Agent skill

Internal Control Framework

by revfactory in revfactory/harness-100

Internal control framework guide. An agent skill from revfactory/harness-100.

Apache-2.0Auto-check passedLegal & Compliance

Install Internal Control Framework

skills CLI
$ npx skills add revfactory/harness-100 --skill internal-control-framework -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 internal-control-framework --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/94-audit-report/.claude/skills/internal-control-framework .claude/skills/internal-control-framework && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
internal-control-framework
GitHub stars
1.3k
Token cost
~889 tokens
SKILL.md length
195 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

Internal control framework guide. An agent skill from revfactory/harness-100.

  • Tasks that involve Audit readiness
  • SKILL.md covers COSO Internal Control Framework, Audit Scope Design Framework, Checklist Design Patterns and Quality Checklist
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Legal research

What it does

Internal Control Framework is an agent skill from revfactory/harness-100. Internal control framework guide. Referenced by scope-designer and checklist-builder agents when designing audit scope and control items. Used for 'COSO', 'internal controls', 'control testing' requests. Note: external audit representation and legal opinion preparation are out of scope.

Its SKILL.md is about 890 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Audit readiness and Legal research. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Audit readiness
  • Tasks that involve Legal research

Example prompts

  • “internal controls”
  • “control testing”
  • “/internal-control-framework”

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Internal Control Framework loads about 889 tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 195 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~889

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 195 words, ~889 tokens.

Download SKILL.mdSave it as .claude/skills/internal-control-framework/SKILL.md (or your agent's skills folder).
name
internal-control-framework
description
Internal control framework guide. Referenced by scope-designer and checklist-builder agents when designing audit scope and control items. Used for 'COSO', 'internal controls', 'control testing' requests. Note: external audit representation and legal opinion preparation are out of scope.

Internal Control Framework

Enhances the audit design capabilities of scope-designer / checklist-builder agents.

COSO Internal Control Framework

5 Components
ComponentDescriptionAudit Points
Control EnvironmentOrganizational culture, ethics, competenceCode of ethics, segregation of duties, training
Risk AssessmentIdentification/analysis of risks to objectivesRisk assessment process, documentation
Control ActivitiesPolicies/procedures responding to risksApprovals, verification, physical controls
Information/CommunicationTimely delivery of necessary informationReporting structure, IT controls
MonitoringContinuous evaluation of control effectivenessSelf-assessments, internal audit
Control Types
TypeDescriptionExamples
PreventiveBlock before occurrenceApproval procedures, access restrictions, training
DetectiveDiscover after occurrenceAudit logs, reconciliation, anomaly detection
CorrectiveRectify after discoveryCorrective actions, rollback, recovery
Control Testing Methods
MethodDescriptionBest For
InquiryInterview the ownerInitial understanding, process mapping
ObservationObserve actual executionField control verification
InspectionReview documents/recordsEvidence verification, approval records
ReperformanceExecute the control procedureDirect verification of control effectiveness

Audit Scope Design Framework

Risk-Based Audit Approach
1. Identify audit target processes
2. Assess inherent risk (amount, complexity, change)
3. Assess control risk (control design, operating effectiveness)
4. Residual risk = Inherent risk × Control risk
5. Prioritize audit by highest residual risk
Audit Scope Definition Template
markdown
## Audit Scope

### In-Scope
- Period: [YYYY-MM-DD to YYYY-MM-DD]
- Target: [Department/Process/System]
- Criteria: [Regulations/Policies/Laws]

### Out-of-Scope
- [Excluded items and rationale]

### Audit Criteria
| Criteria | Source |
|----------|--------|
| [Criteria 1] | [Internal policy/Law] |
| [Criteria 2] | [Industry standard] |

Checklist Design Patterns

Control Item Card
markdown
## Control Item: [ID]-[Item Name]

- Category: [COSO component]
- Type: [Preventive/Detective/Corrective]
- Owner: [Department/Role]
- Frequency: [Daily/Weekly/Monthly/Quarterly/Annual]

### Control Description
[Specific control activity description]

### Test Procedure
1. [Test step 1]
2. [Test step 2]
3. [Verification criteria]

### Evidence
- [Required evidence list]

### Determination Criteria
- Effective: [Criteria]
- Partially effective: [Criteria]
- Ineffective: [Criteria]

Quality Checklist

ItemCriteria
COSO coverage5 components reviewed
Risk-basedResidual risk-based prioritization
Control typesPreventive/detective/corrective balance
Test methods2+ methods per item
EvidenceRequired evidence specified per test
Determination3-level determination criteria

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/94-audit-report/.claude/skills/internal-control-framework of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Internal Control Framework next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Internal Control Framework compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Internal Control Framework this skillrevfactory/harness-1001.3k—~889Automated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Tw Legal RAGaa0101181514/tw-legal-rag327—~580Automated safety check: PassCustom licence
Design Award SearchSeanJ1ang/design-judge-skills712—~3kAutomated safety check: PassApache-2.0
China Lawyer AnalystCSlawyer1985/china-lawyer-analyst194—~3.3kAutomated safety check: PassNone
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Tw Legal RAG

    aa0101181514/tw-legal-rag

    Retrieve real Taiwan court judgments with verifiable citations before answering any question about Taiwan law or case law.

    327 GitHub stars~580 tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Design Award Search

    SeanJ1ang/design-judge-skills

    Find and verify award-winning designs in the same or adjacent functional category through eight explicit relevance dimensions: problem and user, core function, sensing technology, intervention…

    712 GitHub stars~3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • China Lawyer Analyst

    CSlawyer1985/china-lawyer-analyst

    通过中国法律视角分析事件,运用成文法解释、指导案例参照、请求权基础分析等方法, 理解权利义务、评估责任风险、识别法律依据并推荐合规策略。

    194 GitHub stars~3.3k tokensUpdated 8 mo ago
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Billing And Litigation Budget

    THUYRan/Legal-Skills-Chinese

    A skill your agent uses when the user needs to track or manage attorney hours, expert fees, and investigation costs; control litigation spend; or prepare timesheets or expense statements for clients.

    868 GitHub stars~5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Internal Control Framework

What does Internal Control Framework do?

Internal control framework guide. An agent skill from revfactory/harness-100. Internal Control Framework is an agent skill from revfactory/harness-100. Internal control framework guide.

When should I use Internal Control Framework?

Internal Control Framework fits situations like: tasks that involve Audit readiness; tasks that involve Legal research.

How do I install Internal Control Framework in Claude Code?

Run `npx skills add revfactory/harness-100 --skill internal-control-framework -a claude-code`. Or copy the skill folder (en/94-audit-report/.claude/skills/internal-control-framework in revfactory/harness-100) into .claude/skills/internal-control-framework in your project. Claude Code loads it when a task matches its description.

How do I install Internal Control Framework in Codex?

Run `npx skills add revfactory/harness-100 --skill internal-control-framework -a codex`. Or copy the skill folder (en/94-audit-report/.claude/skills/internal-control-framework in revfactory/harness-100) into .agents/skills/internal-control-framework in your project. Codex loads it when a task matches its description.

Can I use Internal Control Framework in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill internal-control-framework -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/internal-control-framework, .gemini/skills/internal-control-framework, .github/skills/internal-control-framework and .opencode/skills/internal-control-framework in your project.

What does Internal Control Framework need to run?

SKILL.md names no scripts, command-line tools or credentials: Internal Control Framework is instructions for the agent only.

Does Internal Control Framework access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Internal Control Framework safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Internal Control Framework use?

Internal Control Framework is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Internal Control Framework use?

About 889 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Internal Control Framework?

Skills that share tags, products or a category with Internal Control Framework: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Tw Legal RAG (aa0101181514/tw-legal-rag, 327 stars), Design Award Search (SeanJ1ang/design-judge-skills, 712 stars) and China Lawyer Analyst (CSlawyer1985/china-lawyer-analyst, 194 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Internal Control Framework?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.