regulatory constraints, data privacy, or non-ISA environments).
- OpenAgentSkill の利用フィードバックはまだありません
実装パス
- 1サンドボックスの Agent にインストールし、Content automation タスクを一度最初から最後まで実行します。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信頼プロファイル
サンドボックス限定
信頼シグナルが不足または混在する有用な候補です。結果ループがタスク適合を示すまで、隔離されたワークスペースで使用してください。
GitHub 採用度
確認GitHub スター 37
スター/フォーク活動
確認スター 37、フォーク 2; 現在のメタデータでは Issue 活動を利用できません
最近のメンテナンス
合格本日プッシュ
ライセンスの明確さ
合格MIT
良いシグナル
- AI レビュー承認済み
- インストールパスを利用できます
- リポジトリの根拠を利用できます
- 最近保守されたリポジトリ
- インストールコマンドに明確な高リスクパターンはありません
- 成果ループは準備済みですが、最初の実行が必要です
インストール前にレビュー
- No explicit limitations section delineating when this skill should not be used (e.g., regulatory constraints, data privacy, or non-ISA environments).
- Low GitHub adoption signal
- Quality score needs review
- GitHub adoption: 37 GitHub stars
- Stars/forks activity: 37 stars, 2 forks; issue activity unavailable in current metadata
- README/SKILL.md completeness: Public metadata needs stronger README/SKILL.md context
- 実際の Agent 成果レポートはまだありません
- 無人インストールの前に人によるレビューが必要です
推奨アクション
実作業で使う前に、サンドボックスでのみ実行し、近い代替と比較してください。
品質プロファイル
有望 Agent ワークフロー向けの候補
有用な候補ですが、採用前に代替と比較してください。
ワークフロー適合
このスキルを使うシナリオ
Publish consistently
Content automation
I need my agent to turn research and product updates into useful content drafts.
Operate web apps
Browser automation
I need my agent to control a browser, fill forms, and verify web app workflows.
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
ワークフロー適合
完全なワークフローに追加
Turn skills into distribution
Content growth agent
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
代替候補
インストール前に比較
このタスクに適する可能性のある類似スキル。
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
概要
--- name: audit-substantive-procedures description: "设计和执行实质性审计程序,覆盖细节测试、实质性分析程序、函证程序和审计抽样,基于ISA 330框架。" --- # 实质性审计程序设计与执行
## When To Use - 需要针对已评估的认定层次重大错报风险设计审计应对程序 - 执行实质性程序以获取充分、适当的审计证据 - 对账户余额、交易类别和披露实施细节测试 - 执行实质性分析程序以验证财务数据的合理性 - 设计函证程序并评估回函结果
## Tools - `search` — 搜索被审计单位财务数据、账户明细、历史审计工作底稿 - `read` — 读取风险评估结果、控制测试结论、重要性水平设定 - `write` — 生成实质性程序工作底稿 - `edit` — 修改程序设计、更新测试结果
## Framework
### NTE框架(Nature, Timing, Extent) 基于ISA 330第6-12条,审计师应从性质、时间安排和范围三个维度设计实质性程序:
1. **性质(Nature)** — 选择程序类型 - 细节测试:针对重大交易、余额和披露的测试 - 实质性分析程序:当预期关系稳定且可预测时使用 - 函证:针对应收账款、银行存款、法律事项等第三方确认 - 重新计算:验证会计估计和计算的准确性
2. **时间安排(Timing)** — 确定执行时点 - 期中测试 + 期后覆盖:对期中余额执行程序,并覆盖剩余期间 - 期末测试:针对重大风险或期中测试不可行的情况 - 期后事项审查:关注资产负债表日后的事项
3. **范围(Extent)** — 确定样本量和覆盖范围 - 考虑评估的重大错报风险水平 - 考虑已获取的其他审计证据的说服力 - 考虑审计抽样方法的适当性
### 细节测试实施步骤(ISA 330第18-21条) 1. 识别需要测试的认定(存在、完整性、准确性、截止、分类、计价) 2. 选取测试项目(全部测试/选取特定项目/审计抽样) 3. 设计审计程序并记录预期结果 4. 执行程序并记录实际结果 5. 评估差异是否构成错报
### 实质性分析程序(ISA 520) 1. 确定预期值的精确度要求 2. 建立数据间预期关系(趋势分析、比率分析、合理性测试) 3. 评估预期值的可靠性 4. 确定可接受差异额 5. 调查并核实不可接受的差异
### 函证程序(ISA 505) 1. 确定函证范围和对象 2. 设计询证函格式(积极式/消极式) 3. 控制函证的发送和收回 4. 评估回函结果和替代程序
### 审计抽样(ISA 530) 1. 确定抽样总体和抽样单元 2. 选择抽样方法(统计抽样/非统计抽样) 3. 确定样本量(考虑可容忍错报、预计总体错报、置信水平) 4. 评价样本结果并推断总体
## Workflow 1. 从风险评估程序获取已识别的重大错报风险 2. 运用NTE框架确定实质性程序的性质、时间安排和范围 3. 针对每个重要账户和认定设计具体程序 4. 执行细节测试、分析程序和函证程序 5. 记录测试结果,识别和评价错报 6. 汇总发现的错报并与管理层沟通 7. 评估获取的审计证据是否充分、适当
## Output Format
```markdown # 实质性程序工作底稿 — [账户名称]
## 一、基本信息 | 项目 | 内容 | |------|------| | 被审计单位 | [公司名称] | | 审计期间 | [期间] | | 账户/认定 | [账户名称] / [相关认定] | | 执行人/日期 | [姓名] / [日期] | | 复核人/日期 | [姓名] / [日期] |
## 二、风险评估结果 - 已识别的重大错报风险:[描述] - 风险水平:[高/中] - 相关认定:[存在/完整性/准确性/截止/计价]
## 三、NTE设计决策 | 维度 | 决策 | 理由 | |------|------|------| | 性质 | [细节测试/分析程序/函证] | [理由] | | 时间安排 | [期中+期后/期末] | [理由] | | 范围 | [样本量/覆盖比例] | [理由] |
## 四、审计程序及结果 | 序号 | 审计程序 | 预期结果 | 实际结果 | 差异 | 结论 | |------|----------|----------|----------|------|------| | 1 | [程序描述] | [预期] | [实际] | [差异额] | [结论] |
## 五、函证程序(如适用) | 函证对象 | 金额 | 函证方式 | 回函情况 | 差异及原因 | |----------|------|----------|----------|------------| | [单位] | [金额] | [积极/消极] | [相符/不符/未回] | [说明] |
## 六、抽样结果(如适用) | 项目 | 数值 | |------|------| | 总体规模 | [数量] | | 样本量 | [数量] | | 样本错报额 | [金额] | | 推断总体错报 | [金额] | | 可容忍错报 | [金额] |
## 七、结论 - [ ] 获取了充分、适当的审计证据 - 识别的错报汇总:[金额] - 是否需要调整:[是/否] ```
## Diagnostic Questions - 风险评估结果中哪些认定涉及重大错报风险? - 是否对所有重要账户的认定设计了实质性程序? - 实质性分析程序的预期关系是否稳定可靠? - 函证程序是否受到被审计单位的限制? - 审计抽样的可容忍错报是否考虑了重要性水平?
## Verification - 核实所有已识别的重大错报风险均有对应的实质性程序覆盖 - 验证样本量满足ISA 530的要求 - 确认函证过程的独立性和控制有效性 - 复核错报汇总的完整性
## Saving 将工作底稿保存至 `audit-workpapers/[年份]/substantive-procedures/[账户名称].md`,确保包含执行人和复核人签字及日期。
## Capability Upgrade
### Mode Selection
- **Quick**: 根据账户和风险认定,给出实质性程序建议清单。 - **Standard**: 设计 NTE、样本策略、函证/替代程序、分析程序和工作底稿模板。 - **Deep**: 结合风险评估、重要性、控制测试结果、历史错报和数据明细,形成可执行审计程序包和复核清单。
### Aria Context Enrichment
优先读取审计风险评估、重要性水平、试算平衡表、账户明细、上期审计调整、控制测试结果和管理层解释。若缺少关键资料,先列资料缺口,并说明会影响性质、时间或范围中的哪一项。
### NTE Decision Engine
| 风险条件 | 性质 Nature | 时间 Timing | 范围 Extent | |----------|-------------|-------------|-------------| | 重大错报风险高,控制不可依赖 | 细节测试为主,必要时函证 | 期末或接近期末 | 扩大样本,覆盖高金额和异常项目 | | 风险中等,预期关系稳定 | 分析程序 + 有限细节测试 | 期中结合期末滚动 | 标准样本,关注波动项目 | | 控制测试有效,风险较低 | 分析程序或定向测试 | 可期中执行 | 缩小范围,但保留不可预见性 | | 管理层限制函证或资料不完整 | 替代程序 + 风险升级 | 期末 | 扩大替代程序并评估范围受限 |
### Exception Handling
发现差异时必须判断:
1. 是否为事实错报、判断错报或推断错报。 2. 是否需要扩大样本或追加程序。 3. 是否影响同类账户、披露或相关认定。 4. 是否需要汇总至审计调整表或沟通治理层。
### Quality Gates
- [ ] 每个重大认定都有对应程序,不存在风险未响应。 - [ ] 样本选择逻辑能复核,覆盖高金额、异常和随机样本。 - [ ] 函证过程独立控制,未回函有替代程序。 - [ ] 所有差异都有原因、金额、影响和处理结论。 - [ ] 工作底稿可以支持充分、适当审计证据的结论。
### Deliverable Catalog
| Deliverable | When to use | Minimum content | Format | |-------------|-------------|-----------------|--------| | Substantive audit program | 设计账户审计程序 | 账户、认定、风险、程序、时间、范围和负责人 | Excel / Markdown | | NTE decision memo | 程序设计需要解释 | Nature、Timing、Extent、依据和风险响应 | Markdown | | Sampling workpaper | 使用抽样测试 | 总体、样本、方法、差异、推断错报和结论 | Excel | | Confirmation control log | 执行函证 | 对象、金额、发函、回函、差异、替代程序 | Excel | | Misstatement summary | 发现差异 | 事实错报、判断错报、推断错报、调整建议 | Excel | | Completion workpaper | 账户完工 | 程序执行结果、证据、复核点和结论 | Word / Markdown |
技術詳細
- バージョン
- 1.0.0
- ライセンス
- MIT
- 最終更新
- 2026年8月24日
- 公開日
- 2026年8月24日
判断の要約
代替候補
最近のリポジトリ活動
Agent 実証エビデンス
Agent 実証エビデンス
Resolve、レビュー、インストール、限定実行後の成果レポート。
- 成功率
- —
- 直近の失敗
- —
- 成果
- 0
- 出力品質
- —
- 失敗
- 0
- 非該当
- 0
- インストール数
- 0
- リスクによりブロック
- 0
- 設定が必要
- 0
- 本番
- 0
Agent の実行結果はまだありません。最初の実行では /api/agent/outcome を通じて成功、設定要件、リスクによるブロック、失敗、非該当を報告できます。
成長ループ
共有キット
audit-substantive-procedures 用のシナリオベース草案です。X へ手動投稿できます。
For a real agent workflow, this is a skill worth shortlisting before another blank prompt. audit-substantive-procedures: 设计和执行实质性审计程序,覆盖细节测试、实质性分析程序、函证程序和审计抽样,基于ISA 330框架。 37 stars https://www.openagentskill.com/skills/guoliang1114-boop-audit-substantive-procedures?ref=x
任意:インストールコマンド付きの返信
Listing + install path for audit-substantive-procedures: https://www.openagentskill.com/skills/guoliang1114-boop-audit-substantive-procedures?ref=x Install: npx skills add guoliang1114-boop/AriaAI --skill audit-substantive-procedures
掲載元
Registry により登録
この掲載は公開ソースから登録されており、メンテナー申請が承認されるまで公式として表示されません。
- インデックス作成者
- OpenAgentSkill コミュニティインデックス
帰属は公開リポジトリまたは作成者プロフィールにリンクされています。作成者は掲載を申請して所有権シグナルを更新できます。
このスキルを申請所有者の申請
このスキル掲載を申請
この Registry により登録 掲載は guoliang1114-boop に帰属していますが、まだ公式として表示されていません。申請すると、確認済み所有者シグナルが追加され、今後の公開、インストール、監査更新の信頼性が高まります。
クリエイター被リンクキット
README にエビデンスバッジを追加
開発者がリポジトリを評価する場所で、正規掲載、現在の信頼・監査シグナル、実際の Agent-Proven エビデンスを表示します。
[](https://www.openagentskill.com/skills/guoliang1114-boop-audit-substantive-procedures)
[](https://www.openagentskill.com/skills/guoliang1114-boop-audit-substantive-procedures)
[](https://www.openagentskill.com/skills/guoliang1114-boop-audit-substantive-procedures/audit)
[](https://www.openagentskill.com/skills/guoliang1114-boop-audit-substantive-procedures)作者
guoliang1114-boop
@guoliang1114-boop
プラットフォーム適合
健全性シグナル
- GitHub スター
- 37
- 品質スコア
- 34/100
- 最終 GitHub プッシュ
- 2026年8月24日
- フレームワークのヒント
- 不明
- OpenAgentSkill 閲覧数
- 0
- インストールコピー数
- 0
- 外部クリック
- 0
コミュニティシグナル
このスキルが Agent ワークフローに役立つかを共有してください。集約されたフィードバックがランキングを改善します。
信頼と安全性
サンドボックス限定
- GitHub 採用度GitHub スター 37確認
- スター/フォーク活動スター 37、フォーク 2; 現在のメタデータでは Issue 活動を利用できません確認
- 最近のメンテナンス本日プッシュ合格
- ライセンスの明確さMIT合格
- README/SKILL.md の完全性公開メタデータにはより十分な README/SKILL.md の文脈が必要です確認
- 依存関係/ランタイムのリスク公開メタデータに重大な依存関係リスクのヒントはありません合格
関連スキル
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K スターMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K スターNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K スターInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K スター