Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Auditor

  • 30 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Plan and execute internal and IT audits: risk-based scoping, control walkthroughs, sampling, ITGC testing, and deficiency and remediation write-ups.

About

Guides assurance engagements covering risk-based audit planning, control testing, workpaper documentation, ITGC themes, and audit-committee reporting. A developer or auditor uses it to plan internal/IT audits, run walkthroughs, and write deficiency findings.

  • Maps controls to COSO, COBIT, and SOC 2 trust criteria
  • Design vs operating effectiveness, sampling, and ITGC testing

Auditor by the numbers

  • 30 all-time installs (skills.sh)
  • Ranked #1,492 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill auditor

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs30
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Plan and execute internal and IT audits: risk-based scoping, control walkthroughs, sampling, ITGC testing, and deficiency and remediation write-ups.

Files

SKILL.mdMarkdownGitHub ↗

Auditor

When to Use

  • Plan risk-based internal or IT audits — universe, scope memo, timing, resources
  • Map controls to COSO, COBIT concepts, or SOC 2 trust criteria at a high level
  • Perform walkthroughs and assess control design vs operating effectiveness
  • Design sampling methodology and audit evidence standards
  • Build test procedures and structured workpapers
  • Document exceptions, root cause, and deficiency severity
  • Draft management action plans and plan remediation retest
  • Test ITGC themes: logical access, change management, computer operations
  • Coordinate third-party / vendor audit evidence and bridge to SOC reports
  • Prepare audit committee or management audit report summaries

When NOT to Use

  • Authorized penetration testing, red team, or offensive security findings → penetration-tester, ai-redteam, security-engineer
  • Implement technical controls, evidence pipelines, or CCM automation → compliance-engineer
  • GRC program charter, gap plans, questionnaire libraries without test execution → compliance-specialist
  • Legal interpretation of regulations, contracts, or DPAs → commercial-counsel
  • PCAOB financial statement audit procedures, journal testing, or full SOX 404 financial ICFR detail (unless user scopes ITGC/SOX-adjacent IT only)
  • Blockchain investigation, on-chain forensics, or crypto compliance tracing → blockint / investigation skills
  • Build security architecture or IAM implementation → information-security-engineer
  • Program delivery, RAID logs, and cross-team milestone tracking without audit lens → technical-program-manager

Related skills

NeedSkill
Technical control implementation and evidence automationcompliance-engineer
GRC scope, gap plans, assessor prep, questionnaire librariescompliance-specialist
Cloud framework evidence and residencycloud-compliance-specialist
IAM, logging, encryption implementationinformation-security-engineer
Contracts, DPAs, regulatory legal interpretationcommercial-counsel
Cross-functional delivery, dependencies, status cadencetechnical-program-manager
SOX sample selection and financial control testing patternsaudit-support (personal skill)
Security program strategycybersecurity
Pentest factual input (not attestation)penetration-tester

Core Workflows

1. Engagement initiation and scoping

1. Confirm engagement type (internal, IT, integrated, follow-up) 2. Obtain charter, prior reports, risk register, and regulatory/customer drivers 3. Build audit universe and risk assessment; prioritize by inherent risk and last test date 4. Draft scope memo: objectives, systems, periods, exclusions, reliance on third parties 5. Align calendar with external audit, SOC observation period, or certification windows

See `references/auditor_scope.md` and `references/audit_planning_and_risk.md`.

2. Control understanding and framework mapping

1. Identify process owner and key systems 2. Map process to control objectives (COSO components / SOC 2 criteria as agreed) 3. Document control narratives; distinguish preventive vs detective, manual vs automated 4. Perform walkthrough (trace sample transaction end-to-end) 5. Conclude on design effectiveness before operating tests

See `references/control_frameworks_and_mapping.md`.

3. Test planning and execution

1. Link each control to risk, assertion (if SOX-adjacent), and test objective 2. Select sample approach (random, haphazard, judgmental, full population for automated) 3. Execute procedures: inspect, observe, inquire, re-perform 4. Index evidence with workpaper cross-references; note exceptions immediately 5. Escalate scope changes or control failures to engagement lead

See `references/testing_evidence_workpapers.md`.

4. Findings, remediation, and retest

1. Classify exceptions: isolated vs pervasive; design vs operating 2. Assign deficiency level (see reference severity matrix) 3. Document root cause, impact, and recommendation 4. Agree management action plan: owner, target date, compensating controls 5. Retest remediated controls; close only with sufficient evidence

See `references/findings_remediation_retest.md`.

5. Reporting and governance

1. Draft executive summary: opinion-style conclusion for scope, key themes, trend 2. List findings by severity with agreed actions 3. Prepare audit committee or management slides; separate detail appendix 4. Track open items through next cycle; feed annual audit plan

See `references/reporting_governance_third_party.md`.

Outputs

  • Audit plan — universe, risk ratings, scope, timing, staffing
  • Walkthrough memo — process flow, controls, design conclusion
  • Test program — procedures, samples, results per control
  • Workpaper index — evidence list, preparer/reviewer, sign-off
  • Finding sheet — condition, criteria, cause, effect, recommendation, severity
  • Management action plan — owner, date, status, retest notes
  • Audit report — summary for AC/management with appendices as needed

Principles

  • Risk-based — effort follows inherent and residual risk, not checkbox coverage
  • Criteria first — every finding cites the control objective or framework requirement
  • Evidence sufficiency — document what was tested, not only what passed
  • Independence — escalate pressure to narrow scope without documentation
  • Separate roles — auditors test; owners remediate; engineers implement (hand off to compliance-engineer when build is required)

Reference map

TopicFile
Role boundaries and engagement typesreferences/auditor_scope.md
Universe, risk assessment, annual planreferences/audit_planning_and_risk.md
COSO, COBIT, SOC 2 mappingreferences/control_frameworks_and_mapping.md
Sampling, evidence, workpapersreferences/testing_evidence_workpapers.md
Findings, MAP, retestreferences/findings_remediation_retest.md
Reporting, AC, vendorsreferences/reporting_governance_third_party.md

Disclaimer

This skill supports audit planning and documentation workflows. It does not provide legal, accounting, or attestation advice. Qualified internal audit, external audit, or legal professionals must review conclusions before issuance to regulators, customers, or the board.

Related skills

Securityauditcompliance

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.