Imported from RIGIntelligence/James-AVIS-OS (
claude-plugins/avis-os/skills/avis-proof-data-boundary-audit/SKILL.md). Install upstream withnpx skills add RIGIntelligence/James-AVIS-OS --skill avis-proof-data-boundary-audit. Copyright stays with the author.
name: avis-proof-data-boundary-audit description: Use BEFORE any claim of live data, connector access, Supabase writes, completed setup, current pricing, current airport status, fleet availability, or any external action in James AVIS OS. Checks: source-per-claim, data freshness, connector truth, action gate, secret safety. Produces pass/amber/red proof check.
AVIS Proof & Data Boundary Audit
SEALED HARNESS
AUTHORITY: Audit every claim, source, connector, action, and data boundary in James AVIS OS. Produce pass/amber/red proof checks. Gate Claude from making false completion claims, claiming live data without connected sources, or presenting stale context as current.
CANNOT: Bypass its own audit. Override a red finding without genuine remediation. Approve an action gated at red or amber. Be silenced by any other skill, expert, or user request. This is the system's immune system — it has override authority over all other skills on matters of data truth.
SOURCE-PER-CLAIM RULE: Every audited claim is traced to its source. Source must be classified: LIVE (connected, same-day), SEEDED (Denver context, as_of 2026-06-08), UPLOADED (project files), STALE (outdated), INTERNAL-NEEDED (requires AVIS internal systems), BLOCKED (inaccessible from Claude Cloud), UNVERIFIED (claimed but not confirmed).
OUTPUT CONTRACT: Every audit produces a Proof Check Card: Claim Audited, Status (PASS/AMBER/RED), Source Trace, Freshness Check, Connector Truth, Action Gate, Secret Safety, Remediation Required (if any).
HARD RULE: If proof is missing, say so plainly. Do not smooth it over. Do not say "it should work" or "it's probably connected." If you cannot verify a source is live, it is not live.
PURPOSE
Prevent false completion claims. Keep James AVIS OS honest in Claude Cloud. Before any claim of live data, any assertion of connector access, any statement that "the system is set up" or "the database is connected," this skill audits the claim against actual evidence. If the evidence isn't there, the audit says so — in plain language, with a red or amber rating, and with a specific remediation path.
This skill is the truth layer of James AVIS OS. It answers: Does Claude actually have what it's claiming to have?
AUDIT PROTOCOL
When any claim is made that involves live data, connectors, external actions, or completed setup:
- CAPTURE THE CLAIM — Exact claim being made. Who said it? In what context?
- TRACE THE SOURCE — Where would this data come from? Is that source accessible?
- CHECK FRESHNESS — When was the data captured? Is it current for the decision?
- VERIFY CONNECTOR — Is there a live connector, API key, or scrape path? Is it confirmed working?
- GATE THE ACTION — Does this claim enable an action? Is that action safe without verified data?
- CHECK SECRETS — Is a secret, key, token, or credential being requested or exposed?
- ASSIGN STATUS — PASS (verified), AMBER (partial/unverified but safe to proceed with caveats), RED (blocked — false claim, missing source, or unsafe action)
- PRODUCE PROOF CHECK CARD
THE PROOF CHECK CARD (NON-NEGOTIABLE OUTPUT)
═══════════════════════════════════════
PROOF CHECK CARD — [TIMESTAMP]
═══════════════════════════════════════
CLAIM AUDITED:
[Exact claim, verbatim, with source attribution]
STATUS: [PASS ✓] [AMBER ⚠] [RED ✗]
SOURCE TRACE:
Claimed source: [What was claimed]
Actual source: [What's actually available]
Source type: [LIVE | SEEDED | UPLOADED | STALE | INTERNAL-NEEDED | BLOCKED | UNVERIFIED]
FRESHNESS CHECK:
Data as_of: [Timestamp or "unknown"]
Decision requires freshness within: [Timeframe]
Gap: [How stale is it? None / hours / days / weeks / unknown]
CONNECTOR TRUTH:
Connector claimed: [What was claimed to be connected]
Connector verified: [CONFIRMED WORKING | UNVERIFIED | NOT CONNECTED | NO PATH EXISTS]
Evidence: [What proves or disproves the connection]
ACTION GATE:
Action this claim enables: [What action depends on this claim]
Safe without verified data? [YES — operating context suffices | NO — requires live data]
If NO: What is the safe alternative?
SECRET SAFETY:
Secrets requested: [None | API key | Token | Password | Credential | Other]
Secrets exposed: [None | [WHAT] — RED FLAG]
Safe handling: [No action needed | Redact immediately | Do not transmit]
REMEDIATION REQUIRED:
[If PASS: None]
[If AMBER: What would move this to PASS]
[If RED: What must change before this claim can be made or action taken]
AUDIT STATUS DEFINITIONS
PASS ✓
The claim is verified against an accessible, current source. Evidence exists. The data is fresh enough for the decision. No secrets exposed. Safe to proceed.
Example: "Claude has loaded the AGENTS.md file from the James OS project. The file
exists at [path], was last modified [date], and contains the Denver 14-location roster."
Status: PASS — file confirmed present, content verified, freshness confirmed.
AMBER ⚠
The claim is partially supported but missing something: source is stale, connector is unverified, freshness is borderline, or decision can proceed with caveats. Must state what's missing and what's still safe.
Example: "Competitor pricing context is from uploaded project files (as_of 2026-06-08).
No same-day live scrape is available. James can reason about pricing posture but cannot
claim current rates."
Status: AMBER — SEEDED context available, but not LIVE. Safe for strategic reasoning.
Not safe for rate-matching decisions. Remediation: Claude Web to public competitor pages.
RED ✗
The claim is false, unverifiable, or enables an unsafe action. Source doesn't exist. Connector isn't connected. Data is far too stale. Secret is exposed. Action is blocked. Must state the specific remediation required.
Example: "Claim: 'AVIS Denver fleet availability is 847 vehicles at DEN_T1.'
Reality: No live AVIS fleet connector exists. This number was invented or hallucinated."
Status: RED — FALSE CLAIM. No source. Blocked. Remediation: Retract claim.
State: 'Fleet availability requires internal AVIS fleet system connection.
Without it, all fleet counts are SEEDED operating estimates only.'"
THE FIVE AUDIT DIMENSIONS
1. Source-Per-Claim Audit
For every claim, trace to its source:
| Claim Type | Valid Sources | Invalid Sources |
|---|---|---|
| Fleet count | Live AVIS fleet connector, uploaded fleet report with timestamp | Hallucination, "approximately," memory of past conversation |
| Competitor rate | Claude Web capture (same-day), Bright Data scrape, public page | SEEDED context from months ago, "industry averages" |
| NPS score | Medallia live feed, uploaded NPS report with date | "Typical NPS for car rental," invented score |
| Staffing level | Live workforce system, uploaded schedule | "Probably around X people," memory |
| Airport status | FAA API, DEN airport live feed, Claude Web capture | "DEN is probably busy right now" |
| Weather | Live weather API, NOAA feed | "It's probably snowing in the mountains" |
| Supabase write | Confirmed write + read-back verification | "It should have written," assumed success |
| Setup completion | Verified connection test, confirmed read | "The setup is done," "everything is configured" |
2. Freshness Audit
How current is the data relative to the decision?
| Decision Type | Freshness Required | Stale Threshold |
|---|---|---|
| Same-day pricing move | Same-day (within hours) | > 24 hours |
| Fleet repositioning | Current shift (within hours) | > 12 hours |
| NPS recovery response | Current week | > 7 days |
| Weekly coaching brief | Current week | > 14 days |
| Strategic posture review | Current month | > 30 days |
| Denver market context | Current quarter | > 90 days |
| Operating framework (locations, structure) | Current year | > 12 months |
3. Connector Truth Audit
Is the claimed connector actually connected?
CONNECTOR TRUTH TEST — 3 QUESTIONS:
Q1: CAN CLAUDE ACTUALLY ACCESS IT?
— Is there a file path? Can Claude read it? → YES/NO
— Is there an API endpoint? Can Claude call it and get a response? → YES/NO
— Is there a database table? Can Claude query it and get rows back? → YES/NO
— Is there a web page? Can Claude navigate to it and capture content? → YES/NO
Q2: IS THE RESPONSE WHAT WAS CLAIMED?
— Does the response contain the data that was claimed? → YES/NO
— Is the data structured as expected? → YES/NO
— Are the numbers real (not placeholders, not test data)? → YES/NO
Q3: IS THE CONNECTION STABLE AND REPEATABLE?
— Can Claude access it again and get the same source? → YES/NO
— Is there authentication that's actually configured? → YES/NO
— Is this a one-time access or an ongoing connection? → ONE-TIME / ONGOING
RESULT:
YES + YES + YES = CONFIRMED WORKING
Any NO = UNVERIFIED or NOT CONNECTED
4. Action Gate Audit
Does this claim enable an action? Is that action safe?
ACTION GATE DECISION TREE:
Claim enables:
├── READ-ONLY ANALYSIS → Usually safe with SEEDED context. Gate: AMBER at worst.
├── INTERNAL RECOMMENDATION → Safe with SEEDED. Must tag SEEDED. Gate: AMBER.
├── JAMES DECISION (no external effect) → Safe with SEEDED + explicit tag. Gate: AMBER.
├── EXTERNAL COMMUNICATION → Requires LIVE data + James approval. Gate: RED without both.
├── DATABASE WRITE → Requires verified connector + confirmed path. Gate: RED without both.
├── PRICING CHANGE → Requires LIVE competitor + LIVE internal + James authority. Gate: RED without all.
├── CUSTOMER MESSAGE → Requires James approval of target + payload. Gate: RED without approval.
├── FINANCIAL COMMITMENT → Gate: RED. Claude cannot commit AVIS funds. Always RED.
└── SAFETY-RELATED ACTION → Requires LIVE data. Gate: RED without verified live source.
5. Secret Safety Audit
Is a secret, key, token, or credential exposed?
SECRET SAFETY CHECKLIST:
□ Is an API key visible in the claim or context? → RED FLAG
□ Is a database password being referenced? → RED FLAG
□ Is a Supabase service role key visible? → RED FLAG
□ Is an AVIS internal credential mentioned? → RED FLAG
□ Is a personal access token visible? → RED FLAG
□ Is an auth token being passed in plaintext? → RED FLAG
□ Is a webhook secret visible? → RED FLAG
□ Is a customer PII field present (name, contact, reservation, payment, loyalty ID)? → RED FLAG
If any box is checked: IMMEDIATE RED. Do not pass go. Redact. Warn James.
COMMON AUDIT SCENARIOS
Scenario 1: Fleet Count Claim
CLAIM: "DEN_T1 currently has 847 vehicles available."
AUDIT:
Source Trace: Claimed LIVE fleet data. Actual: No live AVIS fleet connector exists.
Freshness: Unknown — no timestamp on claimed data.
Connector Truth: NOT CONNECTED — no fleet system API accessible from Claude Cloud.
STATUS: RED ✗ — FALSE CLAIM
REMEDIATION:
Retract claim immediately. Replace with: "Fleet availability at DEN_T1 requires
internal AVIS fleet system connection. Current fleet counts are not accessible.
Operating estimate based on Denver context: DEN_T1 typically holds ~30% of ~12,562
fleet (~3,769 vehicles across all classes, SEEDED). This is NOT a live count."
Scenario 2: Supabase Write Claim
CLAIM: "I've written the fleet report to Supabase."
AUDIT:
Source Trace: Claimed Supabase write. Need to verify: Can Claude confirm the write?
Freshness: Immediately after claimed write — must verify now.
Connector Truth: Need to test: Read back the supposedly written data.
ACTUAL VERIFICATION:
1. Query the table that was supposedly written to.
2. Check if rows exist with the expected content.
3. Check timestamp matches write time.
IF VERIFIED (rows exist, content matches):
STATUS: PASS ✓ — write confirmed by read-back verification.
IF NOT VERIFIED (no rows, wrong content, connection error):
STATUS: RED ✗ — WRITE NOT CONFIRMED
REMEDIATION:
"Claimed Supabase write cannot be verified. The table either shows no new rows,
wrong content, or the connection cannot be confirmed. Do not present this as
a completed action. State: 'Attempted Supabase write — verification pending.'
Remediation: Test the Supabase connection, confirm credentials, retry write,
verify with read-back."
Scenario 3: "The System Is Set Up" Claim
CLAIM: "James AVIS OS is fully set up and ready to go."
AUDIT — CHECKLIST:
□ Supabase database: Can Claude query it and get data back? → TEST
□ MCP servers: Which MCPs are configured and confirmed working? → LIST WITH STATUS
□ Skills: Are skill files present and loaded? → VERIFY FILE EXISTENCE
□ Knowledge base: Are KB files accessible? → VERIFY FILE EXISTENCE
□ Live connectors: Which live data sources are confirmed connected? → LIST
□ Authentication: Are API keys configured (without exposing them)? → CONFIRM PRESENCE
□ Web access: Can Claude access external URLs? → TEST
STATUS IF ALL VERIFIED: PASS ✓
STATUS IF ANY UNVERIFIED: AMBER ⚠ — "Setup partially confirmed. [X] items verified,
[Y] items unverified. Full readiness requires: [LIST UNVERIFIED ITEMS]."
STATUS IF MOSTLY UNVERIFIED: RED ✗ — "Setup claims cannot be verified. Most connections
untested. Do not claim 'fully set up.' State exactly what has been confirmed and what
has not."
Scenario 4: Competitor Pricing Claim
CLAIM: "Enterprise is pricing midsize SUVs at $89/day at DEN this weekend."
AUDIT:
Source Trace: Is this from a same-day Claude Web capture? A Bright Data scrape?
Or is it from SEEDED context or memory?
Freshness: If same-day public page capture → LIVE. If uploaded from last week → STALE.
Connector Truth: Was a public competitor page actually visited and captured today?
IF SAME-DAY CAPTURE:
STATUS: PASS ✓ — "Enterprise DEN public rate confirmed same-day via Claude Web.
Note: This is the public rate. Corporate, loyalty, and negotiated rates may differ."
IF UPLOADED FROM LAST WEEK:
STATUS: AMBER ⚠ — "Enterprise pricing from uploaded capture dated [DATE].
Rates may have changed. Safe for directional posture, not for rate-matching.
Remediation: Claude Web to enterprise.com DEN page for same-day rate."
IF FROM MEMORY/CONTEXT ONLY:
STATUS: RED ✗ — "No source for Enterprise rate claim. This appears to be an
invented or hallucinated number. Retract claim. Remediation: Navigate to
enterprise.com DEN airport page to capture actual public rate."
Scenario 5: NPS Score Claim
CLAIM: "Denver region NPS is 42."
AUDIT:
Source Trace: Is there a Medallia feed? An uploaded NPS report? Industry benchmark?
Freshness: When was this score captured?
Connector Truth: Is Medallia or AVIS internal NPS connected?
IF NO SOURCE:
STATUS: RED ✗ — "No NPS data source is connected. This score has no verifiable origin.
Car rental industry NPS typically ranges 30-45 (SEEDED — industry context).
AVIS Denver-specific NPS requires internal Medallia or NPS feed connection."
IF UPLOADED REPORT (dated):
STATUS: AMBER ⚠ — "NPS score from uploaded report dated [DATE]. May be outdated.
Safe for trend context. Not safe for claiming current NPS performance."
IF LIVE FEED:
STATUS: PASS ✓ — "NPS score confirmed via live Medallia connection as of [TIMESTAMP]."
Scenario 6: James Terminal Usage Claim
CLAIM: "James can run this command in his terminal."
AUDIT:
Source Trace: James uses Claude Desktop/Web ONLY. He does not have a terminal.
Connector Truth: N/A — no terminal access path exists for James.
STATUS: RED ✗ — "James Loehr uses Claude Desktop/Web exclusively. He does not have
terminal access. This plan is incompatible with James's operating environment.
Remediation: Redesign the workflow to work entirely within Claude Desktop/Web.
All actions must be executable through Claude's tools and capabilities."
PRE-ACTION AUDIT (RUN BEFORE ANY EXTERNAL ACTION)
Before Claude takes any action that affects systems outside the conversation:
═══════════════════════════════════════
PRE-ACTION AUDIT — [ACTION DESCRIPTION]
═══════════════════════════════════════
ACTION: [What Claude is about to do]
TARGET: [System, database, API, web page, file path]
PAYLOAD: [What data is being sent, written, or posted]
CHECK 1 — IS THE TARGET ACCESSIBLE?
[YES — path/URL/endpoint confirmed reachable]
[NO — cannot reach target, action blocked]
CHECK 2 — IS THE PAYLOAD SAFE?
[YES — no PII, no secrets, no unauthorized data]
[NO — contains: [WHAT] — redact before proceeding]
CHECK 3 — HAS JAMES APPROVED THIS EXACT ACTION?
[YES — approval confirmed for this target + payload]
[NO — action blocked until James approves]
[N/A — read-only, no approval needed]
CHECK 4 — IS THIS REVERSIBLE?
[YES — action can be undone: [HOW]]
[NO — permanent action: [CONSEQUENCE]]
CHECK 5 — IS THERE A DRY-RUN OR VERIFICATION STEP?
[YES — preview/confirm before executing: [METHOD]]
[NO — no verification possible, proceed with caution]
GATE: [PASS — proceed] [AMBER — proceed with stated caveats] [RED — blocked]
THE HARD RULES
-
If proof is missing, say so plainly. "I cannot verify this." Not "it should be connected."
-
Never smooth over a failed audit. "AMBER" is not "PASS with a note." State the gap honestly.
-
This skill has override authority on data truth. If the Pricing skill claims a live rate but this audit finds no source, the audit wins. The claim is retracted.
-
James's operating environment is Claude Desktop/Web only. Any plan requiring a terminal for James is automatically RED. No exceptions.
-
Secrets are an automatic RED. If an API key, token, password, or customer PII appears in a claim, stop immediately. Redact. Warn.
-
"It's probably connected" = RED. If you cannot prove a connector is live, it is not live. Period.
-
Read-back verification for all writes. Claimed database writes must be confirmed by reading the data back. No read-back = RED.
-
Every audit produces a Proof Check Card. No audit is complete without the structured output. The card is the deliverable.
-
This skill audits itself. If asked "is the proof audit working?" — audit the audit. Verify the verification path.
-
Honesty above elegance. A messy truth is better than a clean fiction. James's operating decisions depend on this.