qlty-check

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external code files and repository content, which could contain malicious patterns or instructions designed to influence the agent's behavior during analysis.
  • Ingestion points: Processes repository files via scripts/qlty_check.py and the qlty CLI.
  • Boundary markers: No specific delimiters or instructions to ignore embedded content are defined in the instructions.
  • Capability inventory: The skill utilizes the Bash and Read tools to perform its tasks.
  • Sanitization: No explicit sanitization or filtering of the analyzed file content is mentioned.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute a Python harness (scripts/qlty_check.py) that interacts with the qlty CLI to perform linting, formatting, and metrics calculations.
  • [EXTERNAL_DOWNLOADS]: The skill references the external qlty CLI repository on GitHub (https://github.com/qltysh/qlty) as a functional requirement. This is an informational reference to a third-party developer tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — qlty-check