Agent skill

Audit Harness

by filedcom in filedcom/opentax

Generic audit/fix loop. An agent skill from filedcom/opentax.

AGPL-3.0Auto-check passed

Install Audit Harness

skills CLI
$ npx skills add filedcom/opentax --skill audit-harness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install filedcom/opentax audit-harness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/filedcom/opentax.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-harness .claude/skills/audit-harness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-harness
GitHub stars
108
Token cost
~1.8k tokens
SKILL.md length
776 words
Files
4
Skills in repo
8
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Generic audit/fix loop. An agent skill from filedcom/opentax.

  • Works in 8 steps: Initialize State → Checkpoint Git State → Spawn Planner (Plan Phase) → …
  • SKILL.md covers Step 0 — Initialize State, Step 1 — Checkpoint Git State, Step 2 — Spawn Planner (Plan… and Step 3 — Spawn Auditor Teams…, plus 7 more sections
  • Calls git

What it does

Audit Harness is an agent skill from filedcom/opentax. Generic audit/fix loop. Pass a goal string. Planner subdivides work, auditor/fixer teams run in parallel, loop until 2 consecutive clean cycles.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `agents/auditor.md`, `agents/fixer.md` and `agents/planner.md`).

The repository describes itself as: Fully open-source US federal tax engine. Single binary cli. Runs on macOS, Linux, and Windows. Built for AI agents using AI agents. The licence is AGPL-3.0.

Example prompts

  • “/audit-harness”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Initialize State
  2. Checkpoint Git State
  3. Spawn Planner (Plan Phase)
  4. Spawn Auditor Teams (Parallel)
  5. Update State from Team Results
  6. Commit if Progress Made
  7. Spawn Planner (Review Phase)
  8. Finalize

What it can do on your machine

Read from SKILL.md and the folder at commit 0c6ae76. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Harness loads about 1.8k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 776 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from filedcom/opentax at commit 0c6ae76, republished under its AGPL-3.0 licence (© filedcom). 776 words, ~1,797 tokens.

Download SKILL.mdSave it as .claude/skills/audit-harness/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
audit-harness
description
Generic audit/fix loop. Pass a goal string. Planner subdivides work, auditor/fixer teams run in parallel, loop until 2 consecutive clean cycles.

Audit Harness — Generic Audit/Fix Loop

Goal: $ARGUMENTS


Step 0 — Initialize State

Generate a run_id: take the first 5 words of $ARGUMENTS, lowercase, replace spaces with hyphens, append today's date as -YYYYMMDD. Example: "ensure compute functions handle edge" → ensure-compute-functions-handle-edge-20260411.

Read .state/audit/state.json. If the file does not exist, create it:

json
{"version": 1, "runs": {}}

Check if runs[run_id] exists:

  • If status === "done" → print "Run already completed." and stop.
  • If status === "stalled" → print "Run stalled previously. Reset status to 'running' in state.json to retry." and stop.
  • If status === "running" → resume from current global_cycle (skip to Step 2 if work_packages exist, otherwise Step 2 will re-plan).
  • If not present → create a new entry:
    json
    {
      "goal": "$ARGUMENTS",
      "status": "running",
      "created_at": "<ISO timestamp>",
      "global_cycle": 0,
      "global_clean_count": 0,
      "checkpoint_commit": null,
      "work_packages": [],
      "cycles": []
    }

Write state.json.


Step 1 — Checkpoint Git State

bash
git add -A && git status --porcelain

If there are uncommitted changes, commit them:

bash
git commit -m "audit-harness: checkpoint before run {run_id}"

Record the current HEAD SHA as checkpoint_commit in the run entry. Write state.json.


Step 2 — Spawn Planner (Plan Phase)

Spawn one agent using the prompt from .claude/skills/audit-harness/agents/planner.md.

Pass as context in the agent prompt:

  • goal: The full $ARGUMENTS string
  • mode: "plan"
  • state: The full run entry JSON (so planner can see prior cycles if resuming)

Wait for the planner to complete. Find the line starting with PLANNER_RESULT: in its output. Parse the JSON after the prefix.

Expected shape:

json
{"action": "plan", "work_packages": [...]}

Write the work_packages array into the run entry (merge with existing if resuming — keep packages that are already "done"). Increment global_cycle. Write state.json.


Step 3 — Spawn Auditor Teams (Parallel)

Collect all work_packages where status !== "done" (i.e., clean_count < 2).

For each active package, spawn one agent using .claude/skills/audit-harness/agents/auditor.md.

Pass as context in each agent prompt:

  • goal: $ARGUMENTS
  • work_package: The full package object (id, area, description, scope_files)
  • mode: "audit"
  • prior_findings: The package's findings array (so auditor avoids re-reporting fixed issues)

Spawn ALL auditor agents in a SINGLE message (parallel execution).

Wait for all to complete. For each, find the AUDITOR_RESULT: line and parse the JSON.


Step 3b — Spawn Fixer Agents (Parallel)

Collect all packages where the auditor returned clean === false (has findings).

For each package with findings, spawn one agent using .claude/skills/audit-harness/agents/fixer.md.

Pass as context:

  • goal: $ARGUMENTS
  • work_package: The package object
  • findings: The findings array from the auditor

Spawn ALL fixer agents in a SINGLE message (parallel execution).

Wait for all to complete. Parse each FIXER_RESULT: output.


Step 3c — Spawn Verification Auditors (Parallel)

For each package where the fixer applied at least one fix (applied === true), spawn one agent using .claude/skills/audit-harness/agents/auditor.md.

Pass as context:

  • goal: $ARGUMENTS
  • work_package: The package object
  • mode: "verify"
  • fixes_applied: The fixes array from the fixer output

Spawn ALL verification agents in a SINGLE message (parallel execution).

Wait for all to complete. Parse each AUDITOR_RESULT: output.


Show full SKILL.md (353 more words)Show less

Step 4 — Update State from Team Results

For each work_package:

  1. Determine final audit result for this cycle:

    • If the package had no findings in Step 3 (auditor clean === true) → clean cycle
    • If the package had findings, got fixes, and verification auditor returned clean === true → clean cycle
    • Otherwise → dirty cycle
  2. Update the package:

    • Clean cycle: increment clean_count by 1
    • Dirty cycle: reset clean_count to 0
  3. Append new findings to the package's findings array with the current cycle number. Mark fix_applied and fix_verified based on fixer and verification results.

  4. If clean_count >= 2: set package status to "done".

Record a cycle summary in the cycles array:

json
{
  "cycle": <global_cycle>,
  "total_findings": <sum of all findings across packages>,
  "packages_active": <count of non-done packages at start>,
  "packages_clean": <count that had clean cycles>,
  "commit": null
}

Write state.json.


Step 5 — Commit if Progress Made

bash
git diff --stat

If there are changes:

bash
git add -A
git commit -m "audit-harness: {run_id} cycle {global_cycle} — {N} findings fixed"

Update the last cycle entry's commit field and checkpoint_commit in the run. Write state.json.

If there are no changes (all fixers skipped or no findings), skip the commit.


Step 6 — Spawn Planner (Review Phase)

First, check short-circuit: If ALL work_packages have status === "done", skip the planner and go directly to Step 7.

Otherwise, spawn one agent using .claude/skills/audit-harness/agents/planner.md.

Pass as context:

  • goal: $ARGUMENTS
  • mode: "review"
  • state: The full run entry JSON (including updated cycles and work_packages)

Wait for the planner. Parse PLANNER_RESULT: JSON.

Handle the result:

If action === "done":

  • Go to Step 7.

If action === "continue":

  • Apply any adjustments from the planner:
    • {"type": "add", "package": {...}} → append to work_packages
    • {"type": "remove", "package_id": "wp-03"} → remove the package
    • {"type": "update", "package_id": "wp-02", ...} → merge updates into the package
  • Write state.json
  • Go back to Step 3

Step 7 — Finalize

Set the run's status to "done". Set updated_at to current timestamp. Write state.json.

Append a summary to .state/audit/progress.md:

markdown
## [{run_id}] Complete — {timestamp}
- Goal: {goal}
- Cycles: {global_cycle}
- Total findings fixed: {sum across all packages}
- Packages: {count} ({list of areas})
- Final commit: {checkpoint_commit}

Print the summary to the user.


Key Constraints

  • Never modify files outside of agent spawning — the main loop only manages state and git
  • Always commit net-positive changes — if fixers made things worse, the verification auditor catches it
  • Stall protection: If global_cycle >= 10, set status to "stalled" and stop (the planner should catch this earlier, but this is a hard cap)
  • Resume-safe: Every step reads state.json before acting, so interrupted runs can resume
  • Parallel-safe: Work packages have non-overlapping scope_files, so fixers cannot conflict

© filedcom, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in .claude/skills/audit-harness of filedcom/opentax.

  • SKILL.md
  • agents/auditor.md
  • agents/fixer.md
  • agents/planner.md

Open the folder on GitHubat commit 0c6ae76

Compare with similar skills

Audit Harness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Harness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Harness this skillfiledcom/opentax108—~1.8kAutomated safety check: PassAGPL-3.0
Agent Goal Plannerruvnet/ruflo74k3 repos~842Automated safety check: PassMIT
Agent Code Goal Plannerruvnet/ruflo74k3 repos~3.6kAutomated safety check: PassMIT
Plannerpenpot/penpot61k—~2.7kAutomated safety check: PassMPL-2.0
Goalscodewhale-hq/Codewhale41k—~273Automated safety check: PassMIT
Agent Plannerruvnet/ruflo74k2 repos~1.2kAutomated safety check: PassMIT

Similar skills

  • Agent Goal Planner

    ruvnet/ruflo

    Agent skill for goal-planner - invoke with $agent-goal-planner

    74k GitHub starsUsed in 3 repos~842 tokens
    Auto-check passed
  • Agent skill for code-goal-planner - invoke with $agent-code-goal-planner

    74k GitHub starsUsed in 3 repos~3.6k tokens
    Agent WorkflowsAuto-check passed
  • Planner

    penpot/penpot

    Read-only planning and architecture analysis — produce a structured implementation plan with task breakdown, acceptance criteria, sizing, and checkpoints.

    61k GitHub stars~2.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Goals

    codewhale-hq/Codewhale

    Set, review, and update the user's goals. An agent skill from codewhale-hq/Codewhale.

    41k GitHub stars~273 tokensUpdated today
    Auto-check passed
  • Agent Planner

    ruvnet/ruflo

    Agent skill for planner - invoke with $agent-planner. An agent skill from ruvnet/ruflo.

    74k GitHub starsUsed in 2 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Goal Plan

    ruvnet/ruflo

    Create and execute Goal-Oriented Action Plans (GOAP) with precondition analysis, cost optimization, and adaptive replanning

    74k GitHub stars~807 tokensUpdated today
    Auto-check: notes

More from filedcom/opentax

All 8 skills in this repo
  • Save Skill

    filedcom/opentax

    Helps users permanently set up the OpenTax skill on their AI platform so they don't have to load it every time.

    108 GitHub stars~724 tokensUpdated yesterday
    Auto-check passed
  • Tax Build

    filedcom/opentax

    Autonomous form builder. An agent skill from filedcom/opentax.

    108 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Tax Cases

    filedcom/opentax

    Generate realistic benchmark cases from IRS-published sources (VITA exercises, Pub 17 examples, MeF test cases).

    108 GitHub stars~923 tokensUpdated yesterday
    Auto-check passed
  • Tax Fix

    filedcom/opentax

    Autonomous bug-fix loop for any form:year. An agent skill from filedcom/opentax.

    108 GitHub stars~699 tokensUpdated yesterday
    Auto-check passed
  • Tax Preparer

    filedcom/opentax

    Tax preparer agent that uses the opentax CLI to prepare, validate, and export federal tax returns.

    108 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Tax Reviewer

    filedcom/opentax

    Tax return reviewer that audits a completed return against source documents using the opentax CLI.

    108 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed

Questions about Audit Harness

What does Audit Harness do?

Generic audit/fix loop. An agent skill from filedcom/opentax. Audit Harness is an agent skill from filedcom/opentax. Generic audit/fix loop.

How do I install Audit Harness in Claude Code?

Run `npx skills add filedcom/opentax --skill audit-harness -a claude-code`. Or copy the skill folder (.claude/skills/audit-harness in filedcom/opentax) into .claude/skills/audit-harness in your project. Claude Code loads it when a task matches its description.

How do I install Audit Harness in Codex?

Run `npx skills add filedcom/opentax --skill audit-harness -a codex`. Or copy the skill folder (.claude/skills/audit-harness in filedcom/opentax) into .agents/skills/audit-harness in your project. Codex loads it when a task matches its description.

Can I use Audit Harness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add filedcom/opentax --skill audit-harness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-harness, .gemini/skills/audit-harness, .github/skills/audit-harness and .opencode/skills/audit-harness in your project.

What does Audit Harness need to run?

Going by SKILL.md and its folder, Audit Harness needs the command-line tools its instructions call (git).

Does Audit Harness access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Harness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Harness use?

Audit Harness is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Harness use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Harness?

Skills that share tags, products or a category with Audit Harness: Agent Goal Planner (ruvnet/ruflo, 74k stars), Agent Code Goal Planner (ruvnet/ruflo, 74k stars), Planner (penpot/penpot, 61k stars) and Goals (codewhale-hq/Codewhale, 41k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Harness?

filedcom (a GitHub organization) maintains it in filedcom/opentax, which has 108 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 7, 2026.

Source: filedcom/opentax on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.