QA测试主管 质量门禁验收

PassAudited by VirusTotal on May 8, 2026.

Overview

Type: OpenClaw Skill Name: qa-quality-gate Version: 1.1.0 The skill bundle defines a QA Lead role focused on quality gate enforcement, test evidence review, and release-readiness assessment. The instructions in SKILL.md are strictly operational, detailing workflows for validating unit, HTTP, and E2E tests within a specific project context (Weline). No indicators of malicious intent, data exfiltration, unauthorized execution, or harmful prompt injection were found.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

QA recommendations may depend on local project instructions that are outside this package review.

Why it was flagged

The skill asks the agent to rely on local project documents that were not included in the reviewed artifact set. This is not suspicious by itself, but those documents could influence the agent's QA standards and should be trusted.

Skill content
Source Material

- `AI-ENTRY.md`
- `CLAUDE.md`
- `dev/ai/skills/testing/SKILL.md`
- `dev/ai/skills/planning/SKILL.md`
- `dev/ai/skills/documentation-standards/SKILL.md`
Recommendation

Before using the skill, inspect the referenced project documents and confirm they match your intended QA process.

What this means

Information from test evidence or runtime logs could be shared in a team or agent collaboration channel.

Why it was flagged

The skill includes a disclosed collaboration step to notify a named Weline lead. This appears purpose-aligned, but it may route QA findings or evidence summaries to another role or agent.

Skill content
When a problem, blocker, risk, validation failure, or cross-agent issue is found, notify `@Weline-技术主管`.
Recommendation

Use the notification step only in the intended workspace and avoid including secrets, tokens, or unrelated sensitive log data.