Install
$ agentstack add skill-sttrevens-4dgames-skills-agentic-automation-review-gate ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Agentic Automation Review Gate
Use this skill to review output from recurring agent automations. The goal is to decide whether the automation produced reliable, scoped, and useful work, not to rubber-stamp it because it ran.
When To Use
- A background agent opened a branch, commit, PR, report, QA artifact, or
next-stone recommendation.
- A recurring automation claims a check passed or a product state is ready.
- A bot/agent proposes merge, deployment, publication, outreach, or user-facing
trust claims.
- The user asks whether an automation is "working", "safe to merge", or "going
in the right direction".
Review Stance
Findings first. Prefer concrete bugs, missing evidence, unsafe scope, stale baseline, undocumented behavior, failed gates, or claims that exceed proof.
Do not merge, deploy, send, publish, or mark a goal complete unless the evidence supports that exact action.
Workflow
- Read the automation prompt/config and its latest memory or handoff.
- Identify the candidate output.
- branch/commit/report/artifact/date;
- workspace and baseline;
- claimed goal;
- files or systems touched.
- Check scope.
- Is the output inside the automation's mandate?
- Did it avoid unrelated user work?
- Did it avoid secrets, private data, broad rewrites, or unapproved external
actions?
- Check evidence.
- Commands/tests run;
- screenshots or runtime proof when product-facing;
- docs updated when durable truth changed;
- residual risk stated honestly.
- Decide.
ACCEPT: safe to merge/use/report.REQUEST CHANGES: useful direction but blocked by fixable gaps.REJECT: wrong scope, unsafe, stale, or not evidenced.NO CANDIDATE: nothing new to review.
- If blocked, write feedback that the next automation run can act on.
Output Shape
## Findings
- [P1/P2/P3] Finding with file, command, artifact, or exact evidence.
## Decision
ACCEPT / REQUEST CHANGES / REJECT / NO CANDIDATE
## Gates Checked
- Scope:
- Baseline:
- Tests/evidence:
- Docs:
- Safety:
## Feedback For Next Run
- Candidate:
- Blocked gate:
- Required change:
- Whether to amend, replace, or abandon:
Hard Rules
- "95% automated" still needs review if the remaining 5% can lose trust.
- Do not infer external events such as payments, sends, customer replies, or
successful runtime QA without evidence.
- For code branches, stage and merge only explicit intended files.
- For game projects, product-facing claims require playable, runtime, visual, or
carefully scoped static evidence.
Common Failure Modes
- Accepting an automation because the scheduler ran, even though there is no
candidate artifact.
- Treating green tests as enough when the automation changed unrelated scope.
- Letting a report make user-facing trust claims without runtime proof.
- Giving vague feedback that the next automation run cannot execute.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Sttrevens
- Source: Sttrevens/4dgames-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.