qc
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides templates for GitHub Actions and CI pipelines that reference official actions from the
actions(GitHub) andsonarsource(SonarSource) organizations. These are recognized well-known services. - [COMMAND_EXECUTION]: The instructions and reference files provide templates for executing standard development and quality tools, including
npm run lint,npm audit,pytest, andgolangci-lint. These commands are intended to be run within the user's local or CI environment. - [DATA_EXFILTRATION]: The
references/qc-metrics-dashboard.mdfile includes Python templates for metrics collectors that interact with legitimate APIs from SonarCloud (sonarcloud.io) and GitHub (api.github.com). This is consistent with the skill's purpose of quality monitoring. - [PROMPT_INJECTION]: The agent instructions include strict output constraints (e.g., "No preamble. No postamble.") to ensure reports follow a specific template. These are standard instructional controls for structured output.
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were identified. The skill promotes industry-standard quality control practices.
Audit Metadata