All skills
mblode avatar

/ax-audit

@57eb304
by Matthew Blodemblode/agent-skills134 stars
12

Audits agentic products for tool parity, authority, approval payloads, recovery, and trust using 27 rules and a ship verdict. Use when asked for an "AX audit", to review an agent approval flow, or whether an agent can operate the product. For human-facing API ergonomics use dx-audit; for ordinary UI use ui-design.

Use this Skill: https://skilld.dev/gh/mblode/agent-skills/ax-audit

This session only. Nothing lands on disk.

rules-axcontext-no-adaptive-canvas.md

≈821 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Interface static during agent task progression

Agent moves through phases (researching, drafting, reviewing, complete) but the UI looks identical in each. No phase indicator, no layout change, no context-appropriate tools surfaced. Adaptive Canvas requires the interface to reshape around the agent's current activity.

What goes wrong

Agent starts a research task. User sees "Searching..." then nothing changes for 45 seconds. The agent transitions through phases but the layout never shifts: no stepper, no phase-specific controls. The user can't tell where the agent is or how close to done.

Detection

Surfaces: agent-config

Auditability: code-auditable

Static signals:

  1. Find agent workflow state: phase, status, or stage enums/state machines.
  2. Check whether rendering differs across phases (conditional rendering, different components per phase).
  3. Flag workflows where UI is identical regardless of agent phase.
  4. In chat surfaces, look for per-phase rendering of stream parts: a component chosen on part.type for data-* and tool parts, or MCP Apps ui:// resources per tool. A chat that renders only text parts while part.type carries tool and step states has the phase information and drops it.

Concrete commands:

rg '(phase|stage|status|workflow).*(enum|type|const)' --type=ts src/
rg '(stateMachine|createMachine|useReducer|switch.*phase)' --type=ts src/
rg '(Stepper|ProgressBar|PhaseIndicator|StageIndicator)' --type=ts -l src/
rg -n "part\.type|case ['\"]data-|ui://" --type=ts src/components/

False-positive guards:

  • Skip files with // ax-audit-ignore:context-no-adaptive-canvas.
  • Skip test and Storybook fixtures.
  • Skip single-step agent interactions where no multi-phase workflow exists.

Fix

Show a phase indicator (stepper, progress bar). Surface phase-appropriate tools (research tools during research, editing tools during review). Reshape the layout to match the current activity.

Default tier and overrides

Defaults to: backlog

Surface Tier
Agent tool execution fix-this-sprint
Agent dashboard backlog
Agent config backlog

Examples

Anti-pattern (fails):

function ResearchAgent({ status }: { status: string }) {
  // status is "searching" | "analyzing" | "complete": UI never changes
  return <div className="flex"><ChatPanel /><Sidebar /></div>;
}

Applied (passes):

function ResearchAgent({ status, data }: { status: AgentStatus; data: AgentData }) {
  return (
    <div>
      <Stepper steps={["Searching", "Analyzing", "Complete"]} current={status} />
      {status === "searching" && <SearchProgress queries={data.queries} />}
      {status === "analyzing" && <AnalysisView sources={data.sources} />}
      {status === "complete" && <ResultsView results={data.results} />}
    </div>
  );
}

Suppression

{/* ax-audit-ignore:context-no-adaptive-canvas, single-turn chat, no multi-phase workflow */}
<AgentChat />

Source: SKILL.md on GitHub

No alerts13d3 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a specialized auditing framework for AI agent products, focusing on architectural integrity and user trust. It uses standard shell tools for static analysis of codebases. The analysis found no malicious behavior, obfuscation, or data exfiltration risks.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 57eb304. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for mblode/agent-skills/ax-audit