qe-court
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a sophisticated orchestration layer for multi-agent adversarial reviews. It includes self-learning mechanisms and cryptographic signing of results (ADR-118/ADR-124). The 'seeded-mutant' files are clearly documented test fixtures for validating the review court's detection capabilities and do not represent actual vulnerabilities in the skill's code.
- [REMOTE_CODE_EXECUTION]: The skill mentions 'codex exec review' and command execution via Bash for cross-vendor reviews. However, these are presented as orchestration patterns for the agent to follow using its internal tools, rather than insecure remote scripts or unverified downloads. The configuration explicitly enforces a budget cap and provider layer (ADR-123) for all model calls.
- [SAFE]: Dependency management and environment configurations are handled via standard
config.jsonand external tool requirements (likejq), which is standard practice for this platform tier. - [SAFE]: The skill includes extensive validation logic in
referee.ts(referenced) to prevent jury collusion and ensure vendor diversity, which are safety-enhancing architectural choices.
Audit Metadata