Finance Audit Agent

ReviewAudited by ClawScan on May 16, 2026.

Overview

This is an instruction-only finance-audit prompt with no executable code, but it asks users to handle sensitive financial, identity, and medical records and should be used with human review.

Before using this skill, confirm you have permission to process the audit documents, redact unnecessary sensitive fields, verify any claimed external identity or sanctions checks independently, and keep a human auditor responsible for final conclusions.

Findings (3)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Audit prompts and generated reports may contain private identity numbers, bank card details, health information, and financial records.

Why it was flagged

The skill is designed to parse highly sensitive personal, financial, and medical information into the agent context and outputs.

Skill content
| 身份证 | 全行业 | 姓名/身份证号/.../住址/有效期 | ... | 银行卡 | 全行业 | 卡号/... | ... | 病历资料 | 保险 | 医院名称/.../诊断/.../费用明细 |
Recommendation

Use only authorized audit materials, redact unnecessary identifiers where possible, and confirm how the host platform stores or retains uploaded documents and generated outputs.

What this means

Users could assume the agent can perform official identity verification even though no credentials, integrations, or authority are declared in the supplied artifacts.

Why it was flagged

The described identity verification workflow implies biometric and official/public-security database access, which would require proper authorization if actually performed.

Skill content
R001:投保人身份真实性核验 - 身份证OCR识别+人脸比对+公安库交叉验证
Recommendation

Treat these checks as audit-control descriptions unless you have separately authorized and configured lawful data sources; do not rely on unsupported claims of official database access.

What this means

A user might place too much trust in generated audit findings, especially for claims handling, AML, sanctions, or compliance decisions.

Why it was flagged

Strong performance claims in a regulated audit context could encourage overreliance, although the skill also describes a human judgment layer for final conclusions.

Skill content
核赔准确率89% → 超越人类初审水平
Recommendation

Use the agent’s output as a draft or checklist and require qualified human validation before taking business, regulatory, or customer-impacting action.