Skip to content
Back to skills

Comp Final Audit

ASecurity

数模竞赛交付前的最终审计:核对证据链、质量检查结论、审稿记录与交付文件,产出可追溯的审计结论。触发词:交付审计、最终审计、AUDIT_REPORT、交付前检查。

  • 10 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agentspythongogit

Security analysis

A100/100

Scanned September 29, 2026

npx -y skills add FOURTEEN1416/academic-agent-toolkit --skill comp-final-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Comp Final Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Comp Final Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/fourteen1416-comp-final-audit/badge)](https://www.skillsdirectory.com/skills/fourteen1416-comp-final-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: comp-final-audit
description: "数模竞赛交付前的最终审计:核对证据链、质量检查结论、审稿记录与交付文件,产出可追溯的审计结论。触发词:交付审计、最终审计、AUDIT_REPORT、交付前检查。"
---

# Competition Final Audit

Read the persisted workflow report, manifests, gate results, review verdicts, and final PDF. Generate `AUDIT_REPORT.json` through the engine, never handwrite a passing verdict. Its machine contract includes `workflow_id`, non-empty `artifacts` (`path` plus SHA-256), `directory_coverage`, `gate_outcomes`, `waivers`, and `delivery_decision`. While the final step is running or waiting for approval, only `eligible` is possible; after successful completion and any required human approval, derive a separate `DELIVERY_REPORT.json` with `ready`. A missing gate, skip waiver, changed artifact, or unresolved fatal finding blocks delivery.

## 默认执行:自动采集而非手工证明

使用 `next` 返回的执行会话,按本技能执行真实引用、数字一致性与合规检查;命令通过 `session run` 自动记录,检查结论写入工作区。然后 `session finish` 自动汇聚证据、生成候选审计并一次验收,不手工写evidence或passing verdict,不先preflight再complete。

真实竞赛终审含业务检查和人工判断,不能仅因技能名为comp-final-audit而自动当作完成。只有模板明确声明machine_audit_only=true的纯机器聚合步可自动接续;人工批准永不代替。

执行者只处理引用、数据一致性、合规及未解决发现。程序绑定当前步骤和版本、生成候选报告、验证已接受的事件与目录成员并推进到检查点;不要另写evidence、重算hash或重复preflight。交付报告发布失败保持pending,通过finish/next恢复,不改写已接受预审。

Delivery conformance (data-driven per family): consume this step's bound `contest_profile` snapshot — the engine-injected `CONTEST_ID` / `PAGE_CAP` / `PAGE_SCOPE` / `PAGE_CAP_STATUS` / `EDITION` are the machine source of truth (not a hand-read of `engine/modex-core/comp_rules.json`) — never hardcode one family's caliber for another. **CUMCM profile**: check the final PDF against `_utils/cumcm_2026_format.md` (official CUMCM 2026 format-spec digest, verified against the official source): margins ≥2.5cm; electronic version starts at the abstract page (no commitment/ID pages); page numbers from the abstract page, footer center; no TOC; body ≤30 pages (`official_verified`); appendix lists support files and full runnable source; no identity information anywhere; single PDF ≤20MB; support archive ≤20MB. **GMCM (华为杯) profile** (corrected 2026-09-25 against the official opening announcement): the official template contains **no** pledge page (`pledge_page: absent_in_official_template` — the signed pledge is school-level material, never part of the paper); the first page is the immutable cover (4 logos must not be replaced); no identity information (institution/names/team number) may appear on any page after the first, or the paper is void; **no operative body limit is on file for the current edition** (`hw-page-limit: unknown` — the 80-page figure was a one-off migration_evidence task ruling for huawei2026d_zcode and is NOT inherited by new tasks; the legacy 50-page baseline is obsolete) — treat the page limit as 待核实 rather than asserting any number; the figure-count band in the snapshot constraints is an experience compilation, advisory only. Record any violation as a fatal finding.

Similarity red line: per CUMCM 2026 duplication policy, a paper with either similarity (CNKI literature base or contest self-built base) ≥25% is in principle barred from national review; unofficial stricter community targets are ≤15% similarity and ≤20% AIGC. The audit cannot measure this itself — verify the delivery notes record a plagiarism self-check and flag its absence as a finding.

Companion-skill ledger (C1 gate companion check): read the per-step execution evidence under `.engine/evidence/` and verify every step that carried `companion_skills` recommendations declared its `companion_skills` decision (used and/or skipped with reasons). List any gap as a finding with the step name; the runner blocks completion before step 14, so a gap here indicates evidence tampering — treat it as fatal.

AI-disclosure red line (CUMCM 2026 hard compliance; the same 双件套 mechanism is mandatory on the GMCM/华为杯 chain since its S14 shares this skill): verify the deterministic AI 双件套 end to end — `paper/main.tex` must contain the "AI工具使用声明" section placed before the references, and `python skills/_utils/build_ai_disclosure.py --check-only --paper-source <工作区>/paper/main.tex` must exit 0 against the workspace's `.mh/ai_disclosure.json` manifest. A hand-written declaration with no script-backed manifest/detail PDF, or a failing `--check-only`, is a fatal finding (the declaration text must originate from the user-confirmed tool list, never authored freely by a language model).

Reference and consistency final sweep: run `python tools/citation_checker.py <工作区>/paper/main.tex` for a reference-entry machine sweep and `python tools/paper_data_check.py --mode pdf --workspace <工作区>` for number-vs-ledger cross-checking; report any mismatch as a finding (fatal when it touches headline numbers, page-limit items, or the reference list). The audit is their mandatory consumer.

Asset-declaration ledger (C2 gate companion check): for every step whose evidence carries an `assets` declaration, verify coverage of the step's StepAction.assets list (same rule as the companion ledger). For workflows started before the C2 mechanism, `assets` is legitimately absent from both StepAction and evidence — absence is not a finding; only steps that carry the field must satisfy it. A machine sweep is available: `python tools/check_asset_utilization.py` (utilization ledger + map coverage + template asset paths).

Integrity anchor (anti-Goodhart): every gate, template, and test lives inside the agent's write scope, so internal checks can themselves be gamed by editing the checker. The final `approve` of this step belongs to the human operator; before `delivery_decision=ready`, the operator must verify repo integrity from outside the agent's session: `git status` clean, `git log` reviewed for any contest-window modification to `engine/`, `tests/`, `engine/modex-core/templates.json`, or quality-gate scripts without a logged justification, and optionally `pytest -q` re-run from a fresh clone/worktree. Any unexplained gate-file modification = fatal finding; document the check in `AUDIT_REPORT.json` notes.

## 退出判据(Verification)

本步完成前逐项自检(不达标即视为未完成):

- [ ] 证据链完整:每步有产物、命令、哈希与事件
- [ ] 门禁结论逐项列出,不得只写一句「通过」
- [ ] 交付文件清单与实际文件一致(含体积与格式合规)
- [ ] 不得存在 skip_ 类豁免参数;存在即判定交付阻断

## 常见合理化(Common Rationalizations)

| 合理化 | 现实 |
|---|---|
| "门禁都过了就交付" | 门禁只覆盖检查项全集,不覆盖本次风险面;审计要给出逐项结论。 |
| "审计报告写个通过就行" | 手写散文式「审计」过不了产物规格(需含门禁逐项结论字段)。 |
| "这条豁免先留着" | skip_ 类豁免只留痕不放行:存在即阻断交付,须以不含豁免的流程重跑。 |

> 本段与 `skills/_utils/anti_rationalization.md`(全局版)配套:本表是本步专属,
> 全局版覆盖跨步骤通用借口。新增借口时优先落到本表(更贴岗位),能泛化再上升。

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…