Token导航 LogoToken导航TokenDH.com
研究检索只读github未标认证来源可访问clear审计通过

internalauditinternalaudit 搜索

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

445

周安装

18

GitHub Stars

1

下载量

140
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:internalaudit(internalaudit 搜索)
来源仓库:https://github.com/robdtaylor/personal-ai-infrastructure
仓库路径:skills/internalaudit
安装命令:
npx skills add https://github.com/robdtaylor/personal-ai-infrastructure --skill Internalaudit
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/robdtaylor/personal-ai-infrastructure --skill Internalaudit

简介

internalaudit 用于辅助安全审计、权限检查和凭据风险排查。

  • 适合让 Agent 梳理敏感配置、分析鉴权逻辑或生成安全复核清单。
  • 使用时不能把工具输出直接当最终结论,需人工复核关键操作。
  • 涉及密钥、令牌或生产系统时,应先确认最小权限和脱敏方式。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

Internal Audit

When to Activate This Skill

  • "Plan internal audit programme"
  • "Create audit checklist for [process/area]"
  • "Conduct process/product/QMS audit"
  • "Document audit findings"
  • "Write nonconformance report"
  • "Plan layered process audit (LPA)"
  • "Prepare for IATF 16949 certification audit"

IATF 16949 Audit Requirements

Clause 9.2.2.1 - Internal Audit Programme

The organization shall:

  • Maintain documented internal audit programme
  • Cover all QMS processes over audit cycle (typically 3 years)
  • Include customer-specific requirements (CSRs)
  • Consider process risk and previous audit results
  • Define audit criteria, scope, frequency, methods

Types of Internal Audits

IATF 16949 requires three types of internal audit (clauses 9.2.2.2–9.2.2.4):

Audit TypeFocusFrequencyReference
QMS AuditManagement system conformance to IATF 16949/ISO 9001Annual minimum per clause9.2.2.2
Process AuditManufacturing process effectiveness (process approach)Based on risk, min annual9.2.2.3
Product AuditProduct conformance at production/delivery stagesPer control plan, min annual9.2.2.4
Note: Layered Process Audits (LPA) are not a standalone IATF 16949 requirement. They are a customer-specific requirement (CSR) from certain OEMs (e.g., GM, Ford, Stellantis). They must be implemented when required by customer CSRs but are separate from the three IATF-mandated audit types above.

QMS Audit (9.2.2.2)

Purpose

Verify conformance to IATF 16949/ISO 9001 requirements and organization's QMS.

Scope

All clauses of IATF 16949 over the audit cycle:

  • Context of organization (4)
  • Leadership (5)
  • Planning (6)
  • Support (7)
  • Operation (8)
  • Performance evaluation (9)
  • Improvement (10)

Approach

  • Clause-based checklist
  • Interview management and staff
  • Review documented information
  • Verify implementation and effectiveness

Output

  • Completed checklist
  • Finding report (NCRs, OFIs)
  • Audit report

Process Audit (9.2.2.3)

Purpose

Evaluate effectiveness of manufacturing processes using process approach.

Scope

Each manufacturing process including:

  • Inputs and outputs
  • Process controls
  • Operator competence
  • Equipment capability
  • Work instructions compliance

Approach - Turtle Diagram Method

         INPUTS                    OUTPUTS
            ↓                         ↑
    Materials, specs           Products, data
            ↓                         ↑
       ┌─────────────────────────────┐
       │                             │
WITH → │      PROCESS BEING          │ → METRICS
WHAT?  │        AUDITED              │   KPIs met?
       │                             │
       └─────────────────────────────┘
            ↑                         ↑
      WHO?                        HOW?
    Competent?                  Per procedure?

Key Questions

  • Are inputs conforming?
  • Are process parameters controlled?
  • Are operators competent and trained?
  • Is equipment maintained and capable?
  • Are work instructions followed?
  • Are outputs conforming?
  • Are KPIs being met?

Product Audit (9.2.2.4)

Purpose

Verify product conformance at appropriate stages of production and delivery.

Scope

  • Dimensional verification vs. drawing
  • Functional testing vs. specification
  • Appearance vs. standards
  • Packaging and labeling
  • Documentation/traceability

Approach

  • Select sample per Control Plan
  • Measure against all drawing requirements
  • Verify special characteristics
  • Check packaging and identification
  • Document all measurements

Frequency

  • At defined stages (per Control Plan)
  • All special characteristics covered annually
  • After process changes

Layered Process Audit (LPA)

Purpose

Standardized process verification at multiple organizational levels.

Structure

LevelAuditorFrequencyScope
Level 1Team LeaderDailyKey process steps
Level 2SupervisorWeeklyProcess area
Level 3ManagerMonthlyDepartment
Level 4Plant ManagerMonthlyMultiple areas

Key Characteristics

  • Same checklist at all levels
  • Focus on standardized work
  • Quick (10-15 minutes)
  • Immediate corrective action
  • Trend tracking

Audit Planning

Annual Audit Schedule

Consider:

  • All QMS processes over cycle (max 3 years)
  • All manufacturing processes annually
  • Risk-based frequency (high risk = more frequent)
  • Previous audit results
  • Customer complaints
  • Internal quality performance
  • Changes to processes

Audit Plan Elements

ElementDescription
Audit numberUnique identifier
DateScheduled date
ScopeWhat will be audited
CriteriaRequirements to audit against
Auditor(s)Qualified auditor assignment
AuditeeProcess owner/department
DurationExpected time

Auditor Qualification

Requirements (per 9.2.2.2)

  • Understanding of automotive process approach
  • Customer-specific requirements knowledge
  • ISO 19011 audit principles
  • Core tools knowledge (FMEA, SPC, MSA)
  • IATF 16949 requirements knowledge

Independence

  • Auditors shall not audit their own work
  • Cross-functional audit teams encouraged
  • External auditor for sensitive areas

Training Path

  1. Internal training on QMS and IATF 16949
  2. Core tools training
  3. Audit technique training
  4. Shadow audits (observe experienced auditor)
  5. Supervised audits
  6. Independent auditor status

Conducting the Audit

Opening Meeting

  • Confirm scope and schedule
  • Explain audit method
  • Confirm resources and access
  • Answer questions

Evidence Collection

  • Interview personnel
  • Review documents and records
  • Observe processes
  • Take notes with objective evidence

Audit Techniques

  • Open-ended questions (How? What? Why?)
  • Request evidence for claims
  • Follow the trail (traceability)
  • Verify vs. specification
  • Compare to procedure

Closing Meeting

  • Present findings
  • Confirm accuracy with auditee
  • Agree on corrective action timelines
  • Thank participants

Finding Classification

Major Nonconformance

Definition: Absence or complete breakdown of system to meet requirement, or situation likely to result in shipping nonconforming product.

Examples:

  • No documented procedure when required
  • Consistent failure to follow procedure
  • Pattern of nonconforming product
  • Missing required records

Action: Requires root cause analysis, corrective action, and verification before certification.

Minor Nonconformance

Definition: Single lapse in meeting a requirement; does not affect product quality or system integrity.

Examples:

  • Isolated instance of missing signature
  • Minor record-keeping gap
  • Single deviation from procedure
  • Incomplete training record

Action: Requires correction, may require root cause and corrective action.

Opportunity for Improvement (OFI)

Definition: Not a nonconformance, but improvement recommendation.

Examples:

  • Better organization possible
  • More efficient method available
  • Good practice from other areas
  • Proactive enhancement

Action: Optional implementation, tracked for consideration.


Corrective Action Process

Timeline Requirements

FindingInitial ResponseCorrective ActionVerification
Major24-48 hours30 days maxWithin 90 days
Minor5 business days60 days maxWithin 90 days
OFI30 daysAs appropriateAs appropriate

Corrective Action Elements

  1. Containment: Immediate action to contain impact
  2. Root Cause: Analysis to determine true cause (5-Why, Fishbone)
  3. Corrective Action: Action to eliminate root cause
  4. Implementation: Execute corrective action
  5. Verification: Confirm effectiveness
  6. Prevent Recurrence: Systemic changes

Output Format

Audit Report Structure

# Internal Audit Report

## Audit Information
| Field | Value |
|-------|-------|
| Audit Number | IA-[YYYY]-[SEQ] |
| Type | QMS / Process / Product |
| Date | [YYYY-MM-DD] |
| Auditor(s) | [Names] |
| Auditee | [Name/Department] |
| Scope | [Description] |

## Executive Summary
[Brief summary of audit results]

## Findings Summary
| Major NC | Minor NC | OFI | Positive Findings |
|----------|----------|-----|-------------------|
| [count] | [count] | [count] | [count] |

## Detailed Findings

### Finding 1: [Title]
**Classification:** Major / Minor / OFI
**Requirement:** [Reference]
**Evidence:** [Objective evidence]
**Finding:** [Description]
**Response Due:** [Date]

[Repeat for each finding]

## Positive Observations
[Good practices observed]

## Conclusions
[Overall assessment]

## Approvals
| Role | Name | Signature | Date |
|------|------|-----------|------|
| Lead Auditor | | | |
| Quality Manager | | | |

Integration with Related Skills

AutomotiveManufacturing

Process audits verify work instruction compliance:

  • Are documented procedures being followed?
  • Are quality checkpoints being executed?
  • Are records being maintained?

Load: read ~/.claude/skills/Automotivemanufacturing/SKILL.md

A3criticalthinking

For audit finding root cause analysis:

  • Use 5-Why methodology
  • Fishbone diagram for complex issues
  • A3 format for corrective action plans

Load: read ~/.claude/skills/A3criticalthinking/SKILL.md


Supplementary Resources

For detailed guidance: read ~/.claude/skills/Internalaudit/CLAUDE.md

For checklists: ls ~/.claude/skills/Internalaudit/templates/

For IATF clause questions: read ~/.claude/skills/Internalaudit/reference/iatf-clause-questions.md

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Claude Code

28.81%
按下载量换算40

windsurf

20.55%
按下载量换算29

trae

16.49%
按下载量换算23

OpenCode

13.28%
按下载量换算19

Cursor

8.17%
按下载量换算11

Codex

3.3%
按下载量换算5

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

只读

该 Skill 主要提供规则、说明或参考内容,本身偏只读;真正读写文件、联网或执行命令仍取决于宿主 Agent 的任务。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。

来源信息

继续浏览同类 Skills