Agent skill

Finding Classification

by revfactory in revfactory/harness-100

Audit finding classification and reporting framework. An agent skill from revfactory/harness-100.

Apache-2.0Auto-check passedLegal & Compliance

Install Finding Classification

skills CLI
$ npx skills add revfactory/harness-100 --skill finding-classification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 finding-classification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/94-audit-report/.claude/skills/finding-classification .claude/skills/finding-classification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
finding-classification
GitHub stars
1.3k
Token cost
~1k tokens
SKILL.md length
230 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit finding classification and reporting framework. An agent skill from revfactory/harness-100.

  • Tasks that involve Audit readiness
  • SKILL.md covers Finding Rating System, Finding Report Structure, Root Cause Analysis and Recommendation Writing Rules, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Finding Classification is an agent skill from revfactory/harness-100. Audit finding classification and reporting framework. Referenced by findings-analyst and recommendation-writer agents when systematically classifying findings and writing improvement recommendations. Used for 'finding classification', 'audit reporting', 'improvement recommendations' requests. Note: legal sanction decisions and disciplinary procedures are out of scope.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Audit readiness. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Audit readiness

Example prompts

  • “finding classification”
  • “audit reporting”
  • “improvement recommendations”
  • “/finding-classification”

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Finding Classification loads about 1k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 230 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 230 words, ~1,018 tokens.

Download SKILL.mdSave it as .claude/skills/finding-classification/SKILL.md (or your agent's skills folder).
name
finding-classification
description
Audit finding classification and reporting framework. Referenced by findings-analyst and recommendation-writer agents when systematically classifying findings and writing improvement recommendations. Used for 'finding classification', 'audit reporting', 'improvement recommendations' requests. Note: legal sanction decisions and disciplinary procedures are out of scope.

Finding Classification — Finding Classification Framework

Enhances the finding classification and reporting capabilities of findings-analyst / recommendation-writer agents.

Finding Rating System

4-Level Classification
RatingNameDefinitionResponse Timeline
CriticalCriticalRisk of major loss/regulatory violationImmediate (7 days)
HighHighKey control failure, recurring30 days
MediumMediumPartial control deficiency, improvement needed90 days
LowLowEfficiency improvement, best practice suggestion180 days
Classification Decision Tree
Q1: Financial impact exceeds $100K or regulatory violation?
├── YES → Critical
└── NO → Q2: Is the control failure recurring?
    ├── YES → High
    └── NO → Q3: Could it worsen without corrective action?
        ├── YES → Medium
        └── NO → Low

Finding Report Structure

Finding Card
markdown
## Finding F-[Number]: [Title]

### Rating: [Critical/High/Medium/Low]

### Condition
[Current state discovered — facts only]

### Criteria
[Standard/regulation/policy that should apply]

### Cause
[Why the gap between criteria and condition occurred]

### Effect
[Current/potential impact — quantify where possible]

### Recommendation
[Specific improvement actions]

### Management Response
[Responsible department's response plan]
- Agreement: □ Agree □ Partially agree □ Disagree
- Corrective action: [Specific action]
- Owner: [Name/Title]
- Completion deadline: [YYYY-MM-DD]

Root Cause Analysis

Cause Categories
CategoryDescriptionExample
Policy/Procedure gapRegulation missing or insufficientApproval procedure not established
Personnel/CompetencyTraining or staffing deficiencyOwner not trained
System/ToolsIT control deficiencyAccess rights management gaps
Supervision/MonitoringManagement review absenceReconciliation not performed
CommunicationInformation transfer failurePolicy changes not shared

Recommendation Writing Rules

SMART Recommendations
Bad example: "Controls should be strengthened"
Good example: "By June 2025, implement dual approval 
             for all expenditures exceeding $50,000, 
             and verify compliance through monthly reconciliation"
Recommendation Priority Scoring
CriteriaWeight
Risk reduction effect40%
Implementation ease25%
Cost efficiency20%
Urgency15%

Implementation Tracking Ledger

FindingRatingCorrective ActionOwnerDeadlineStatusVerification Date
F-01Critical[Action][Name][Date]In progress-
F-02High[Action][Name][Date]Completed[Date]
Status Definitions
StatusDescription
Not startedBefore corrective action begins
In progressCorrective action underway
CompletedCorrection done, awaiting verification
VerifiedAuditor verification passed
ClosedFinalized
OverduePast deadline, incomplete

Quality Checklist

ItemCriteria
4C structureCondition, Criteria, Cause, Effect
Rating consistencyDecision tree applied
QuantificationImpact expressed in amounts/counts
SMART recommendationsSpecific + Measurable + Time-bound
Management responseAgreement/disagreement recorded
Tracking5-stage status management

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/94-audit-report/.claude/skills/finding-classification of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Finding Classification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Finding Classification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Finding Classification this skillrevfactory/harness-1001.3k—~1kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~3.7kAutomated safety check: PassMIT
Fleet Triagegoogle-labs-code/jules-sdk136—~1.2kAutomated safety check: PassApache-2.0
PCI DSS Compliancewshobson/agents40k10 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    939 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Fleet Triage

    google-labs-code/jules-sdk

    Official

    Cognitive triage of fleet audit findings. An agent skill from google-labs-code/jules-sdk.

    136 GitHub stars~1.2k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • PCI DSS Compliance

    wshobson/agents

    Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

    40k GitHub starsUsed in 10 repos~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Finding Classification

What does Finding Classification do?

Audit finding classification and reporting framework. An agent skill from revfactory/harness-100. Finding Classification is an agent skill from revfactory/harness-100. Audit finding classification and reporting framework.

When should I use Finding Classification?

Finding Classification fits situations like: tasks that involve Audit readiness.

How do I install Finding Classification in Claude Code?

Run `npx skills add revfactory/harness-100 --skill finding-classification -a claude-code`. Or copy the skill folder (en/94-audit-report/.claude/skills/finding-classification in revfactory/harness-100) into .claude/skills/finding-classification in your project. Claude Code loads it when a task matches its description.

How do I install Finding Classification in Codex?

Run `npx skills add revfactory/harness-100 --skill finding-classification -a codex`. Or copy the skill folder (en/94-audit-report/.claude/skills/finding-classification in revfactory/harness-100) into .agents/skills/finding-classification in your project. Codex loads it when a task matches its description.

Can I use Finding Classification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill finding-classification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/finding-classification, .gemini/skills/finding-classification, .github/skills/finding-classification and .opencode/skills/finding-classification in your project.

What does Finding Classification need to run?

SKILL.md names no scripts, command-line tools or credentials: Finding Classification is instructions for the agent only.

Does Finding Classification access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Finding Classification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Finding Classification use?

Finding Classification is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Finding Classification use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Finding Classification?

Skills that share tags, products or a category with Finding Classification: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars), Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars) and Fleet Triage (google-labs-code/jules-sdk, 136 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Finding Classification?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.