Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Hr Audit

ASecurity

Runs an HR Audit Report across files, policies and practices, with a gap list ordered by risk and effort, a fix plan with owners, and the deficiency summary leaders sign off. Use for "run hr-audit", "HR audit", "audit our personnel files", "I inherited a mess", "HR audit checklist", "employee file audit", "records retention check", "first 90 days as HR lead", part of the AI for HR Pack by Polar Bear.

2 stars
0 votes
0 copies
0 views
Added 10/4/2026
ai-agentsgo

Works with

cli

Security Analysis

A100/100

Scanned 10/4/2026

$npx -y skills add polar-bear-org/claude-skills --skill hr-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hr Audit?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Hr Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/polar-bear-org-hr-audit/badge)](https://www.skillsdirectory.com/skills/polar-bear-org-hr-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: hr-audit
description: Runs an HR Audit Report across files, policies and practices, with a gap list ordered by risk and effort, a fix plan with owners, and the deficiency summary leaders sign off. Use for "run hr-audit", "HR audit", "audit our personnel files", "I inherited a mess", "HR audit checklist", "employee file audit", "records retention check", "first 90 days as HR lead", part of the AI for HR Pack by Polar Bear.
---

# HR Audit

## When To Use
You inherited months of no HR: files in random folders, medical notes mixed into personnel files, policies nobody has opened in years. Use this to answer: what is kept, where and who can see it, which policies exist and are applied, and what do you fix first?

## When Not To Use
If you do not yet know which obligations apply, run HR Compliance Checklist first; the audit tests practice against that list. For the ongoing record of live cases, use Employee Relations Case Log; an audit is a point-in-time check, not a log.

## Inputs
- An inventory of where HR records live (systems, shared drives, paper), even rough.
- Your policy list with owners and review dates, if any.
- Your compliance register and where people work (country, and state or province where it matters).
If you have none of this, I start from a standard files, policies and practices checklist and mark the output as a first draft.

## Approach
An HR audit against a records and policy checklist, using the ICO guidance on keeping employment records (ico.org.uk, employment practices and data protection) and US DOL Fact Sheet 21 on FLSA recordkeeping (dol.gov/agencies/whd/fact-sheets/21-flsa-recordkeeping). The judgement is in order: files first, because nothing else can be checked if you cannot find the record. The failure it prevents is the one inheritors describe: backfilling documents after the fact to look tidy, which turns a records gap into a credibility problem. The audit records what exists; it never creates what should have existed.

## Workflow
1. Ask three questions: where people work, which record stores and policies exist, and what risk and effort mean for you at high, medium and low (you set each level).
2. Files pass: for each record type, what is kept, where, who can open it, and whether health information is held apart from the personnel file. Retention per type is "the source says, confirm with a qualified adviser". Example: the ICO ties retention to legal requirement and business need; the DOL fact sheet gives retention periods for payroll and wage records.
3. Policies pass: for each policy, does it exist, who owns it, when is it due for review, and is it applied. "Applied" needs evidence, not a yes.
4. Practices pass: you pick a sample of recent cases (leave, discipline, onboarding); check each against the written process step by step and note where practice departed.
5. Score each gap on risk and effort with your definitions. Order the fix plan high risk and low effort first.
6. Fix plan: gap, fix, owner role, date. Deficiency summary: one line per high-risk gap for a named leader to sign.
7. List adviser questions, above all on retention and any record that may need to be destroyed or moved.

## Output Format
```markdown
# HR Audit Report
Scope: [locations, record stores, policies] | Sample: [cases chosen by you] | Audited on: [date]
## Gap list
| Pass | Item | What we found | Risk | Effort | Source or rule | Confirm with a qualified adviser |
|---|---|---|---|---|---|---|
| [files/policies/practices] | [item] | [fact] | [high/medium/low] | [high/medium/low] | [link or internal] | [yes/no] |
## Fix plan
| Gap | Fix | Owner role | Date |
|---|---|---|---|
| [gap] | [fix] | [role] | [date] |
## Deficiency summary
- [High-risk gap in one line]
## Adviser questions
- [question]
## Decision
[Named leader] signs the deficiency summary and approves the fix plan by [date].
```

## Done When
- All three passes are done in order, each with its findings.
- Every gap has risk and effort on your definitions, and the fix plan follows that order.
- Every retention period is marked to confirm with a qualified adviser.
- Every high-risk gap appears in the deficiency summary.

## Quality Bar
- The audit checks files, never the person in them; content is read only as far as the check needs.
- Health data is flagged for separation, never summarised.
- Findings are facts with a location, not impressions.
- No document is created or backdated to close a gap.
- Score files, policies and processes, never people; every legal point goes to a qualified adviser for the country it concerns.

## Next
Run hr-dashboard (HR Dashboard) to report the fixed state to leaders.

## About the makers

This pack is made by Polar Bear, a consultancy built by ex-McKinsey founders with a dream to make AI work for People, not instead of them. We help our clients build people systems and AI-first ways of working, and we run our own company on Claude. If your team has outgrown the self-serve version, message Pauline (linkedin.com/in/paulinebertry).

Attribution

polar-bear-orgpolar-bear-org
View sourceSee grades on GitHubMore from polar-bear-org →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698431 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →