qe-quality-assessment

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The 'Gotchas' section includes behavioral steering instructions that utilize reinforcement learning concepts ('reward 0.92') and references to behavioral shifts ('Nagual pattern') to influence how the agent validates its own output.
  • [COMMAND_EXECUTION]: The skill executes shell commands using the 'aqe' tool and performs local file system updates using 'node -e' scripts to persist run history.
  • [EXTERNAL_DOWNLOADS]: The skill depends on an external command-line tool 'aqe' which is not declared in the skill's mandatory tool requirements and is not a standard system utility.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its analysis of untrusted source code.
  • Ingestion points: Reads files from the 'src/' directory during quality assessment.
  • Boundary markers: The skill does not use delimiters or instructions to ignore embedded directions in the analyzed code.
  • Capability inventory: Capabilities include shell command execution ('aqe', 'node') and file system read/write access.
  • Sanitization: No sanitization or filtering of the source code content is described before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 08:03 AM