All skills
mblode avatar

/ax-audit

@57eb304
by Matthew Blodemblode/agent-skills136 stars
12

Audits agentic products for tool parity, authority, approval payloads, recovery, and trust using 27 rules and a ship verdict. Use when asked for an "AX audit", to review an agent approval flow, or whether an agent can operate the product. For human-facing API ergonomics use dx-audit; for ordinary UI use ui-design.

Use this Skill: https://skilld.dev/gh/mblode/agent-skills/ax-audit

This session only. Nothing lands on disk.

rules-axcontext-under-contextual.md

≈743 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Agent ignores available context it should use

The system has the user's project history, preferences, recent activity, and team context, but the agent's prompt includes none of it. The agent asks questions it should already know the answer to, wasting time and making it feel stupid.

What goes wrong

User opens a project page and asks "help me write a status update." Agent responds: "What project are you working on?" The project name, recent commits, and open tickets are all in app state, but the prompt ignores them. Every needless question erodes confidence.

Detection

Surfaces: agent-tool-execution

Auditability: hybrid

Static signals:

  1. Catalog available context sources (user profile, project state, recent activity, team info).
  2. Find agent prompt/context assembly functions.
  3. Check whether available sources are referenced in context injection.
  4. Flag significant context sources never passed to the agent.

Concrete commands:

rg '(useUser|useProject|useTeam|useActivity|currentProject|activeWorkspace)' --type=ts -l src/
rg '(buildPrompt|systemPrompt|assembleContext|getAgentContext)' --type=ts -l src/
rg -A 15 '(buildPrompt|assembleContext|getAgentContext)' --type=ts src/

Judgment signals:

  • Would a human assistant in this position already know the answer?
  • Is the missing context high-signal (project name, recent activity) or low-signal?

False-positive guards:

  • Skip files with // ax-audit-ignore:context-under-contextual.
  • Skip test/Storybook fixtures and generic agent surfaces with no page-specific context.

Fix

Inject relevant context at session start using the context.md pattern: "What I Know About This User," "What Exists," "Recent Activity." Update dynamically during the session.

Default tier and overrides

Defaults to: backlog

Surface Tier
Agent tool execution fix-this-sprint
Agent chat backlog

Examples

Anti-pattern (fails):

// User is on /projects/acme-redesign but agent gets no project context
export function ProjectAgent() {
  const { sendMessage } = useAgent({ system: "You are a helpful assistant." });
  return <AgentChat onSend={sendMessage} />;
}

Applied (passes):

export function ProjectAgent() {
  const project = useProject();
  const activity = useRecentActivity(project.id);
  const { sendMessage } = useAgent({
    system: `Assistant for ${project.name}. Recent: ${activity.map((a) => a.summary).join("; ")}`,
  });
  return <AgentChat onSend={sendMessage} />;
}

Suppression

{/* ax-audit-ignore:context-under-contextual, generic help chat, no page context needed */}
<HelpAgent />

Source: SKILL.md on GitHub

No alerts13d3 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a specialized auditing framework for AI agent products, focusing on architectural integrity and user trust. It uses standard shell tools for static analysis of codebases. The analysis found no malicious behavior, obfuscation, or data exfiltration risks.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 57eb304. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 32 minutes ago.

Activeupdated 2 weeks ago

README badge

README badge for mblode/agent-skills/ax-audit