ai-change-evidence

Installation
SKILL.md

AI Change Evidence

Change-management controls were written assuming a person made the change. When an agent writes the code and a person approves the pull request, the control still holds — but only if the record shows who decided what, and the record usually does not.

The goal is not to prove an agent was careful. It is to show the same things any change requires: it was authorized, it was reviewed by someone competent and separate, and it can be reconstructed.

1. Establish Where Agents Actually Contribute

Auditors ask about scope before controls. Determine, for the audit period:

  • Which repositories and services accept agent-authored changes
  • Which of those are in scope for the assessment
  • Whether agent commits are distinguishable from human ones at all

If commits are attributed to a human's identity with no marker, say so plainly rather than reconstructing it later. An unmarked population is a scoping problem, not a paperwork one.

2. Establish Provenance

For each in-scope change, the record should support:

Installs
36
First Seen
Sep 2, 2026
ai-change-evidence — securityskills/skills