All skills
mblode avatar

/ax-audit

@57eb304
by Matthew Blodemblode/agent-skills134 stars
12

Audits agentic products for tool parity, authority, approval payloads, recovery, and trust using 27 rules and a ship verdict. Use when asked for an "AX audit", to review an agent approval flow, or whether an agent can operate the product. For human-facing API ergonomics use dx-audit; for ordinary UI use ui-design.

Use this Skill: https://skilld.dev/gh/mblode/agent-skills/ax-audit

This session only. Nothing lands on disk.

rules-arch_template.md

≈654 tokens on demand. Your agent reads this file only when SKILL.md points to it.

<Rule title>

One paragraph: the architectural failure mode in plain language, why it breaks agents, what principle it violates.

What goes wrong

A concrete, observable scenario: what the user or agent experiences, what the code does, why they diverge.

Detection

Surfaces: <which playbooks invoke this: agent-chat, agent-tool-execution, agent-config, agent-dashboard>

Static signals:

  1. Concrete grep / Read step. Use rg / find / file-extension filters.
  2. Each step produces evidence: a file path, a line number, a presence/absence boolean, a count.
  3. Last step compares evidence to a threshold.

Concrete commands:

# Inline grep recipes the agent can run. Note: ripgrep has no 'tsx' type: '--type=ts' covers *.ts and *.tsx.
rg 'pattern' --type=ts src/

False-positive guards:

  • Skip files that already have the expected pattern.
  • Skip files with // ax-audit-ignore:<this-slug> near the match.
  • Skip test and Storybook fixtures.

Fix

Concrete change with the architectural pattern:

// before: the anti-pattern

// after: the corrected pattern

Default tier and overrides

Defaults to: <tier>

Surface Tier
Agent tool execution <usually one tier higher>
Agent chat <same or one tier lower>
Agent config <same>
Agent dashboard <usually one tier lower>

Cover every surface listed in surfaces:. A missing row hands that surface to the generic bump in references/ship-readiness.md, so the table is required even when every row just repeats defaultTier: the repetition is what suppresses the bump. When a row does not follow the shape above, say why in one line under the table (shared orchestrator code does not taper by surface; a flexibility ceiling does not rise on tool execution).

Examples

Anti-pattern (fails):

// Real-world example showing the bug.

Applied (passes):

// Same component with the fix applied.

Suppression

Ignore this rule on a specific component:

{/* ax-audit-ignore:<slug>, reason */}
<Component />

Source: SKILL.md on GitHub

No alerts13d3 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a specialized auditing framework for AI agent products, focusing on architectural integrity and user trust. It uses standard shell tools for static analysis of codebases. The analysis found no malicious behavior, obfuscation, or data exfiltration risks.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 57eb304. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for mblode/agent-skills/ax-audit