audit-trust-and-safety

Audit trust API surfaces, CSP, and safety-evidence pipelines for changes.

3|Updated Feb 3, 2026
One-click install
npx skills add https://github.com/equaltoai/lesser-host --skill audit-trust-and-safety
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-trust-and-safety
Source: https://github.com/equaltoai/lesser-host/tree/main/.codex/skills/audit-trust-and-safety
Command: npx skills add https://github.com/equaltoai/lesser-host --skill audit-trust-and-safety

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Changes to the trust API surface, attestation integrity, instance authentication, CSP, or AI-evidence services carry risk of weakening security posture or governance. This skill provides a rigorous audit cadence to detect, document, and safeguard these surfaces before deployment.

Core Features & Use Cases

  • Comprehensive review of trust API contracts, attestation integrity, instance-auth flows, CSP headers, and safety/evidence pipelines.
  • Generates governance-ready audit reports that summarize risk, impacted surfaces, and recommended mitigations; facilitates cross-team collaboration with security, product, and legal stakeholders.
  • Enables traceability for changes, evidence requirements, and compliance checks across MCP tooling and deployment pipelines.

Quick Start

Audit a proposed change affecting trust API surfaces, attestation shape, CSP, and safety-evidence components and generate an audit-ready report.

Frequently Asked Questions about audit-trust-and-safety

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit changes affecting CSP policies and trust API surfaces?

Auditing changes to CSP policies and trust API surfaces involves enforcing a structured evaluation of surface contracts, attestation integrity, key-hash authentication, and safety-evidence workflows. This process detects governance risks and generates a mitigation report before deployment.

What is attestation integrity and when do I need to audit it?

Attestation integrity is the validation of trust signals within attestation pipelines, typically found in /.well-known/* or /attestations/* paths. You need to audit it when changes impact instance-auth flows or safety-evidence workflows to prevent weakening your security posture.

How do I generate governance-ready audit reports for safety-evidence pipelines?

Generate governance-ready audit reports by applying a structured evaluation to changes touching safety-evidence pipelines and CSP directives. The resulting report summarizes risk, impacted surfaces, and recommended mitigations to facilitate cross-team collaboration.

Can I use this audit process for changes across both web and API layers?

Yes, you can audit changes across both web and API layers. The evaluation explicitly covers CSP policies, instance-auth, and trust API surfaces spanning both layers, ensuring comprehensive governance and risk documentation for the entire deployment.

Does instance-auth key-hash authentication review support MCP tooling compliance checks?

Yes, reviewing instance-auth key-hash authentication supports MCP tooling compliance checks. The audit enables traceability for changes, evidence requirements, and compliance checks across MCP tooling and deployment pipelines.