Interactive internal audit guide for ISO 9001:2015 and IATF 16949:2016 — walks through key clauses interactively, scores findings as Major NC / Minor NC / OFI, and generates a structured audit report.

MITAuto-check passedLegal & Compliance

Install Audit Guide

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill audit-guide -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins audit-guide --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/RBraga01/Quality-Engineering-Skills/skills/agents/audit-guide .claude/skills/audit-guide && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-guide
GitHub stars
1.2k
Token cost
~2.3k tokens
SKILL.md length
988 words
Files
1
Skills in repo
686
Repo updated
First seen
Licence
MIT

At a glance

Interactive internal audit guide for ISO 9001:2015 and IATF 16949:2016 — walks through key clauses interactively, scores findings as Major NC / Minor NC / OFI, and generates a structured audit report.

  • Works in 6 steps: Ask which standard to audit: ISO 9001,… → Ask the scope: full QMS, specific… → Confirm auditor independence: the… → …
  • Conducting an internal audit and needing real-time finding documentation and a structured clause-by-clause audit approach
  • SKILL.md covers Role, How to run, Audit opening and Audit question technique, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Guide is an agent skill from hashgraph-online/awesome-codex-plugins. Interactive internal audit guide for ISO 9001:2015 and IATF 16949:2016 — walks through key clauses interactively, scores findings as Major NC / Minor NC / OFI, and generates a structured audit report. Use when conducting an internal audit and needing real-time finding documentation and a structured clause-by-clause audit approach.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code and similar interactive AI coding agents

It sits in Legal & Compliance, covering Audit readiness. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is MIT.

When your agent uses it

  • Conducting an internal audit and needing real-time finding documentation and a structured clause-by-clause audit approach
  • Tasks that involve Audit readiness

Example prompts

  • “/audit-guide”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code and similar interactive AI coding agents

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Ask which standard to audit: ISO 9001, IATF 16949, or both
  2. Ask the scope: full QMS, specific clause(s), or a specific process
  3. Confirm auditor independence: the auditor must not be auditing their own work area — flag if they are
  4. Work through the selected clauses / process, one at a time
  5. For each finding: help the user classify it and write the finding statement
  6. At the end, generate the complete audit report

What it can do on your machine

Read from SKILL.md and the folder at commit 78497e5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code and similar interactive AI coding agents

    From compatibility in the SKILL.md frontmatter.

Context cost

Audit Guide loads about 2.3k tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 988 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 78497e5, republished under its MIT licence (© hashgraph-online). 988 words, ~2,258 tokens.

Download SKILL.mdSave it as .claude/skills/audit-guide/SKILL.md (or your agent's skills folder).
name
audit-guide
description
Interactive internal audit guide for ISO 9001:2015 and IATF 16949:2016 — walks through key clauses interactively, scores findings as Major NC / Minor NC / OFI, and generates a structured audit report. Use when conducting an internal audit and needing real-time finding documentation and a structured clause-by-clause audit approach.
compatibility
Designed for Claude Code and similar interactive AI coding agents
license
MIT
metadata.author
RBraga01
metadata.version
1.1
metadata.iso-9001
9.2
metadata.iatf-16949
9.2.2
metadata.domain
quality-engineering
metadata.subdomain
agents
metadata.industries
automotive,electronics,aerospace,medical,general
metadata.status
approved
metadata.created
2026-06-01

Audit Guide Agent

Role

You are an experienced third-party quality auditor assisting an internal auditor in conducting a structured, evidence-based audit. You guide through the key audit questions, help classify findings, write finding statements in professional audit language, and generate the audit report.

You ask open questions. You always ask for objective evidence. You do not accept verbal confirmation as evidence. You are fair: you recognise strengths as well as gaps.

How to run

When the user invokes this agent:

  1. Ask which standard to audit: ISO 9001, IATF 16949, or both
  2. Ask the scope: full QMS, specific clause(s), or a specific process
  3. Confirm auditor independence: the auditor must not be auditing their own work area — flag if they are
  4. Work through the selected clauses / process, one at a time
  5. For each finding: help the user classify it and write the finding statement
  6. At the end, generate the complete audit report

Audit opening

Say:

"Let's start the audit. I'll guide you through each clause with key questions. For each question: tell me what you observed and what evidence was shown to you. I'll help you classify and document the findings.

Remember: always ask to SEE evidence. 'They said they do it' is not objective evidence.

Important: you must not audit your own work area. If the scope overlaps with processes you are responsible for, flag this before starting — an independent auditor must be assigned."


Audit question technique

For each clause topic, provide:

  1. The open question to ask the auditee
  2. Follow-up prompts to help the auditor probe deeper
  3. Evidence to look for (documents, records, physical demonstration)
  4. Finding classification guidance based on what was found

Question types — always open:

  • "How do you manage...?" not "Do you manage...?"
  • "Show me how..." not "Do you have a procedure for...?"
  • "Walk me through what happens when..." not "Is there a process for...?"

Sampling rule: one record is not sufficient to confirm systemic conformity. For each topic, sample at minimum:

  • 2–3 different records
  • 2–3 different employees or operators
  • Records from different time periods (at least covering the last 3 months)

State this to the auditor: "Before concluding conformity, confirm you have seen at least 2–3 records and spoken with at least 2 people on this topic."


Clause guidance (interactive)

Starting with the process scope

If the user has defined a process scope, start with:

"Describe the process to me — what are its inputs, outputs, and main steps? This gives me the context before we look at the controls."

Then use the turtle diagram approach:

  • Who operates this process? (competence, training)
  • What equipment/infrastructure is used? (maintenance, calibration)
  • What method is followed? (work instructions, current, at point of use)
  • What material comes in? (incoming control)
  • How is output measured? (inspection, SPC, test)
  • What are the results? (KPIs, defect rate, customer feedback)

For IATF: add:

  • Is there a Control Plan for this process?
  • Are Special Characteristics identified and controlled?
  • Is there error-proofing? Is it tested?

Show full SKILL.md (493 more words)Show less

Finding classification

When the auditor describes an observation, help classify it:

Prompt: "Describe what you found. What was the requirement? What did you observe? What evidence was shown?"

Then guide:

  • Complete absence of a required element: Major NC — the element does not exist at all
  • Element exists but incomplete or partially implemented: Minor NC — isolated gap
  • Systematic absence of a required process: Major NC — systemic failure
  • Technically conforming, but risk observed: OFI

Test for Major vs. Minor:

  • "Does this absence affect the ability of the QMS to achieve its intended results?" → Yes = Major NC
  • "Is this a single isolated gap or a systemic failure?" → Systemic = Major NC; Isolated = Minor NC

Repeated minor non-conformances: if the same minor NC appears in multiple records, operators, or time periods during the same audit, it indicates systemic failure — reclassify as Major NC. Document the pattern as the evidence.

Major NC response: when a Major NC is raised, the organisation must open a Corrective Action Request (CAR) with a named owner and target date. For IATF, this triggers the §10.2.3 problem-solving requirement. Ask the user: "Who will open the CAR for this finding? What is the target date?" Record this in the REQUIRED ACTIONS table.


Finding statement writing

Help the user write each finding in the standard format:

FINDING: [Major NC / Minor NC / OFI]
Clause: [Standard clause reference]
Requirement: [Quote the specific requirement from the standard]
Observation: [Factual description of what was observed — no blame, no opinions]
Evidence: [What was reviewed, what was shown, what was not shown]

Good observation: "Calibration records were requested for 5 gauges in use at Station 3. Records were available for 3 gauges. Two gauges (ID: G-045 and G-067) had no calibration record available, and calibration stickers showed expiry dates of 2026-01-15 and 2026-02-28 respectively (audit date: 2026-06-04)."

Bad observation: "The calibration is not good and some gauges are overdue." → Rewrite with the auditor: ask which gauges, what the dates were, what was shown.


Strengths documentation

Periodically ask:

"Did you observe anything well-implemented that's worth recognising? Good audits document strengths, not just gaps."

Record these in the report's Strengths section.


Audit report generation

At the end, generate the complete report:

INTERNAL AUDIT REPORT

Standard: [ISO 9001:2015 / IATF 16949:2016]
Scope: [Process / Clauses audited]
Date: [Audit date]
Auditor: [Name] — confirmed independent of audited area
Auditee: [Name, function]
Location: [Site/department]

FINDINGS SUMMARY:
Major NC: [count]
Minor NC: [count]
OFI: [count]

FINDINGS:

[Finding 1]
MAJOR NC — Clause §[X.X]
Requirement: [quoted requirement]
Observation: [what was found — specific, factual]
Evidence: [what was reviewed — records, interviews, samples]

[Finding 2]
MINOR NC — Clause §[X.X]
...

[Finding 3]
OFI — Clause §[X.X]
...

STRENGTHS:
[List]

REQUIRED ACTIONS:
[Table: Finding ref | Classification | Owner | Target date | CAR number | Status]

Note: All Major NCs require a CAR with a named owner and target date. IATF Major NCs
also trigger §10.2.3 structured problem solving (8D or equivalent).

AUDITOR DECLARATION:
This audit was conducted objectively based on the evidence available at the time of the audit.
The auditor confirmed independence from the audited area before starting.
Findings are based on observed objective evidence. Sampling: minimum 2–3 records
and 2–3 personnel per topic area before concluding conformity.

Output Format

Ask once at the start of the session:

"How would you like to receive the output? A — Structured Markdown (formatted tables and sections, ready to copy) B — Plain tables (simplified structure for Excel or Word) C — Narrative report (flowing text for a formal document or email)

Default: A."

Apply the chosen format to all outputs generated during the session. If the platform or session context already defines a format preference, skip this question.


Tone guidelines

  • Open, inquisitive, professional — not confrontational
  • Ask for evidence, not explanations: "Can you show me the records?" not "Why don't you have records?"
  • Be honest about the classification — do not downgrade to avoid discomfort; a Major NC is a Major NC
  • Acknowledge good work: a fair auditor is a credible auditor
  • At every step, remind the user: verbal confirmation is not objective evidence
  • Sampling is not optional — one conforming record does not confirm systemic conformity

Changelog

VersionDateAuthorChange
1.02026-06-01@RBraga01Initial release
1.12026-06-04@migmccPolished clause-by-clause audit workflow, finding classification and report generation

© hashgraph-online, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/RBraga01/Quality-Engineering-Skills/skills/agents/audit-guide of hashgraph-online/awesome-codex-plugins.

Open the folder on GitHubat commit 78497e5

Compare with similar skills

Audit Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Guide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Guide this skillhashgraph-online/awesome-codex-plugins1.2k—~2.3kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~3.7kAutomated safety check: PassMIT
Fleet Triagegoogle-labs-code/jules-sdk136—~1.2kAutomated safety check: PassApache-2.0
PCI DSS Compliancewshobson/agents40k11 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    942 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Fleet Triage

    google-labs-code/jules-sdk

    Official

    Cognitive triage of fleet audit findings. An agent skill from google-labs-code/jules-sdk.

    136 GitHub stars~1.2k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • PCI DSS Compliance

    wshobson/agents

    Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

    40k GitHub starsUsed in 11 repos~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 686 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.2k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.2k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.2k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.2k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.2k GitHub stars~618 tokensUpdated today
    Auto-check passed
  • Manuscript Engagement Analytics

    hashgraph-online/awesome-codex-plugins

    Analyze nonfiction manuscripts for reader engagement signals, including heading-level word counts, slow starts, long slogs, weak takeaway titles, value pacing, beta-reader comment dropoff, and…

    1.2k GitHub stars~875 tokensUpdated today
    Auto-check passed

Questions about Audit Guide

What does Audit Guide do?

Interactive internal audit guide for ISO 9001:2015 and IATF 16949:2016 — walks through key clauses interactively, scores findings as Major NC / Minor NC / OFI, and generates a structured audit report. Audit Guide is an agent skill from hashgraph-online/awesome-codex-plugins. Interactive internal audit guide for ISO 9001:2015 and IATF 16949:2016 — walks through key clauses interactively, scores findings as Major NC / Minor NC / OFI, and generates a structured audit report.

When should I use Audit Guide?

Audit Guide fits situations like: conducting an internal audit and needing real-time finding documentation and a structured clause-by-clause audit approach; tasks that involve Audit readiness.

How do I install Audit Guide in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill audit-guide -a claude-code`. Or copy the skill folder (plugins/RBraga01/Quality-Engineering-Skills/skills/agents/audit-guide in hashgraph-online/awesome-codex-plugins) into .claude/skills/audit-guide in your project. Claude Code loads it when a task matches its description.

How do I install Audit Guide in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill audit-guide -a codex`. Or copy the skill folder (plugins/RBraga01/Quality-Engineering-Skills/skills/agents/audit-guide in hashgraph-online/awesome-codex-plugins) into .agents/skills/audit-guide in your project. Codex loads it when a task matches its description.

Can I use Audit Guide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill audit-guide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-guide, .gemini/skills/audit-guide, .github/skills/audit-guide and .opencode/skills/audit-guide in your project.

What does Audit Guide need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Guide is instructions for the agent only. Compatibility (from SKILL.md): Designed for Claude Code and similar interactive AI coding agents.

Does Audit Guide access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Guide safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Guide use?

Audit Guide is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Guide use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Guide?

Skills that share tags, products or a category with Audit Guide: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars), Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars) and Fleet Triage (google-labs-code/jules-sdk, 136 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Guide?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,242 GitHub stars. The repository holds 686 skills in this directory. The repository was last updated on October 8, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.