All skills
mblode avatar

/ax-audit

@57eb304
by Matthew Blodemblode/agent-skills134 stars
12

Audits agentic products for tool parity, authority, approval payloads, recovery, and trust using 27 rules and a ship verdict. Use when asked for an "AX audit", to review an agent approval flow, or whether an agent can operate the product. For human-facing API ergonomics use dx-audit; for ordinary UI use ui-design.

Use this Skill: https://skilld.dev/gh/mblode/agent-skills/ax-audit

This session only. Nothing lands on disk.

rules-axcontrol-no-escape-hatch.md

≈843 tokens on demand. Your agent reads this file only when SKILL.md points to it.

No way to interrupt, redirect, or undo agent action

Agent starts a long response or multi-step workflow. User realizes it's wrong but there's no stop, undo, or "go back": they watch it do the wrong thing and can't intervene. Autonomy without exit is coercion.

What goes wrong

User asks the agent to refactor a module. It begins a 12-step migration; at step 3 the user sees it's wrong. No stop button: it runs to completion, leaving the codebase in an unwanted state. Manual revert takes longer than doing it themselves.

Detection

Surfaces: agent-chat, agent-tool-execution

Auditability: hybrid

Static signals:

  1. Find agent execution UI (chat panels, action panels, tool execution views).
  2. Check for cancel/stop during execution (onCancel, AbortController, useChat().stop, query.interrupt).
  3. Trace the signal to the server. stop() aborts the client fetch; the route has to pass req.signal as abortSignal into streamText (or the loop), and each tool's execute has to read it, or the executor finishes every remaining call after Stop.
  4. Check for undo/revert after completion. Flag flows with neither.

Concrete commands:

rg -l 'AbortController|onCancel|stopGenerat' --type=ts src/
rg -A 10 'isGenerating|isStreaming|isPending' --type=ts src/ | rg -v 'cancel|stop|abort'
rg -n 'abortSignal|req\.signal|request\.signal' --type=ts src/app/api/ src/server/

Judgment signals:

  • A cancel button not wired to AbortController.abort() is a false affordance, worse than nothing.
  • A stop() that closes the stream while the server loop keeps executing tools is the same false affordance one layer down: the UI goes quiet and the emails still go out.

False-positive guards:

  • Skip // ax-audit-ignore:control-no-escape-hatch, test, and Storybook files.

Fix

During execution: stop button wired to AbortController, and the signal threaded through the route into the loop and each tool. After completion: undo/revert for reversible actions. For irreversible actions, the approval gate (control-no-approval-gate) is the pre-execution escape hatch.

Examples

Anti-pattern (fails):

<div>
  {messages.map((m) => <Message key={m.id} {...m} />)}
  {isGenerating && <Spinner />}
  {/* no stop button, no undo */}
</div>

Applied (passes):

<div>
  {messages.map((m) => <Message key={m.id} {...m} />)}
  {isGenerating && (
    <>
      <Spinner />
      <Button onClick={onStop} aria-label="Stop generating">Stop</Button>
    </>
  )}
  {!isGenerating && <Button onClick={onUndo} variant="ghost">Undo</Button>}
</div>

Default tier and overrides

Defaults to: release-blocker

Surface Tier
Agent tool execution release-blocker
Agent chat release-blocker
Agent config fix-this-sprint
Agent dashboard fix-this-sprint

Suppression

{/* ax-audit-ignore:control-no-escape-hatch, single status check, completes in <1s */}
<StatusCheckResult result={result} />

Source: SKILL.md on GitHub

No alerts13d3 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a specialized auditing framework for AI agent products, focusing on architectural integrity and user trust. It uses standard shell tools for static analysis of codebases. The analysis found no malicious behavior, obfuscation, or data exfiltration risks.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 57eb304. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for mblode/agent-skills/ax-audit