Agent skill

Omh Internal Audit

by rlaope in rlaope/oh-my-hermes

[omh] Testing an internal control -- SOX, ICFR or ITGC: define the population and the sample, name the evidence that proves each item, re-perform the control, and grade any deficiency from stated…

MITAuto-check passedLegal & Compliance

Install Omh Internal Audit

skills CLI
$ npx skills add rlaope/oh-my-hermes --skill omh-internal-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rlaope/oh-my-hermes omh-internal-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rlaope/oh-my-hermes.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/omh-internal-audit .claude/skills/omh-internal-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
omh-internal-audit
GitHub stars
3.2k
Token cost
~2.4k tokens
SKILL.md length
1,204 words
Files
2 (incl. references)
Skills in repo
143
Repo updated
First seen
Licence
MIT

At a glance

[omh] Testing an internal control -- SOX, ICFR or ITGC: define the population and the sample, name the evidence that proves each item, re-perform the control, and grade any deficiency from stated…

  • The user says: internal-audit
  • SKILL.md covers Why This Exists, First Steps, Do Not Use When and Examples, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Internal control

What it does

Omh Internal Audit is an agent skill from rlaope/oh-my-hermes. [omh] Testing an internal control -- SOX, ICFR or ITGC: define the population and the sample, name the evidence that proves each item, re-perform the control, and grade any deficiency from stated likelihood, magnitude and compensating-control criteria, never by assertion. Use when the user says: internal-audit, internal audit, internal control, internal controls, internal control audit, control testing, test of controls, tests of controls.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/control-audit-method.md`).

It sits in Legal & Compliance, covering Audit readiness. The repository describes itself as: All in one plugin for Hermes Agent ⚚ the coding intelligence, a long-term memory system and model optimized workflow packages. The licence is MIT.

When your agent uses it

  • The user says: internal-audit
  • Internal control
  • Internal controls
  • Internal control audit

Example prompts

  • “/omh-internal-audit”

What it can do on your machine

Read from SKILL.md and the folder at commit 7cd0d02. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Omh Internal Audit loads about 2.4k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 1,204 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rlaope/oh-my-hermes at commit 7cd0d02, republished under its MIT licence (© rlaope). 1,204 words, ~2,417 tokens.

Download SKILL.mdSave it as .claude/skills/omh-internal-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
omh-internal-audit
description
[omh] Testing an internal control -- SOX, ICFR or ITGC: define the population and the sample, name the evidence that proves each item, re-perform the control, and grade any deficiency from stated likelihood, magnitude and compensating-control criteria, never by assertion. Use when the user says: internal-audit, internal audit, internal control, internal controls, internal control audit, control testing, test of controls, tests of controls.

Internal Audit

This is a Hermes-native internal-audit workflow skill.

Why This Exists

internal-audit exists because control-testing methodology had no owner: finance-analysis reports figures and names control exceptions, tech-debt-audit audits code, and production-audit audits a release, while population, sampling, re-performance, and deficiency severity had nothing that derived a grade from criteria.

First Steps

  • Ask what the control is meant to prevent or detect, and over which population and period it operates.
  • Ask for the sampling guidance and the materiality threshold before sizing any sample or grading anything.

Do Not Use When

  • The ask is the month's figures, a budget variance, or the close itself; use finance-analysis.
  • The ask is reading a contract or a regulation for legal risk; use legal-compliance-review.
  • The ask is whether a service is ready to launch; use production-audit.
  • The ask is ranking a codebase's debt; use tech-debt-audit.

Examples

Good example:

  • Prompt: we need to test the quarterly access review control for sox and grade what we find
  • Expected behavior: Define the population of quarterly reviews for the period and check its completeness, size the sample from the quarterly frequency, request the signed review and the removal tickets per item, re-perform the comparison of access lists, and grade any deviation from stated likelihood, magnitude and compensating controls.
  • Why: A grade that is not derived from criteria cannot be defended to an external auditor.

Bad example:

  • Prompt: the owner says the control worked, just mark it effective
  • Expected behavior: Refuse to conclude on inquiry alone: sample the population, obtain the evidence, and re-perform before any conclusion.
  • Why: An owner's statement is the weakest evidence a control test can hold.

Completion Checklist

  • The control, its population, and the completeness check are stated.
  • The sample size is derived from stated frequency, confidence, and tolerable rate, and the selection can be redrawn.
  • Each sample item names the evidence obtained, not described.
  • Each item's re-performance result cites its evidence.
  • The severity grade shows every criterion, or is withheld with the missing one named, and OMH signed off nothing.

Recovery Notes

  • If the population cannot be shown complete, stop and name the completeness test before any sampling.
  • If materiality or the compensating controls are not stated, report the deviations and withhold the grade.

Workflow Lane

  • Current lane: Research and company ops (product-docs, source-finder, web-research, research, model-optimization, inference-serving, model-finetuning, research-brief, +20 more) - research, signals, ops, and briefings.
  • If intent belongs to another lane, hand back to oh-my-hermes or name the adjacent workflow.
  • Shared product, routing, compatibility, and evidence rules: omh-routing/references/skill-common-rail.md.

Use When

Use when an internal control is being tested or a control failure graded: SOX or ICFR testing, IT general controls, a control owner's evidence, a sample of transactions, re-performing a reconciliation or an approval, or deciding whether a deficiency is a significant deficiency or a material weakness. The output is the control and its population, the sample design, the evidence per item, the re-performance record, and a severity grade derived from stated criteria; OMH reads no ledger and tests nothing itself.

Strong routing signals: `internal-audit`, `internal audit`, `internal control`, `internal controls`, `internal control audit`, `control testing`, `test of controls`, `tests of controls`, `sox`, `sox 404`, `sox testing`, `sox control`, `icfr`, `itgc`, `itgcs`, `material weakness`, `significant deficiency`, `control deficiency`, `deficiency severity`, `re-performance`, `reperformance`, `reperform`, `reperform the control`, `audit sampling`, `attribute sampling`, `control population`, `audit evidence`, `audit workpaper`, `segregation of duties`

Catalog Metadata

Category: review Phase: internal-audit Hermes role: reviewer Quality tier: criteria-derived-severity Reasoning demand: standard

Quality bar:

  • Define the population and check its completeness before designing the sample.
  • Load references/control-audit-method.md for the sample-size table, the evidence hierarchy, and the severity decision table instead of recalling them.
  • Re-perform the control independently; do not re-read the owner's conclusion.
  • Show every criterion beside the severity grade so a reviewer can re-derive it.
  • Keep planned, sampled, evidenced, re-performed, and graded as separate states for every item.

Handoff policy:

Keep the control definition, sample design, evidence requests, re-performance record, and severity grade in Hermes. Populations, sample items, evidence, and re-performance results are recorded only from auditor, control owner, or operator observed output; OMH never queries a ledger or system of record and never signs off a control.

Required inputs:

  • the control: its objective, owner, frequency, and the risk or assertion it addresses
  • the population it operates over: the period, the source system, and how completeness was checked
  • the firm's or team's sampling guidance, or the confidence and tolerable deviation rate to use
  • the materiality threshold and the compensating controls that exist
  • the evidence each sample item actually produced, as observed documents, logs, or approvals
Show full SKILL.md (449 more words)Show less

Expected outputs:

  • control_under_test/v1
  • sample_design/v1
  • evidence_request/v1
  • reperformance_record/v1
  • deficiency_severity_grade/v1

Artifact expectations:

  • control_under_test/v1 names the control's objective, owner, frequency, and risk, and the population with its period, source, and completeness check
  • sample_design/v1 states the sampling method and derives the sample size from the control's frequency and the stated confidence and tolerable deviation rate, with a selection record that lets someone draw the same items again
  • evidence_request/v1 names, per sample item, the document, log, or approval that proves the control operated and who provides it, and separates evidence obtained from evidence described
  • reperformance_record/v1 records, per sample item, the independent re-performance of the control and its result -- operated, deviation, or not testable -- with the evidence reference
  • deficiency_severity_grade/v1 derives control deficiency, significant deficiency, or material weakness from stated likelihood, magnitude against stated materiality, and compensating controls, shows each criterion's value and source, and withholds the grade when a criterion is missing

Safety rules:

  • Derive every severity grade from stated criteria -- likelihood, magnitude against a stated materiality, and compensating controls; with a criterion missing, withhold the grade rather than assert one.
  • Check the population's completeness before sampling from it; a sample from an incomplete population says nothing about the items left out.
  • Record evidence obtained, not evidence described; a control owner's explanation is inquiry, not proof the control operated.
  • Never drop a deviation found in the sample because it was explained; record it and evaluate it against the tolerable rate.
  • OMH reads no ledger, tests no control, and signs off nothing; every population, sample, and result comes from observed output or is marked unverified.

Runtime Evidence

Preferred harness for this skill: critic.

sh
omh runtime record --skill internal-audit --harness critic --status started

Record observed delegation results; otherwise return not_available or not_observed. Prepared OMH routing is not execution, review, CI, merge-readiness, or merge evidence.

  • Treat wrapper memory/context summaries as advisory local context, not proof of opaque Hermes memory reads or changes. Preserve workflow intent and stop conditions; verify before claiming completion. Reply in the user's own words and the host's own voice: its SOUL.md persona owns reply language, tone, speech level, and sentence endings, progress updates included (where it sets no language, use the one the user wrote in), and OMH shapes structure and content only; OMH's record terms (surface, lane, wrapper, handoff, evidence boundary, not_observed) stay in records and tool calls, never in the sentence the user reads unless they ask about one; and when a stop condition or a decision the user owns ends the turn, offer the next action as a question rather than declaring what will not be done.

Use Hermes-native subagent/delegation features when available: native subagents -> Hermes delegation when available, otherwise sequential lanes.

Shared product, compatibility, topology, memory, harness, and execution rules: omh-routing/references/skill-common-rail.md. Load it when applicable; otherwise name an unavailable capability.

© rlaope, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/omh-internal-audit of rlaope/oh-my-hermes.

  • SKILL.md
  • references/control-audit-method.md

Open the folder on GitHubat commit 7cd0d02

Compare with similar skills

Omh Internal Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Omh Internal Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Omh Internal Audit this skillrlaope/oh-my-hermes3.2k—~2.4kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.7kAutomated safety check: PassMIT
Fleet Triagegoogle-labs-code/jules-sdk137—~1.2kAutomated safety check: PassApache-2.0
PCI DSS Compliancewshobson/agents40k11 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Fleet Triage

    google-labs-code/jules-sdk

    Official

    Cognitive triage of fleet audit findings. An agent skill from google-labs-code/jules-sdk.

    137 GitHub stars~1.2k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • PCI DSS Compliance

    wshobson/agents

    Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

    40k GitHub starsUsed in 11 repos~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 6 days ago
    Legal & ComplianceAuto-check passed

More from rlaope/oh-my-hermes

All 143 skills in this repo
  • Omh Accessibility Audit

    rlaope/oh-my-hermes

    [omh] Screen-reader or keyboard accessibility gaps: prepare WCAG, keyboard, focus, screen-reader, target-size, and reflow evidence gates for UI surfaces.

    3.2k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Omh Agent Evaluation

    rlaope/oh-my-hermes

    [omh] Choosing between coding agents on evidence: compare executor or agent choices on reproducible tasks using quality, cost, time, tool, and evidence metrics.

    3.2k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Omh Agent Instructions

    rlaope/oh-my-hermes

    [omh] Agent instruction file for a repo -- AGENTS.md, CLAUDE.md, a Cursor rule: write or update what an agent cannot derive from the code, inside a marked region, with every command verified or…

    3.2k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Omh Agent Ops Review

    rlaope/oh-my-hermes

    [omh] AI agent progress for managers: help managers inspect AI-agent progress, blockers, quality gates, and throughput levers.

    3.2k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Omh AI Slop Cleaner

    rlaope/oh-my-hermes

    [omh] Messy or AI-generated code to clean up: delete AI-generated slop, dead code, and duplication while observable behavior stays identical.

    3.2k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Omh App Debugging

    rlaope/oh-my-hermes

    [omh] Application code misbehaves -- a wrong value, a flaky test, a lost update: reproduce it first, form competing hypotheses, discriminate them with the cheapest observation, and only then fix the…

    3.2k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Questions about Omh Internal Audit

What does Omh Internal Audit do?

[omh] Testing an internal control -- SOX, ICFR or ITGC: define the population and the sample, name the evidence that proves each item, re-perform the control, and grade any deficiency from stated…. Omh Internal Audit is an agent skill from rlaope/oh-my-hermes. [omh] Testing an internal control -- SOX, ICFR or ITGC: define the population and the sample, name the evidence that proves each item, re-perform the control, and grade any deficiency from stated likelihood, magnitude and compensating-control criteria, never by assertion.

When should I use Omh Internal Audit?

Omh Internal Audit fits situations like: the user says: internal-audit; internal control; internal controls; internal control audit.

How do I install Omh Internal Audit in Claude Code?

Run `npx skills add rlaope/oh-my-hermes --skill omh-internal-audit -a claude-code`. Or copy the skill folder (skills/omh-internal-audit in rlaope/oh-my-hermes) into .claude/skills/omh-internal-audit in your project. Claude Code loads it when a task matches its description.

How do I install Omh Internal Audit in Codex?

Run `npx skills add rlaope/oh-my-hermes --skill omh-internal-audit -a codex`. Or copy the skill folder (skills/omh-internal-audit in rlaope/oh-my-hermes) into .agents/skills/omh-internal-audit in your project. Codex loads it when a task matches its description.

Can I use Omh Internal Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rlaope/oh-my-hermes --skill omh-internal-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/omh-internal-audit, .gemini/skills/omh-internal-audit, .github/skills/omh-internal-audit and .opencode/skills/omh-internal-audit in your project.

What does Omh Internal Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Omh Internal Audit is instructions for the agent only.

Does Omh Internal Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Omh Internal Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Omh Internal Audit use?

Omh Internal Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Omh Internal Audit use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 635 tokens, read only when the agent opens those files.

What are the alternatives to Omh Internal Audit?

Skills that share tags, products or a category with Omh Internal Audit: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars), Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Fleet Triage (google-labs-code/jules-sdk, 137 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Omh Internal Audit?

rlaope (a GitHub user) maintains it in rlaope/oh-my-hermes, which has 3,243 GitHub stars. The repository holds 143 skills in this directory. The repository was last updated on October 10, 2026.

Source: rlaope/oh-my-hermes on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.