All skills
mblode avatar

/ax-audit

@57eb304
by Matthew Blodemblode/agent-skills134 stars
12

Audits agentic products for tool parity, authority, approval payloads, recovery, and trust using 27 rules and a ship verdict. Use when asked for an "AX audit", to review an agent approval flow, or whether an agent can operate the product. For human-facing API ergonomics use dx-audit; for ordinary UI use ui-design.

Use this Skill: https://skilld.dev/gh/mblode/agent-skills/ax-audit

This session only. Nothing lands on disk.

rules-archcontext-no-injection.md

≈663 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Agent session starts without knowing what data exists

Static system prompt, no dynamic context. Every session starts ignorant of projects, preferences, and prior work that already exists. Violates Improvement Over Time: each session should build on the last.

What goes wrong

User opens a design review agent for the third time today. It has no memory of earlier sessions, the 5 files reviewed, or the user's accessibility-first preference. It asks "What would you like me to review?" again.

Detection

Surfaces: agent-chat

Static signals:

  1. Find session initialization: agent constructors, chat init, session start handlers.
  2. Check whether initialization loads dynamic context (context files, preferences, recent activity).
  3. Flag sessions that use only static/hardcoded prompt content.

Concrete commands:

rg '(new Agent|createAgent|initSession|startChat)' --type=ts -A 15 src/
rg 'messages\s*[:=]\s*\[' --type=ts -A 5 src/ | rg 'role.*system' | rg -v 'await|fetch|load|get'
rg '(context\.md|loadContext|getContext|sessionContext)' --type=ts src/

False-positive guards:

  • Skip files with // ax-audit-ignore:context-no-injection.
  • Skip test files and fixtures.
  • Skip constructors where context is injected by a parent orchestrator.

Fix

// before: static initialization
function createSession(userId: string) {
  return { messages: [{ role: "system", content: STATIC_PROMPT }] };
}

// after: read context.md at session start
async function createSession(userId: string) {
  const ctx = await readContextFile(userId);
  const prefs = await getUserPreferences(userId);
  return {
    messages: [{ role: "system", content: `${STATIC_PROMPT}\n\n${ctx}\n\n${prefs.summary}` }],
  };
}

Default tier and overrides

Defaults to: fix-this-sprint

Surface Tier
Agent chat release-blocker
Agent tool execution fix-this-sprint
Agent config backlog
Agent dashboard backlog

Examples

Anti-pattern (fails): private messages = [{ role: "system", content: "You review code." }]

Applied (passes): static async create(uid) { const ctx = await loadProjectContext(uid); ... }

Suppression

// ax-audit-ignore:context-no-injection, stateless utility agent, no user context needed
const agent = new StatelessAgent(STATIC_PROMPT);

Source: SKILL.md on GitHub

No alerts13d3 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a specialized auditing framework for AI agent products, focusing on architectural integrity and user trust. It uses standard shell tools for static analysis of codebases. The analysis found no malicious behavior, obfuscation, or data exfiltration risks.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 57eb304. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for mblode/agent-skills/ax-audit