quality-gate-review
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructional reinforcement phrases such as "Strict execution contract" and instructions to ignore platform-specific mode-switches. These are intended to ensure consistent agent behavior across different interfaces rather than bypassing safety protocols.- [DATA_EXPOSURE]: The skill is designed to read project-specific documentation and configuration files (e.g.,
docs/project-config.json,docs/project-reference/). It includes a specific security mandate to "NEVER store secrets, tokens, credentials, or private customer data in goal files."- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface where it ingests untrusted data from pull requests or artifacts provided by the user. This risk is mitigated by mandatory "Anti-bias" protocols that require the agent to "steel-man the OPPOSITE verdict" and verify findings with evidence before emitting a report.- [COMMAND_EXECUTION]: The skill references various internal agent tools (e.g.,$quality-gate,$why-review,$project-init). These are standard tool invocations within the agent's environment and do not involve arbitrary shell command execution or external script downloads.
Audit Metadata