Agent skill

Audit Checklist Engine

by revfactory in revfactory/harness-100

A systematic checklist generation engine for compliance audits.

Apache-2.0Auto-check passedLegal & Compliance

Install Audit Checklist Engine

skills CLI
$ npx skills add revfactory/harness-100 --skill audit-checklist-engine -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 audit-checklist-engine --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/67-compliance-checker/.claude/skills/audit-checklist-engine .claude/skills/audit-checklist-engine && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-checklist-engine
GitHub stars
1.3k
Token cost
~1.3k tokens
SKILL.md length
346 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

A systematic checklist generation engine for compliance audits.

  • Tasks that involve Audit readiness
  • SKILL.md covers Audit Framework: 5-Level…, Domain-Specific Audit…, Audit Report Output Structure and Improvement Priority…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Checklist Engine is an agent skill from revfactory/harness-100. A systematic checklist generation engine for compliance audits. The 'status-auditor' and 'remediation-planner' agents must use this skill's audit framework and checklist templates when conducting status assessments and developing remediation plans. Used for 'audit checklist', 'compliance inspection form', 'compliance status assessment', etc. Note: Law mapping or full orchestration is outside the scope of this skill.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Audit readiness. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Audit readiness

Example prompts

  • “status-auditor”
  • “remediation-planner”
  • “audit checklist”
  • “/audit-checklist-engine”

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Checklist Engine loads about 1.3k tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 346 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 346 words, ~1,306 tokens.

Download SKILL.mdSave it as .claude/skills/audit-checklist-engine/SKILL.md (or your agent's skills folder).
name
audit-checklist-engine
description
A systematic checklist generation engine for compliance audits. The 'status-auditor' and 'remediation-planner' agents must use this skill's audit framework and checklist templates when conducting status assessments and developing remediation plans. Used for 'audit checklist', 'compliance inspection form', 'compliance status assessment', etc. Note: Law mapping or full orchestration is outside the scope of this skill.

Audit Checklist Engine — Compliance Audit Checklist Generation Engine

Converts regulatory obligations into practical inspection items and quantitatively assesses compliance levels.

Audit Framework: 5-Level Maturity Model

Compliance Maturity Levels
LevelNameDescriptionScore
L1UnawareUnaware that the obligation exists0
L2Aware/Non-CompliantAware but no action taken25
L3Partially CompliantSome actions completed, deficiencies exist50
L4Fully CompliantMinimum legal requirements met75
L5Best PracticeIndustry-leading level of operation100
Overall Compliance Rate Calculation
compliance_rate(%) = sum(item_maturity_score x weight) / sum(weight x 100) x 100

weight calculation:
  - Criminal punishment related: 5.0
  - Business suspension related: 4.0
  - High fines (100M+): 3.0
  - General fines: 2.0
  - Administrative guidance: 1.0

grades:
  A (90%+): Excellent — maintain
  B (70-89%): Good — improvement items exist
  C (50-69%): Insufficient — systematic improvement needed
  D (30-49%): Poor — urgent improvement needed
  F (under 30%): Critical — immediate correction required

Domain-Specific Audit Checklist Templates

Personal Data Protection Audit (20 items)

Collection and Use (6 items)

  • Legal basis mapping (consent/law/contract) completed for each collection item
  • Mandatory and optional consent separation implemented
  • Consent withdrawal procedure provided and equally convenient
  • Purpose limitation controls in place
  • Separate consent for sensitive and unique identification information
  • Legal guardian consent for minors under 14

Technical Safeguards (5 items)

  • Access authority management (principle of least privilege)
  • Access log retention and tamper prevention (6+ months)
  • Personal data encryption (SSL/TLS in transit, encryption at rest)
  • Backup and recovery system
  • Physical safeguards (locks, access control)

Administrative Safeguards (5 items)

  • Privacy policy published (website homepage)
  • Internal management plan established and implemented
  • Privacy protection training at least once per year
  • Privacy officer designated and published
  • Processor management and supervision

Destruction (4 items)

  • Prompt destruction upon retention period expiration
  • Destruction using irrecoverable methods
  • Destruction records maintained
  • Separate storage when other law retention obligations apply
Labor Law Audit (15 items)

Working Conditions (5 items)

  • Written employment contract issued
  • Work rules prepared and filed (10+ employees)
  • Statutory working hours compliance (52 hours per week)
  • Minimum wage or above paid
  • Annual paid leave granted and usage promoted

Safety and Health (5 items)

  • Safety and health management system established (50+ employees)
  • Risk assessment conducted
  • Safety and health training conducted
  • Industrial accident reporting
  • Work environment measurement (hazardous factors)

Other (5 items)

  • Workplace harassment prevention training
  • Sexual harassment prevention training (annual)
  • Mandatory employment of persons with disabilities (50+ employees)
  • Four major social insurance enrollment
  • Retirement benefit system established

Audit Report Output Structure

markdown
## Compliance Audit Report

**Target**: [Organization Name] | **Audit Domain**: [Domain] | **Audit Date**: [Date]
**Overall Compliance Rate**: [XX]% | **Grade**: [A/B/C/D/F]

### Results Summary by Domain
| Domain | Inspection Items | Compliant | Non-Compliant | Compliance Rate |
|--------|-----------------|-----------|---------------|----------------|
| Personal Data | 20 | 15 | 5 | 75% |

### Immediate Correction Required (Red)
1. [Item] — Current Status: [L?], Risk: [Violation sanctions]

### Improvement Recommended (Yellow)
1. [Item] — Current Status: [L?], Recommendation: [Action content]

### Best Practices (Green)
1. [Item] — L5 achieved

Improvement Priority Calculation Formula

priority_score = risk_impact(1-25) x (1 - current_compliance_rate) x cost_efficiency(1-5)

cost_efficiency:
  5: No cost/immediately possible (document preparation, training)
  4: Low cost/short-term (within 1 month)
  3: Medium cost/mid-term (within 3 months)
  2: High cost/long-term (6+ months)
  1: Major investment/system implementation

order: highest score first = quickly, at low cost, eliminating major risk

Notes

  • Reference structure from ISMS-P, ISO 27001, SOC2 frameworks
  • Detailed checklists: See references/checklist-templates.md

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/67-compliance-checker/.claude/skills/audit-checklist-engine of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Audit Checklist Engine next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Checklist Engine compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Checklist Engine this skillrevfactory/harness-1001.3k—~1.3kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~3.7kAutomated safety check: PassMIT
Fleet Triagegoogle-labs-code/jules-sdk136—~1.2kAutomated safety check: PassApache-2.0
PCI DSS Compliancewshobson/agents40k10 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    939 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Fleet Triage

    google-labs-code/jules-sdk

    Official

    Cognitive triage of fleet audit findings. An agent skill from google-labs-code/jules-sdk.

    136 GitHub stars~1.2k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • PCI DSS Compliance

    wshobson/agents

    Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

    40k GitHub starsUsed in 10 repos~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Audit Checklist Engine

What does Audit Checklist Engine do?

A systematic checklist generation engine for compliance audits. Audit Checklist Engine is an agent skill from revfactory/harness-100. A systematic checklist generation engine for compliance audits.

When should I use Audit Checklist Engine?

Audit Checklist Engine fits situations like: tasks that involve Audit readiness.

How do I install Audit Checklist Engine in Claude Code?

Run `npx skills add revfactory/harness-100 --skill audit-checklist-engine -a claude-code`. Or copy the skill folder (en/67-compliance-checker/.claude/skills/audit-checklist-engine in revfactory/harness-100) into .claude/skills/audit-checklist-engine in your project. Claude Code loads it when a task matches its description.

How do I install Audit Checklist Engine in Codex?

Run `npx skills add revfactory/harness-100 --skill audit-checklist-engine -a codex`. Or copy the skill folder (en/67-compliance-checker/.claude/skills/audit-checklist-engine in revfactory/harness-100) into .agents/skills/audit-checklist-engine in your project. Codex loads it when a task matches its description.

Can I use Audit Checklist Engine in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill audit-checklist-engine -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-checklist-engine, .gemini/skills/audit-checklist-engine, .github/skills/audit-checklist-engine and .opencode/skills/audit-checklist-engine in your project.

What does Audit Checklist Engine need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Checklist Engine is instructions for the agent only.

Does Audit Checklist Engine access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Checklist Engine safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Checklist Engine use?

Audit Checklist Engine is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Checklist Engine use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Checklist Engine?

Skills that share tags, products or a category with Audit Checklist Engine: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars), Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars) and Fleet Triage (google-labs-code/jules-sdk, 136 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Checklist Engine?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.