qlty-check
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external code files and repository content, which could contain malicious patterns or instructions designed to influence the agent's behavior during analysis.
- Ingestion points: Processes repository files via
scripts/qlty_check.pyand theqltyCLI. - Boundary markers: No specific delimiters or instructions to ignore embedded content are defined in the instructions.
- Capability inventory: The skill utilizes the
BashandReadtools to perform its tasks. - Sanitization: No explicit sanitization or filtering of the analyzed file content is mentioned.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to execute a Python harness (scripts/qlty_check.py) that interacts with theqltyCLI to perform linting, formatting, and metrics calculations. - [EXTERNAL_DOWNLOADS]: The skill references the external
qltyCLI repository on GitHub (https://github.com/qltysh/qlty) as a functional requirement. This is an informational reference to a third-party developer tool.
Audit Metadata