Internal audit support skill aligned with IIA (Institute of Internal Auditors) International Standards. Provides risk-based audit planning, audit program development, workpaper documentation, finding development (Condition/Criteria/Cause/Effect), and Corrective Action Request (CAR) tracking. Use when: planning annual/quarterly audits, creating risk assessment matrices, developing audit programs and test procedures, documenting audit workpapers, writing audit findings and reports, tracking corrective actions and follow-ups, preparing for external audits (SOX, ISO). Triggers: "internal audit", "audit plan", "audit program", "audit workpaper", "audit finding", "risk assessment", "CAR tracking", "corrective action", "IIA Standards", "COSO framework", "監査計画", "監査プログラム", "監査調書", "是正措置", "リスク評価".
「audit」の検索結果
5,633 件 ・ 関連度順
概要と使いどころ
Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation tracking, and management reporting. Covers audit universe definition, annual audit plan, working papers, and closure verification. Keywords: internal audit, privacy audit, fieldwork, remediation, findings, audit plan.
日本語の概要は準備中です。原文の説明を表示しています。
Comprehensive audit of a user's entire Claude environment — combines Project audit (six-dimension Project Scorecard, seven anti-patterns) with Global audit (six-dimension Global Layer Scorecard) plus Cross-Layer Alignment Check across all nine layers and Evolutionary Recommendations across four pathways. Produces a unified action plan. Use when user says "full audit of everything," "audit my entire Claude setup," "full stack audit," "comprehensive review of my project and preferences," "check everything," or wants the complete health check of both a specific Project AND their global configuration. Also use when a project audit reveals cross-layer issues that require full-stack visibility. Do NOT use for auditing only a Project (use rootnode-project-audit if available) or only global layers (use rootnode-global-audit if available). Do NOT use for single prompt evaluation (use rootnode-prompt-validation if available). Run on Opus 5 or Sonnet 5 at `high` effort (both defaults); depth reduces on legacy models.
日本語の概要は準備中です。原文の説明を表示しています。
Flagship comprehensive SEO audit combining Ahrefs and GSC data in sequential waves with checkpoint saves. Use when user says "site audit pro", "full audit", "comprehensive audit", "audit with live data", "deep audit", "pro audit", "complete SEO audit", "run a full site audit", or "audit everything for this domain". Requires domain param. Optional: site param for GSC overlay.
日本語の概要は準備中です。原文の説明を表示しています。
Vulnerability audit and dataflow analysis built on the neug CPG engine. file_audit (default, recommended): first builds a function-level summary graph (tier1) over the entire project, then incrementally builds detailed CPGs (tier2) on demand for chosen functions; both tiers coexist in a single neug database (unified schema, cross-layer refines edges; C/Java/Python/Rust). All capabilities are exposed as CLI tool subcommands (audit/overview/build/query/methods/paths), so an agent can drive the audit step by step via shell; the audit subcommand can also run the built-in LLM loop. The same tooling also supports a dataflow analysis mode (Workflow C): no vulnerability hunting, only variable-level dataflow tracing for functions of interest, producing dataflow_analysis.json. repo_audit: multi-round LLM/Cypher audit over a full-repo CPG. Use when the user asks to audit a codebase/project for vulnerabilities, scan a project with CPG/neug, run repo_audit/file_audit, find source-to-sink taint paths, or analyze dataflow inside a function. Supports C, Java, Python, and Rust.
日本語の概要は準備中です。原文の説明を表示しています。
Audit a Python project's installed dependencies for known CVEs by wrapping pip-audit (PyPA's official vulnerability auditor) and emitting findings in the canonical penetration-tester schema. Detects vulnerable direct AND transitive packages, normalizes pip-audit's severity output via OSV severity bands, falls back to pip list --outdated when pip-audit isn't installed, and supports requirements.txt, pyproject.toml (PEP 621), Pipfile.lock, and poetry.lock as input sources. Use when: pre-merge gate on a Python project, post-incident sweep after a PyPI compromise (e.g. ctx, request-toolbelt typosquats, ultralytics 8.3.42 compromise), SOC2 evidence collection, or inheriting an unfamiliar Python codebase. Threshold: any HIGH or CRITICAL CVE in the resolved dependency tree. MODERATE / LOW reported informationally. Trigger with: "audit python deps", "pip vulnerability scan", "check pypi packages for CVEs", "pip-audit run".
日本語の概要は準備中です。原文の説明を表示しています。
Evidence-first marketing audit of a third-party local business (café, roaster, shop, restaurant, hotel, clinic, home service) from a Google Maps, share.google or website link — located DataForSEO rankings, map packs, search volume and seasonality, listings, reviews, backlinks, AI-assistant answers and a site crawl, plus direct checks (real-browser access, page weight, store shipping quotes, email DNS, mobile screenshots) — delivered as an owner-facing report with priced offers, an exact change list and a 12-week plan, optionally localized and bilingual. Use when "audit this business", "full marketing audit of <business>", "prospect audit", "local business audit", "use DataForSEO for the hard SEO data", "go deeper", "rerun it for local <market>", "also in Spanish", "give me the offers, changes and 3 month plan", or a business link arrives with "audit". For auditing your own product across channels use /kai-audit.
日本語の概要は準備中です。原文の説明を表示しています。
Multi-backend database security auditor. Audits Supabase, Firebase (Firestore/RTDB/Storage/Functions/Remote Config), MongoDB (self-hosted + Atlas), self-hosted PostgreSQL, and self-hosted MySQL for RLS/rules misconfigurations, exposed credentials, auth bypasses, MongoBleed (CVE-2025-14847), pgBouncer CVE-2025-12819, mysql_native_password drift, ghost auth, and storage exposures. Use this skill whenever the user mentions database security, RLS or rule audits, security review, penetration testing a vibe-coded app, checking if their DB is exposed, hardening a backend, fixing security rules, or auditing apps built with Lovable/Bolt/Replit/Cursor/Claude Code on any of these backends. Trigger on phrases like 'is my app secure', 'check my database', 'audit my Firebase', 'audit my MongoDB', 'audit my Postgres', 'audit my Supabase', 'is my DB exposed', or any cross-backend variant ('audit my full stack').
日本語の概要は準備中です。原文の説明を表示しています。
Prepares a DRAFT internal audit pack from the audit plan: scope as stated, criteria with clauses quoted from the documents provided, document requests per auditee with due dates, open interview questions per process and role, previous findings to follow up and a readiness checklist. Never pre-judges conformity, writes findings or selects the sample; the lead auditor decides. Use when the user asks to "prepare the internal audit", "build the audit pack from this plan", "draft the document requests and interview questions" or "get us ready for the supplier audit". Do not use for evidence requests built from a control list, use control-evidence-request-pack instead; to chase actions from earlier audits, use corrective-action-tracker. Drafts for human review; never approves, authorises or signs off.
日本語の概要は準備中です。原文の説明を表示しています。
Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use when the user mentions ISO 27001, ISMS audit, Annex A controls, Statement of Applicability (SOA), gap analysis, nonconformity management, internal audit, surveillance audit, or security certification preparation. Helps review control implementation evidence, document audit findings, classify nonconformities, generate risk-based audit plans, map controls to Annex A requirements, prepare Stage 1 and Stage 2 audit documentation, and support corrective action workflows.
日本語の概要は準備中です。原文の説明を表示しています。
Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema. Detects direct AND transitive vulnerabilities, normalizes npm's severity scale (info/low/moderate/ high/critical) to the shared Severity enum, and parses both v1 and v2 audit output formats so the skill works against npm 6 and npm 7+ lockfiles. Use when: pre-merge gate on a Node project, post-incident sweep after a transitive package compromise (e.g. event-stream, ua-parser, node-ipc, color.js), SOC2 vendor-management evidence collection, or auditing an inherited or acquired Node codebase. Threshold: any HIGH or CRITICAL CVE in the resolved dependency tree. MODERATE / LOW reported informationally. Trigger with: "audit npm deps", "npm vulnerability scan", "check node packages for CVEs", "npm audit".
日本語の概要は準備中です。原文の説明を表示しています。
Diagnostic-only test suite auditor. Classifies repo type, maps against 7-layer testing taxonomy (git hooks → static → unit → integration → system → E2E → acceptance), runs deterministic quality gates (coverage, mutation, CRAP, architecture, escape-scan), builds RTM / personas / journeys traceability, produces TEST_AUDIT.md, updates tests/TESTING.md, and mandatorily hands off to implement-tests when gaps are found. Use when auditing test quality, finding test gaps, or running the full 7-layer sweep. Trigger with "audit tests", "find gaps", "test audit", "check test quality", "full sweep", "7-layer audit", "rtm check".
日本語の概要は準備中です。原文の説明を表示しています。
When the user wants to run an SEO audit, technical SEO audit, or site health check. Also use when the user mentions "SEO audit," "technical audit," "site audit," "crawl audit," "indexing audit," "SEO health," or "fix SEO issues." For prioritization and organic strategy, use seo-strategy. For GSC data analysis, use google-search-console.
日本語の概要は準備中です。原文の説明を表示しています。
Master orchestrator for a full SEO audit suite powered by the Ahrefs MCP. Use this skill when running a comprehensive SEO audit, scoping a quarterly health check, doing pre-acquisition SEO due diligence, or post-migration verification. Triggers on full SEO audit, comprehensive SEO review, SEO health check, audit my site, SEO due diligence, audit suite, comprehensive audit, end-to-end SEO. Also triggers when a stakeholder wants the complete picture rather than a single-dimension audit.
日本語の概要は準備中です。原文の説明を表示しています。
Audit de conformité RGPD complet d'un site internet. Réalise une observation systématique du site selon une checklist de 10 sections (mentions légales, hébergeur, formulaires, newsletter, politique de confidentialité, cookies et bandeau, mots de passe, trackers et mesure d'audience, sous-traitants et transferts hors UE, accessibilité du recueil des droits) plus une annexe 22 items reproduisant les exigences des articles 13 et 14 RGPD. Produit un rapport structuré avec niveau de conformité global, points bloquants (risque 3), points de vigilance (risque 2), recommandations prioritaires et notes techniques. Le skill est tool-agnostique : il fonctionne avec un outil de navigation automatique (Claude in Chrome, Cowork ou équivalent) ou en mode dégradé copier-coller. Triggers : "audit RGPD site", "audit site internet", "vérifie ce site", "scanne ce site", "audit conformité site", "audite la conformité de [URL]", "audit cookies site", "audit politique de confidentialité site".
日本語の概要は準備中です。原文の説明を表示しています。
An SEO agent skill for quick, lightweight, default single-page SEO audits. Performs basic on-page and site-level checks and outputs a structured basic SEO audit report. Use when the user asks for "SEO audit", "SEO check", "check my page SEO", "page analysis", or wants a first-pass review of a URL. If the user requests "deep audit", "full report", "technical SEO audit", or "advanced SEO", use seo-audit-full instead.
日本語の概要は準備中です。原文の説明を表示しています。
Guides privacy audit risk assessment including risk universe development, inherent and residual risk scoring, control effectiveness evaluation, risk-based audit planning, heat map generation, risk appetite alignment, and audit prioritization by risk exposure. Covers the full audit risk assessment cycle from scoping through ongoing monitoring. Keywords: audit risk assessment, risk universe, inherent risk, residual risk, control effectiveness, risk-based audit planning.
日本語の概要は準備中です。原文の説明を表示しています。
Two-layer funnel audit on collected data only — stress-test the awareness layer (hooks, messaging, proof placement, attention leaks on live pages and ads) and the lead-capture layer (opt-ins and lead magnets scored on the four Value Equation variables, friction findings, weakest-magnet rewrite), plus a phone-path check under the Phone Capture Fit Rule. Use when "funnel audit", "audit my funnel", "why is my funnel leaking", "top of funnel isn't converting", "audit our lead magnets", "opt-in audit", "awareness to lead audit", "where are we losing people", "lead capture audit", or any request to diagnose the full awareness-to-lead flow rather than one page.
日本語の概要は準備中です。原文の説明を表示しています。
Write a clear, reviewable audit workpaper documenting procedures, evidence, and conclusions. Use when an auditor says "write a workpaper", "document this audit procedure", "tick and tie this", "I need to document my testing", "substantive testing workpaper", "controls testing documentation", "audit evidence memo", "prepare the workpaper for this balance", "document the audit steps I performed", or needs to capture any audit work in a format that supports review and sign-off. Also trigger when someone has completed audit testing and needs to write it up even if they don't use the word "workpaper".
日本語の概要は準備中です。原文の説明を表示しています。
Use when setting up or auditing how compliance documentation is structured, collected, and preserved for regulatory audit in Salesforce FSC — covering KYC data collection workflows, AML screening integration setup, audit trail configuration, and regulatory reporting readiness. Triggers: KYC form setup, AML integration configuration, compliance data collection, audit trail setup, regulatory documentation workflow, Field Audit Trail configuration, Setup Audit Trail, Event Monitoring, Discovery Framework, FSC KYC objects, Identity Document setup, Party Identity Verification. NOT for security implementation, NOT for designing AML/KYC architecture (use architect/aml-kyc-process-architecture), NOT for configuring who can access deal or client data (use admin/compliant-data-sharing-setup).
日本語の概要は準備中です。原文の説明を表示しています。
Produces structured U.S. legal audit summaries that distill compliance findings into executive-ready risk prioritization and remediation plans, covering likelihood/impact scoring, consequence analysis, and corrective actions with timelines and owners. Use for legal audits, compliance audits, regulatory audits, compliance gap analyses, risk assessments, audit report summaries, or remediation roadmaps. Trigger keywords: audit summary, compliance findings, audit report, risk prioritization, remediation plan, regulatory exposure, corrective action plan.
日本語の概要は準備中です。原文の説明を表示しています。
Use this skill when the user asks about DOT audits, FMCSA compliance reviews, new entrant safety audits (NESA), focused investigations, what auditors actually ask for, audit document checklists, common audit failures, the audit ratings (Satisfactory / Conditional / Unsatisfactory), or how to prepare for an upcoming audit. Cite 49 CFR 385.
日本語の概要は準備中です。原文の説明を表示しています。
Thorough, file-cited technical debt audit across 9 dimensions using AST-grep (tree-sitter), grep, LSP, and language-native tooling. Produces TECH_DEBT_AUDIT.md with severity, effort estimates, and prioritized fixes. Use when asked for codebase health check, tech debt audit, architecture review, code quality assessment, or cleanup planning. Triggers: 'tech debt', 'technical debt', 'debt audit', 'code health', 'technical debt audit', 'codebase health check', 'find tech debt', 'debt analysis', 'audit code quality'.
日本語の概要は準備中です。原文の説明を表示しています。
Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log querying, timeline reconstruction, and integration with SIEM platforms. Activates for requests involving auditd analysis, Linux audit log investigation, ausearch queries, aureport summaries, or host-based intrusion detection on Linux.
日本語の概要は準備中です。原文の説明を表示しています。