skills/dceoy/mt5api/local-qa/Gen Agent Trust Hub

local-qa

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local shell script scripts/qa.sh which orchestrates multiple development tools including Ruff, Pyright, Pytest, Prettier, and Checkov.
  • [DYNAMIC_EXECUTION]: Instructions in SKILL.md direct the agent to dynamically install missing dependencies using system or language-specific package managers (e.g., apt, brew, npm, uv) if the QA script fails due to missing tooling. This is constrained by specific safety instructions to stop if privileges are unavailable.
  • [EXTERNAL_DOWNLOADS]: The script fetches and runs tools from standard registries using npx (npm) and uvx (PyPI). It includes security-enhancing configurations like UV_EXCLUDE_NEWER and NPM_CONFIG_MIN_RELEASE_AGE to avoid recently published packages that might not have been vetted.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository data (code, markdown, and CI/CD workflows) through various linters and test runners.
  • Ingestion points: Local repository files including Python source, Markdown documentation, and GitHub Action YAML files.
  • Boundary markers: None explicitly defined in the script for tool output processing.
  • Capability inventory: Subprocess execution for shell commands, file system read access for analysis, and potential environment modification via package installation.
  • Sanitization: Relies on the standard security boundaries of the executed tools (Ruff, Pytest, etc.).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 10:31 AM