AI, RAG & ML · Audit
AI Safety & Governance Audit
Audit an AI release for misuse, harmful output, privacy, accountability, evaluation evidence, human control, and rollback governance.
Vibe Coding 1.3.0 · vibe-ai · English technical instructions
Use this workflow
Use this workflow in Codex or Claude Code with the free Vibe Coding plugin. Choose your assistant and prompt language, then add your task details after the prompt.
Operation
Inspect the named boundary and report supported findings. Do not edit product code. Include concrete evidence, impact, the owning source, one remediation direction and a meaningful validation route. Severity follows actual impact, not a category example.
Goal and scope
Audit an AI release for misuse, harmful output, privacy, accountability, evaluation evidence, human control, and rollback governance.
Domain invariants
- Intended use, excluded use, affected users, risk owners, human control, and escalation paths are explicit.
- Safety and policy controls are enforced at input/tool/output/product boundaries and tested against reachable misuse.
- Data/model/prompt/tool provenance, evaluation results, approvals, release identity, monitoring, and incident evidence are retained appropriately.
- Disable, rollback, correction, user reporting, and remediation paths exist for harmful or materially wrong behavior.
Audit method
- Define the concrete harm/misuse scenarios and map them to feature capabilities, users, data, tools, and side effects.
- Inspect policy implementation, refusal/guardrails, human review, overrides, logging, appeal/correction, and incident ownership.
- Review evaluation coverage by risk slice, adversarial inputs, false-positive/negative tradeoffs, and model/provider change.
- Check privacy, retention, consent, third-party terms, and cross-tenant exposure from repository evidence.
Priority model
- P0: unsafe action, privacy or tenant leak, materially wrong irreversible decision, corrupted model/data lineage, or critical service failure.
- P1: a reachable quality, grounding, evaluation, serving, cost, or governance defect with clear product impact.
- P2: a lower-risk but concrete robustness, observability, dataset, or maintainability issue.
Workflow ID: ai-safety-governance-audit · View the versioned source · Shared workflow and authority rules