一键导入
trust-audit
Audit whether a product feels trustworthy or unsafe — covering permissions, privacy, billing, file mutation, and silent-failure surfaces.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Audit whether a product feels trustworthy or unsafe — covering permissions, privacy, billing, file mutation, and silent-failure surfaces.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Audit chezmoi dotfiles for drift, unmanaged files, and broken agent skill symlinks across Claude Code, Codex, Gemini, and other harnesses.
Scan Claude/Codex session logs to find agent behavior patterns, Toolsmith adoption gaps, repeated frustrations, and candidates for new skills/tools.
Generate user-facing changelog entries from git history — plain language, audience-segmented, with optional CHANGELOG.md update.
Consolidate/dedupe contacts from macOS, iCloud, Google, Zoho, or VCF with provenance-aware review, backups, and optional approved dossiers.
Capture a technical or product decision with chosen option, rejected alternatives, and rationale — in a format a future agent can read to reconstruct context.
Audit repos for SHA/digest dependency pinning and release cooldowns across Docker, CI, and major language ecosystems; report violations, fix with approval.
| name | trust-audit |
| description | Audit whether a product feels trustworthy or unsafe — covering permissions, privacy, billing, file mutation, and silent-failure surfaces. |
| display_name | Trust Audit |
| brand_color | #059669 |
| local_only | false |
| group | Product & Launch |
| usage | /trust-audit:run |
| summary | Find the moments your product feels sketchy — surprise charges, scary permissions, silent failures — and close the trust gaps. |
| favorite | true |
| default_prompt | Audit this product or feature for trust risks: permissions, privacy, billing, surprise mutations, and anything that feels creepy or unsafe. |
Use this skill to answer the question beneath many launch failures: “Will a normal user feel safe, respected, and in control?”
A trust audit is not a security review. It is a perception-and-reality review of the places where users feel:
Use this skill when reviewing:
Trust breaks when there is a mismatch between:
Audit both the reality and the vibe. A technically defensible flow can still feel shady.
Read enough context to map:
Then summarize in 5-10 bullets:
Evaluate each of these explicitly.
Ask:
Ask:
Ask:
Ask:
Ask:
Produce 6-12 concrete trust risks. For each, include:
Split findings into:
Do not flatten them together.
Use this format:
# Trust Audit: [Product / Feature]
## Executive Read
- Biggest trust risk:
- Most likely “creepy” interpretation:
- Most likely “I got tricked” interpretation:
- Most dangerous file/data surprise:
## Trust Surface Map
- Consent:
- Data flow:
- File/state mutation:
- Billing:
- Degraded-mode honesty:
## High-Risk Trust Failures
### 1. [Title]
**Trust failure:**
**What the user expected:**
**What actually happens:**
**Why this feels bad:**
**Likely reaction:**
**Type:**
**Repair move:**
## Medium-Risk Trust Failures
...
## Trust Theater vs Real Hazard
- Trust theater:
- Real hazard:
## Copy / UX Fixes to Make Immediately
1. [ ]
2. [ ]
3. [ ]
## The Sentence Users Might Say
> “[one-sentence trust-damaging story]”
The audit is complete when it identifies: