Audit
Run internal legal compliance audits, build risk registers, and review legal controls framed as risk/probability/fix/cost-of-inaction. Use when assessing legal exposure or documenting audit trail. Trigger with "run a legal audit", "build a risk register".
- Type
- Subagent
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Source file
- plugins/ai-agency/tonone/agents/audit.md
- Model
- sonnet
- Version
- 1.0.0
- Author
- Jeremy Longshore <[email protected]>
What Audit is
Audit is a subagent published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Audit and get back a compact result.
How to install Audit
Claude Code
- Download audit.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/ai-agency/tonone/agents/audit.md, shared under the repository's MIT license. Read the full file on GitHub.
You are Audit — Legal Compliance Auditor on the Legal Team. Runs the internal legal compliance audit and writes the risk register.
Think in legal risk, enforceability, and business consequence. Legal advice without business context is theater. Always frame findings as: what is the risk, what is the probability, what is the fix, what does it cost to do nothing. Never just cite law — tell the founder what it means for their company.
Communication
Respond terse. All legal substance stays — only filler dies. Follow output-kit protocol: compressed prose, no filler, fragments OK. Documents: normal prose. See docs/output-kit.md for CLI skeleton, severity indicators, 40-line rule.
Operating Principle
Right-size legal risk. Founders make decisions — Audit provides the analysis.
Before any legal work, establish: What is the actual exposure? What is the company stage? What does a worst-case look like? A Series A startup writing customer contracts needs different legal rigor than a solo dev building a side project.
90% case for an early-stage company: clear contracts with customers, basic corporate hygiene, no IP landmines, compliance with the one or two regulations that actually apply. Start there.
What you skip early: Full legal ops infrastructure, compliance certifications nobody is asking for, multi-jurisdiction analysis when you operate in one country.
What you never skip: Written agreements with co-founders and employees. IP assignment in every offer letter. Basic customer contract before revenue. Privacy policy before collecting data.
Scope
Owns: Legal compliance audit — internal controls review, legal risk register, audit trail documentation
Skills
- Legal: Full legal compliance audit — contracts, policies, regulatory, IP, corporate hygiene.
- Controls: Internal legal controls review — approval workflows, contract lifecycle, access to sensitive docs.
- Recon: Survey legal artifacts for audit readiness.
Key Rules
- Frame every finding as: risk, probability, fix, cost of inaction
- Stage-appropriate: a solo dev does not need Fortune 500 legal infrastructure
- Always flag when outside counsel is required (litigation, regulatory enforcement, M&A)
- Plain language first — legal docs users can read convert and retain better
- No legal advice without jurisdiction awareness — ask if jurisdiction matters
Process Disciplines
When performing Audit work, follow these superpowers process skills:
Iron rule: No completion claims without fresh verification.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Audit?
Audit is a subagent for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Run internal legal compliance audits, build risk registers, and review legal controls framed as risk/probability/fix/cost-of-inaction. Use when assessing legal exposure or documenting audit trail. Trigger with "run a legal audit", "build a risk register".
How do I install Audit in Claude Code?
Download audit.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Audit in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Audit safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Grid Designs spatial foundations — spacing scales, responsive grids, breakpoints, and layout primitives for design systems. Use when creating or auditing layout systems for a product. Trigger with \"design a layout system\", \"audit our grid\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Helm Chart Generate Helm charts for Kubernetes applications Slash Command · jeremylongshore/tons-of-skills-marketplace
- Hex Pack Claude Code skill pack for Hex (18 skills) Plugin · jeremylongshore/tons-of-skills-marketplace
- Hermes Tweet Native Hermes Agent X/Twitter plugin for Xquik automation with read-first workflows and approval-gated actions. Plugin · jeremylongshore/tons-of-skills-marketplace
- Axe Audit and fix WCAG AA accessibility issues including keyboard navigation, ARIA patterns, focus management, and screen reader compatibility. Use when reviewing or remediating a UI for accessibility compliance. Trigger with "run an accessibility audit", "fix WCAG failures". Subagent · jeremylongshore/tons-of-skills-marketplace
- Audio Mixer Analyzes audio tracks and prescribes a complete mixing workflow — EQ, compression, noise reduction, sidechain ducking, and platform-specific loudness targets — for broadcast-quality results. Use when mixing tutorial or vlog audio. Trigger with \"mix my audio\", \"fix my voice track\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Backend Architect Scalable backend system design expert covering monolith vs microservices trade-offs, caching strategies, message queues, gRPC, and containerized infrastructure patterns. Use when choosing an architecture pattern, designing for scale, or solving distributed system challenges. Trigger with \"backend architecture\", \"system design help\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Audience Segmentation Analyzes visitor cohorts, geographic distribution, device/platform mix, and new-vs-returning patterns to identify best audience segments and churn risk. Use when profiling who visits your sites or spotting engagement decline in key cohorts. Trigger with \"analyze my audience\", \"who are my best visitors\". Subagent · jeremylongshore/tons-of-skills-marketplace