quality-gate-review

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructional reinforcement phrases such as "Strict execution contract" and instructions to ignore platform-specific mode-switches. These are intended to ensure consistent agent behavior across different interfaces rather than bypassing safety protocols.- [DATA_EXPOSURE]: The skill is designed to read project-specific documentation and configuration files (e.g., docs/project-config.json, docs/project-reference/). It includes a specific security mandate to "NEVER store secrets, tokens, credentials, or private customer data in goal files."- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface where it ingests untrusted data from pull requests or artifacts provided by the user. This risk is mitigated by mandatory "Anti-bias" protocols that require the agent to "steel-man the OPPOSITE verdict" and verify findings with evidence before emitting a report.- [COMMAND_EXECUTION]: The skill references various internal agent tools (e.g., $quality-gate, $why-review, $project-init). These are standard tool invocations within the agent's environment and do not involve arbitrary shell command execution or external script downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:22 PM
Security Audit — agent-trust-hub — quality-gate-review