ワンクリックで
deck-report-qc
Use when running first-pass QC on Public Equity Investing decks or reports. Do not use as external-circulation certification.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Use when running first-pass QC on Public Equity Investing decks or reports. Do not use as external-circulation certification.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated independent discovery passes over one resolved scope with worker-specific threat models, semantically merge candidates, synthesize one canonical validation threat model, then run validation, attack-path analysis, canonical JSON completion, and generated reporting once. Do not use for PRs, commits, branch diffs, or working-tree diffs.
Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.
Use when the user asks for a repository-wide or scoped-path security scan.
Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use it for scans or fixes.
| name | deck-report-qc |
| description | Use when running first-pass QC on Public Equity Investing decks or reports. Do not use as external-circulation certification. |
Before searching connectors, retrieving evidence, or drafting output, run python3 skills/user-context/scripts/user_context_preflight.py with the shell working directory set to this plugin's root, and follow the returned saved_context, source_category_plan, and next_action. Set the working directory before the first attempt; do not probe alternate relative paths. Missing context must not block the requested workflow. Do not initialize state or run onboarding during ordinary workflow work.
If next_action.id = "offer_orientation" and the parent router has not already handled it, complete the requested work first and append its one-line optional setup offer once.
Apply the presentation-surface precedence in ../../shared/deliverable-intake-policy.md. This workflow's natural artifact is a polished standalone HTML senior-review QC report, while direct edits or remediation preserve the source deck or document format. Do not choose chat-only output unless the user explicitly requests a lightweight response.
When invoked as support for an owning workflow, inherit its resolved deliverable preferences and do not re-prompt. Only when this skill independently owns a new standalone reader-facing QC deliverable should it, before source gathering, analysis, or rendering, load ../../shared/deliverable-intake-policy.md and perform its adaptive request_user_input preflight for materially unresolved preferences. For a substantive standalone QC review of an existing deck or report with supporting materials, resolve the presentation surface to a polished standalone HTML senior-review QC report unless the user requests another surface, a quick/no-file answer, or a standardized dashboard. In interactive runs, ask only remaining material questions such as depth, circulation stage, audience, or review focus; in non-interactive runs, default to the HTML QC report and Full working analysis while disclosing those assumptions outside the artifact.
Load shared/equity-research-support-standard.md and shared/support-layer-routing-contract.md before substantial source, data, QA, or style work.
Use this skill as the P0 first-pass quality-control gate for Public Equity Investing deliverables. The default job is to identify issues, prioritize fixes, and produce a senior-review QA pack. Do not imply a deliverable is externally circulable from the heuristic script alone, and do not rewrite, rebuild, or redesign the deliverable unless the user explicitly asks for remediation.
For a substantial standalone HTML QC report, load ../../shared/html-artifact-standard.md. Let the evidence, circulation question, and highest-impact findings determine the hierarchy rather than forcing the review into a fixed dashboard module inventory.
This is an embedded service under the owning workflow unless the user explicitly asks for standalone deck/report QC. Preserve the owning_workflow internally, such as memo-builder, long-short-pitch, initiating-coverage, earnings-preview, earnings-deep-dive, economic-impact-report, equity-model-update, dcf-model-builder, three-statement-model-builder, comps-valuation, thesis-tracker, meeting-prep, or dashboard-builder.
For substantial embedded work, preserve decision_impact, readiness_effect, artifact_role, and hidden_unless_requested in internal context or support artifacts. Do not print those internal field names in the owning workflow's user-facing artifact. Do not own the recommendation or rewrite the thesis; state in natural language how QC issues change valuation, EPS, target/rating support, benchmark weight, catalyst read, source support, model confidence, client trust, or circulation readiness. A polished standalone HTML senior-review QC report is the default human deliverable for substantive explicit QC-only work; CSV, JSON, Markdown, issue logs, extraction logs, payloads, and manifests remain secondary/support artifacts unless requested.
needs_review rather than overclaiming.financial-source-of-truth standards for source hierarchy, stale-data checks, citation format, source conflicts, and fact/assumption labels.model-audit-tieout and data-shaping issues to excel-data-cleaner instead of trying to solve them inside this skill.Identify the file type and purpose:
If the user provides multiple files, identify the controlling artifact and the source artifacts. Example: deck is controlling output; model, evidence ledger, filing, release, transcript, and source tables are supporting materials.
For PPTX, DOCX, XLSX, CSV, TXT, or markdown files, run the bundled first-pass scan script when available:
python scripts/inspect_deck_report.py <file1> <file2> --outdir qc_out
Use the script output as a first-pass map only. It is not a substitute for visual review, chart inspection, model tie-out, source-of-truth review, or PDF rendering.
For PDFs, screenshots, image-heavy slides, or scanned materials, use PDF/rendering tools to inspect pages visually before finalizing QC. If charts are embedded as images, state that the underlying chart data could not be extracted unless the model/source file is provided.
For each critical or high finding that relies on visible content, render and inspect the cited source pages or slides. Keep a plain-language record of what pages, workbook tabs, and support files were inspected, and of what could not be independently verified.
Create or infer:
Consult references/qc-playbook.md for QC categories and references/extraction-and-tieout.md for extraction and tie-out guidance.
Check at minimum:
Consult references/issue-taxonomy.md for severity and issue-type definitions.
Classify each consequential issue using one of these reader-facing confidence descriptions:
confirmed internal mismatch: proved by contradictory values, labels, calculations, or statements within the supplied artifactsexternally verified error: proved against a controlling primary or trusted dated external sourceneeds review: suspected issue or unresolved conflict that requires a source, model, data export, or user confirmationDo not state that an identifier, market fact, source claim, or company fact is confirmed wrong merely because supplied materials conflict or appear unlikely. Without a controlling source, state the internal conflict and route it for confirmation.
Assign one of these postures:
first-pass-clear: no heuristic blockers were identified, but visual/source/model review may still be requiredsenior-review-ready: mostly ready, with limited open questions or judgement callsneeds-targeted-fixes: specific corrections are required before circulationnot-circulable: material numerical, source, chart, or narrative issues remainblocked: necessary source/model files are missingMedium source gaps, repeated-number mismatches, and unit/period ambiguity usually mean needs-targeted-fixes, not senior-review-ready.
Default output should be a senior-review QC readout. For standalone QC-only work, produce a polished standalone HTML senior-review QC report following ../../shared/html-artifact-standard.md. Use chat only when the user explicitly requests a lightweight response. When the script is used, the reader-facing artifact should be public_equity_investing_deck_qc_report.html; CSV, JSON, manifests, payloads, and support notes are audit/import support unless the user asks for them.
Use dashboard-builder, references/DASHBOARD_PACK.md, and references/dashboard-map.md only when the user explicitly asks for a standardized dashboard, reusable dashboard template, issue cockpit, remediation tracker, or structured payload-driven render. On that optional path, deck-report-qc owns issue identification, severity, tie-out judgment, circulation posture, and remediation sequence; dashboard-builder owns the shell/rendering/QA. Build a public_equity_investing_dashboard.v1 payload as an internal renderer input, and keep JSON/Markdown/CSV support files behind the HTML dashboard unless explicitly requested.
The QC readout should include:
Use references/output-templates.md for default templates.
For standalone HTML, keep the first screen focused on the verdict, circulation posture, evidence scope, and the few findings that change senior reliance. When a valuation, target-price, recommendation, rating, benchmark-weight, or other decision-critical tie-out exists, place the Decision-Critical Tie-Out section before Top Issues, Must Fix Before Circulation, or the full issue log; do not make the reader pass through the broader findings register before seeing the central control failure. Place comprehensive registers, source-coverage tables, and presentation-polish findings lower in the report.
Visually inspect local HTML via local headless-browser screenshots, not the in-app Browser plugin, at both desktop and narrow/mobile widths. Tables may scroll horizontally inside a clearly bounded table wrapper on narrow screens, but they must not widen the entire page. In mobile QA, verify that the document viewport itself has no horizontal overflow, for example document.documentElement.scrollWidth <= document.documentElement.clientWidth; use constrained grid/section children and max-width: 100%; overflow-x: auto table wrappers where needed. Iterate on hierarchy, table density, clipping, contrast, and whitespace before delivery.
When scripts/inspect_deck_report.py was used before a substantive standalone HTML review, write a small JSON review record identifying completed_reviews and remaining missing_inputs, then finalize the existing output path after HTML visual inspection:
python scripts/inspect_deck_report.py --finalize \
--outdir <final-output-dir> \
--scan-dir <first-pass-output-dir> \
--primary-report <final-output-dir>/public_equity_investing_deck_qc_report.html \
--review-record <final-output-dir>/qc_review_record.json
Finalization must make the polished HTML the sole primary human deliverable, reconcile manifest status to the work actually performed, and remove the provisional dashboard contract for ordinary standalone HTML reviews. Add --keep-dashboard-contract only when the user explicitly selected the standardized-dashboard path.
For complex medium/large requests, use sub-agents where available; otherwise emulate the split as named workstreams. Suggested lanes: source and number tie-out, chart/visual review, narrative consistency, formatting/circulation posture, and issue log. Keep this skill as the lead: reconcile conflicts, source labels, assumptions, open items, final QA, and the user-facing answer.
When embedded in a broader workflow, "lead" means lead for QC only; the owning workflow remains the investment-artifact owner.
Use these severities:
critical: could change investment decision, valuation, rating, price target, sizing, market read, or client trusthigh: material inconsistency or missing support that must be fixed before circulationmedium: localized inconsistency, unclear caveat, formatting issue, or missing source detail that should be fixedlow: polish item that does not affect substanceneeds_review: possible issue that requires visual, model, source, or user confirmationNever hide uncertainty. If a number may be wrong but cannot be proven wrong from available files, label it needs_review and ask for the model/source support.
Use references/p0-integrations.md when deciding whether an issue belongs in this skill or should be routed to another P0 skill.
Common routes:
financial-source-of-truthmodel-audit-tieoutexcel-data-cleanerdcf-model-builder, comps-valuation, or three-statement-model-builderevent-driven-analyzer, earnings-preview, earnings-deep-dive, equity-model-update, or long-short-pitch; credit-first packs, public-credit memos, bond/loan/CDS decks, covenant/recovery packs, and debt-security materials route to Credit Marketsmemo-builderBefore final output, verify:
confirmed internal mismatch, an externally verified error, or needs review