All skills
mblode avatar

/ax-audit

@57eb304
by Matthew Blodemblode/agent-skills134 stars
12

Audits agentic products for tool parity, authority, approval payloads, recovery, and trust using 27 rules and a ship verdict. Use when asked for an "AX audit", to review an agent approval flow, or whether an agent can operate the product. For human-facing API ergonomics use dx-audit; for ordinary UI use ui-design.

Use this Skill: https://skilld.dev/gh/mblode/agent-skills/ax-audit

This session only. Nothing lands on disk.

rules-axcomm-no-generative-momentum.md

≈666 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Blank-canvas surface with no agent-generated starting content

User opens a new document, email, or report: empty canvas, blinking cursor, agent available but silent. A half-written draft is easier to shape than an empty page, but the agent doesn't offer one.

What goes wrong

User clicks "New marketing email" in a tool that has their brand voice and audience data. Blank editor, agent idle. A contextual draft would have them editing in ten seconds.

Detection

Surfaces: agent-chat

Auditability: observational

Judgment signals:

  • Find creation surfaces (new/create routes, empty editors, blank composition areas).
  • Check whether agent-generated content or templates are offered on first load.
  • Flag blank-canvas surfaces with no generative starting point where the agent has enough context.

Concrete commands:

rg '(/new|/create|/compose|/draft)' --type=ts -l src/
rg '(EmptyState|BlankCanvas|emptyDocument|initialContent:\s*["'"'"']{2})' --type=ts -l src/
rg '(generateDraft|suggestDraft|aiDraft|startWithAI|TemplatePicker)' --type=ts -l src/

False-positive guards:

  • Skip files with // ax-audit-ignore:comm-no-generative-momentum.
  • Skip test/Storybook fixtures and code editors where blank is the expected state.

Fix

Offer an agent-generated draft on blank-canvas surfaces: "Start with AI draft" button, template suggestions, or outline. Always let the user dismiss and start from scratch.

Default tier and overrides

Defaults to: backlog

Surface Tier
Agent chat backlog
Agent config backlog

Examples

Anti-pattern (fails):

export function NewReport() {
  // Agent has project data, metrics, goals: offers nothing
  return <RichTextEditor initialContent="" />;
}

Applied (passes):

export function NewReport() {
  const project = useProject();
  const { suggestion, dismiss } = useAgentSuggestion({
    prompt: `Draft a report outline for ${project.name}`,
  });
  return (
    <div>
      {suggestion && (
        <Banner onAccept={() => editor.setContent(suggestion)} onDismiss={dismiss}>
          Start with AI outline?
        </Banner>)}
      <RichTextEditor ref={editor} />
    </div>
  );
}

Suppression

{/* ax-audit-ignore:comm-no-generative-momentum, code editor, blank canvas is intentional */}
<CodeEditor />

Source: SKILL.md on GitHub

No alerts13d3 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a specialized auditing framework for AI agent products, focusing on architectural integrity and user trust. It uses standard shell tools for static analysis of codebases. The analysis found no malicious behavior, obfuscation, or data exfiltration risks.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 57eb304. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for mblode/agent-skills/ax-audit