QA测试主管 质量门禁验收

AdvisoryAudited by Static analysis on May 8, 2026.

Overview

No suspicious patterns detected.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

QA recommendations may depend on local project instructions that are outside this package review.

Why it was flagged

The skill asks the agent to rely on local project documents that were not included in the reviewed artifact set. This is not suspicious by itself, but those documents could influence the agent's QA standards and should be trusted.

Skill content
Source Material

- `AI-ENTRY.md`
- `CLAUDE.md`
- `dev/ai/skills/testing/SKILL.md`
- `dev/ai/skills/planning/SKILL.md`
- `dev/ai/skills/documentation-standards/SKILL.md`
Recommendation

Before using the skill, inspect the referenced project documents and confirm they match your intended QA process.

What this means

Information from test evidence or runtime logs could be shared in a team or agent collaboration channel.

Why it was flagged

The skill includes a disclosed collaboration step to notify a named Weline lead. This appears purpose-aligned, but it may route QA findings or evidence summaries to another role or agent.

Skill content
When a problem, blocker, risk, validation failure, or cross-agent issue is found, notify `@Weline-技术主管`.
Recommendation

Use the notification step only in the intended workspace and avoid including secrets, tokens, or unrelated sensitive log data.