All skills
mblode avatar

/ax-audit

@57eb304
by Matthew Blodemblode/agent-skills134 stars
12

Audits agentic products for tool parity, authority, approval payloads, recovery, and trust using 27 rules and a ship verdict. Use when asked for an "AX audit", to review an agent approval flow, or whether an agent can operate the product. For human-facing API ergonomics use dx-audit; for ordinary UI use ui-design.

Use this Skill: https://skilld.dev/gh/mblode/agent-skills/ax-audit

This session only. Nothing lands on disk.

rules-axtrust-no-escalation-path.md

≈708 tokens on demand. Your agent reads this file only when SKILL.md points to it.

High-stakes agent action with no human escalation

Agent handles a refund, medical question, or legal inquiry with no way to hand off to a human: it gives a dangerous answer or refuses entirely. An escalation path is the trust floor.

What goes wrong

User asks about a billing dispute. Agent applies a partial credit that doesn't match. No "talk to a person" button. It keeps trying, makes things worse, user files a chargeback.

Detection

Surfaces: agent-tool-execution

Auditability: code-auditable

Static signals:

  1. Find action handlers for high-stakes operations (financial, medical, legal, account deletion).
  2. Check for escalation/handoff logic. Flag high-stakes handlers with no escalation path.

Concrete commands:

rg -l 'refund|payment|delete.*account|send.*email|legal|medical' --type=ts src/
rg 'escalat|handoff|transfer.*human|transfer.*agent' --type=ts src/

Judgment signals:

  • An escalation tool never referenced in the system prompt is effectively invisible.
  • Escalation is a handoff to a human. Refusal is declining a request the agent cannot safely complete. Improvising the nearest write to real state is not a success, and is not fixed by adding an escalate button.

False-positive guards:

  • Skip // ax-audit-ignore:trust-no-escalation-path, test, and Storybook files.

Fix

Add escalate_to_human(reason, context) as an agent tool. Surface it in the UI as "Talk to a person."

Examples

Anti-pattern (fails):

const agentTools = {
  processRefund: async (amount: number) => {
    await api.refund(amount);
    return { success: true, message: "Refund processed." };
  },
};

Applied (passes):

const agentTools = {
  processRefund: async (amount: number) => {
    if (amount > ESCALATION_THRESHOLD) return { escalate: true, reason: "Exceeds limit" };
    await api.refund(amount);
    return { success: true };
  },
  escalateToHuman: async (reason: string, ctx: AgentContext) => {
    await support.transfer({ reason, transcript: ctx.messages });
    return { message: "Connecting you with a team member." };
  },
};

Default tier and overrides

Defaults to: release-blocker

Surface Tier
Agent tool execution release-blocker
Agent chat release-blocker
Agent config backlog
Agent dashboard fix-this-sprint

Suppression

{/* ax-audit-ignore:trust-no-escalation-path, internal admin tool, operator is the human */}
<AgentToolPanel tools={adminTools} />

Source: SKILL.md on GitHub

No alerts13d3 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a specialized auditing framework for AI agent products, focusing on architectural integrity and user trust. It uses standard shell tools for static analysis of codebases. The analysis found no malicious behavior, obfuscation, or data exfiltration risks.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 57eb304. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for mblode/agent-skills/ax-audit