Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    ai agent governance audit

    2

    Audit agentic systems against runtime controls and generate compliance artifacts for ISO 42001 and NIST AI RMF.

    $25

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    ai agent governance audit

    ai agent governance audit

    Example session with this skill installed

    We have a customer-support agent that can issue refunds up to $50. It uses a system prompt to stay in scope and a service account for Shopify. Is this safe to ship?

    • Read your context and instructions
    • Compiled the ai agent governance

    Finding: FAIL. System prompts are requests, not enforcement; prompt injection can bypass refund limits. Finding: FAIL. Service account lacks least-privilege. Status: UNVERIFIED for Containment. Recommendation: Implement a runtime cap at the API level and drill the kill switch before deployment.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Verify if an agent kill switch actually works under load.Map agent behaviors to NIST AI RMF and ISO 42001 controls.Enumerate and minimize over-privileged service account permissions.Test if an audit trail can actually reconstruct specific past actions.

    About this skill

    The problem

    Most AI governance is just a policy binder that ignores how agents actually behave. When an agent holds API keys, makes purchases, or deletes data, a "system prompt" is not a security control, and an unproven kill switch is a liability.

    What it does

    • Audits deployed agents against seven critical runtime controls, including containment, permission scope, and blast radius.
    • Differentiates between PASS, FAIL, and UNVERIFIED status based on evidence rather than architectural claims.
    • Identifies "decorative" human oversight where approval fatigue renders the human-in-the-loop ineffective.
    • Produces audit-ready findings mapped to ISO 42001, NIST AI RMF, and OWASP Agentic AI Top Ten.
    • Generates interview scripts and demonstration lists to force teams to prove their safety claims.

    Why this beats prompting it yourself

    General LLMs treat system prompts as enforcement and often hallucinate framework control IDs. This skill enforces a "test, don't trust" logic that prioritizes exploitability and runtime reality over paperwork, ensuring you don't submit fabricated citations to a real auditor.

    Use cases

    • Pre-deployment security reviews for agents with write-access to production databases or financial tools.
    • Post-incident reconstruction to determine how and why an agent performed an unintended action.
    • Preparing evidence and artifacts for ISO 42001 certification or NIST framework compliance.
    • Validating that multi-agent systems have sufficient circuit breakers to prevent cascading failures.

    Known limitations

    This is not a certification or attestation. It does not cover ML model bias or fairness auditing. It requires manual input of architectural details or interview responses to function.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 month ago

    • Passed all security checks, Safe to install

    Listed1 month ago
    Updated16 days ago

    Frequently Asked Questions