All skills
mblode avatar

/ax-audit

@57eb304
by Matthew Blodemblode/agent-skills134 stars
12

Audits agentic products for tool parity, authority, approval payloads, recovery, and trust using 27 rules and a ship verdict. Use when asked for an "AX audit", to review an agent approval flow, or whether an agent can operate the product. For human-facing API ergonomics use dx-audit; for ordinary UI use ui-design.

Use this Skill: https://skilld.dev/gh/mblode/agent-skills/ax-audit

This session only. Nothing lands on disk.

rules-axcontrol-over-conversational.md

≈648 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Chat interface for actions that should be buttons

User wants to toggle a setting or trigger a known action, but chat is the only interface. They type "turn on dark mode" and wait for a round-trip instead of flipping a switch. Chat is the ONLY path to deterministic actions.

What goes wrong

User types "enable dark mode" in chat; agent responds after 2 seconds. A toggle would take 50ms. Multiply across every simple action and chat becomes a bottleneck.

Detection

Surfaces: agent-chat

Auditability: observational

Static signals:

  1. Find chat input surfaces.
  2. Identify deterministic actions achievable through chat (toggles, selections, CRUD).
  3. Flag cases where chat is the only path to a simple action.

Concrete commands:

rg -l 'ChatInput|MessageInput|PromptInput' --type=ts src/
rg -l 'Toggle|Switch|Select|Dropdown' --type=ts src/components/

Judgment signals:

  • The anti-pattern is chat-only for deterministic actions. Some conversational interface is expected.
  • Controls rendered inside the chat stream count: an MCP Apps ui:// resource or an AI SDK data-* part that renders a real toggle, table, or picker is direct manipulation. The fail is a text box as the only path.

False-positive guards:

  • Skip // ax-audit-ignore:control-over-conversational, test, and Storybook files.

Fix

Add direct-manipulation controls alongside chat: quick-action buttons, command palette, context menus. Keep chat for ambiguous or multi-step requests.

Examples

Anti-pattern (fails):

<div>
  <DataTable data={data} />
  <AgentChat onSend={handleAgentCommand} /> {/* no sort, filter, or action controls */}
</div>

Applied (passes):

<div>
  <DataTable data={data} onSort={handleSort} sortable />
  <QuickActions actions={[{ label: "Export CSV", handler: exportCsv }]} />
  <AgentChat onSend={handleAgentCommand} />
</div>

Default tier and overrides

Defaults to: fix-this-sprint

Surface Tier
Agent tool execution backlog
Agent chat fix-this-sprint
Agent config fix-this-sprint
Agent dashboard fix-this-sprint

Suppression

{/* ax-audit-ignore:control-over-conversational, chat-first product by design */}
<AgentChat onSend={onSend} />

Source: SKILL.md on GitHub

No alerts13d3 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a specialized auditing framework for AI agent products, focusing on architectural integrity and user trust. It uses standard shell tools for static analysis of codebases. The analysis found no malicious behavior, obfuscation, or data exfiltration risks.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 57eb304. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for mblode/agent-skills/ax-audit