Skip to content
Back to skills

Ai Features Readiness

ASecurity

Use when a product calls a language model or other AI API, embeds AI-generated content, or offers a chatbot, and you need to check provider keys and exposure, what user data reaches the provider, disclosure that users are dealing with AI, abuse and cost controls, and failure behavior. Do not use it to add a generic AI disclaimer to a product with no user-facing AI, to judge model quality, or to interpret AI regulation.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agentsrustgonodeapidocumentation

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add moh-obaida/ReadyVibe-Skills --skill ai-features-readiness --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ai Features Readiness?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ai Features Readiness
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/moh-obaida-ai-features-readiness/badge)](https://www.skillsdirectory.com/skills/moh-obaida-ai-features-readiness)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ai-features-readiness
description: "Use when a product calls a language model or other AI API, embeds AI-generated content, or offers a chatbot, and you need to check provider keys and exposure, what user data reaches the provider, disclosure that users are dealing with AI, abuse and cost controls, and failure behavior. Do not use it to add a generic AI disclaimer to a product with no user-facing AI, to judge model quality, or to interpret AI regulation."
license: Apache-2.0
metadata:
  kind: specialist
  compliance-domains: "9,11"
  launch-checks: "38"
  helpers: "scan-secrets"
  references: "official-sources"
  companions: "design-system-reconnaissance"
---

# ai-features-readiness

AI features fail launch in predictable ways: an API key in the browser bundle, unlimited free usage that runs up a bill, user data sent to a provider nobody disclosed, and a "support agent" that is a model with no human route.

## Activate when

- Source calls a model API (OpenAI, Anthropic, Gemini, Mistral, Replicate, Hugging Face, Vercel AI SDK, LangChain, etc.), embeds an AI widget, or the copy mentions AI/assistant/copilot/generated.
- Not when there is no AI feature (say so and stop).

## Working alone

This skill is self-contained. Its **companions** (declared in its metadata) are skills whose method it may need to do its own promised work. Use of a companion can be conditional: declaring one does not mean running it. When a companion's lane applies, use the skill if it is installed; if not, follow its short entry in [references/companion-methods.md](references/companion-methods.md) and say in your report which lanes ran inline at reduced depth. Never skip an applicable lane silently. Skills mentioned here only for escalation, referral, documentation, or optional deeper follow-up are not dependencies: report the hand-off and finish honestly.

Companions: `design-system-reconnaissance`.

## Inspect

1. **Inventory:** providers, models, endpoints, where calls originate (browser vs server), streaming, tools/agents with side effects, retrieval sources.
2. **Key exposure:** `node scripts/scan-secrets.mjs --root .` (paths relative to this skill's folder). Provider keys must be server-side only: no `NEXT_PUBLIC_`/`VITE_` keys, none in bundles, source maps, or client fetches. Confirm the browser talks to *your* API route, not the provider directly with a key.
3. **Data to the provider:** what user input, files, or account data is included in prompts; system prompts containing secrets or private data; conversation logging; whether the disclosure names the provider and states what is sent (`policy-consistency`, `data-flow-mapping`); provider settings on training/retention are owner-side (UNKNOWN unless documented).
4. **Abuse and cost:** auth or rate limits on the AI route; per-user/IP quotas; max tokens and request size; prompt-injection blast radius (can model output trigger actions, browse, run code, send email? What guards exist?); output rendered as HTML (XSS) or executed.
5. **User-facing honesty:** AI-generated output identified where a visitor could mistake it for human or verified content; chatbot presents as a bot; no invented human agents or testimonials generated by AI (`content-trust`).
6. **Failure behavior:** timeouts, provider errors, rate limits, empty responses, refusals: does the UI recover (`failure-resilience`)?
7. **Domain risk:** medical, legal, financial, or children's advice via AI: `regulated-domain-triggers`.

## Evidence that counts

Label each claim OBSERVED, SOURCE-INDICATED, DECLARED, INFERRED, UNKNOWN, or REVIEW REQUIRED. UNKNOWN is never a pass and never a failure.

- A key in source is SOURCE-INDICATED; treat as exposed if it appears in client-shipped output (OBSERVED via scan) and report without printing the value.
- Provider retention/training settings are DECLARED or UNKNOWN unless the owner shows the account setting.
- Prompt-injection resilience is not provable by inspection: say "not tested" or describe the specific tests run.
- **Legal specifics: never from memory.** When a rule, deadline, threshold, or required wording matters, read the current text or guidance at an official source while you run (start from [references/official-sources.md](references/official-sources.md)), cite the source and access date, and treat applicability to this business as REVIEW REQUIRED. If you cannot look it up, the answer is UNKNOWN.

## May change

**Design first.** Before creating or changing anything visible, inspect the project's existing design system (`design-system-reconnaissance`) and build from its tokens and components, by the component ladder: reuse, compose, extend, and only then create a matching component. Never impose a ReadyVibe look on the user's site.

Move the provider call to a server route; read the key from server env; add basic auth/rate limiting and max-token caps where the project has a pattern; escape/sanitize rendered output; add a user-visible "AI-generated" note and a human contact route the owner has; correct disclosure to name the provider and data sent. Never rotate or use a key; never add a generic "AI may be wrong" banner where no user-facing AI exists.

## Must not claim

"Safe", "private", "your data is never used for training", "no hallucinations", "compliant with AI regulation". Do not state provider policies from memory.

## Verify

Re-run the secret scan on rebuilt output; confirm the network tab shows calls only to first-party routes; test an over-limit request and a provider-failure path; check that disclosures match the flows.

## Escalate

An exposed provider key (HIGH; owner must rotate); sensitive data or minors' data going to a provider; agents with destructive tools; regulated advice; automated decisions about people.

## No change is valid when

No AI provider, widget, or AI-generated content exists. Record the searches performed.

Files in this skill

  • SKILL.md5.8 KB
  • references/companion-methods.md2 KB
  • references/official-sources.md6.5 KB
  • scripts/lib/report.mjs3 KB
  • scripts/scan-secrets.mjs12.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…