qe-court

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a sophisticated orchestration layer for multi-agent adversarial reviews. It includes self-learning mechanisms and cryptographic signing of results (ADR-118/ADR-124). The 'seeded-mutant' files are clearly documented test fixtures for validating the review court's detection capabilities and do not represent actual vulnerabilities in the skill's code.
  • [REMOTE_CODE_EXECUTION]: The skill mentions 'codex exec review' and command execution via Bash for cross-vendor reviews. However, these are presented as orchestration patterns for the agent to follow using its internal tools, rather than insecure remote scripts or unverified downloads. The configuration explicitly enforces a budget cap and provider layer (ADR-123) for all model calls.
  • [SAFE]: Dependency management and environment configurations are handled via standard config.json and external tool requirements (like jq), which is standard practice for this platform tier.
  • [SAFE]: The skill includes extensive validation logic in referee.ts (referenced) to prevent jury collusion and ensure vendor diversity, which are safety-enhancing architectural choices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 06:10 PM
Security Audit — agent-trust-hub — qe-court