dev-gate
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFE
Full Analysis
- Sandboxing Implementation: The skill describes using kernel-level sandboxing tools like
Bubblewrap(on Linux) andSeatbelt(on macOS) to isolate build and release commands. This architecture is designed to restrict network access and prevent unauthorized external connections during the qualification process. - Credential Safety: It defines a protocol for handling secrets where sensitive values are automatically redacted in logs, journal entries, and process arguments (
argv). The system utilizes environment-based passing to avoid exposure to other local processes that could read command-line arguments. - Process and File System Isolation: The documentation explains the use of private checkouts via
git clone --localand mandatory machine locks (flock) to ensure that concurrent build processes do not interfere with each other's metadata or shared state. - Automated Security Guards: The skill details the 'Citadel,' a suite of automated tests that enforce architectural invariants, such as preventing recursive command invocation, ensuring shell scripts follow strict linting rules via ShellCheck, and maintaining database access boundaries.
Audit Metadata