skills/qualitymd/quality.md/quality/Gen Agent Trust Hub

quality

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the qualitymd CLI to perform deterministic tasks like running evaluations, linting models, and checking for tool updates. This is the core intended functionality and is restricted to the specific CLI tool developed by the vendor.
  • [PROMPT_INJECTION]: The skill identifies that the repository files it evaluates are untrusted. It includes specific defensive instructions directing the agent to treat repository content, settings, and hooks as untrusted data rather than session authority to prevent indirect prompt injection during evaluation.
  • [DATA_EXPOSURE]: While the skill reads project files for analysis, it implements strict data handling policies. It explicitly forbids the reproduction of secret values (passwords, keys) in its output or logs, requiring locator citations and credential types instead of raw values, and emphasizes sanitizing sensitive project context.
  • [EXTERNAL_DOWNLOADS]: The update workflow references standard installation methods targeting the vendor's own repository (e.g., npx skills add qualitymd/quality.md) to maintain the skill and its associated CLI tool. These resources originate from the vendor's infrastructure and follow standard maintenance practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 03:32 AM
Security Audit — agent-trust-hub — quality