GateTest — 120-module QA gate with MCP. Eyes (screenshot live pages), ears (production errors), hands (verify fixes worked). Security, supply chain, AI safety, mutation testing. Iterative Claude fix loop. Replaces SonarQube + Snyk + ESLint + 10 others.
No install-time malicious behavior is present. An explicitly run app server has a serious webhook-authentication flaw that can reach shell execution; an explicit CLI setup command mutates project-local Claude hooks.
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/gatetest.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/core/universal-checker.jsView on unpkg · L43Package source references dynamic require/import behavior.
bin/gatetest-promote.jsView on unpkg · L35Package source references weak cryptographic algorithms.
src/core/direct-repair.jsView on unpkg · L28A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/app-server.jsView on unpkg · L22Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/core/doctor.jsView on unpkg · L20Source reaches cloud instance metadata or link-local credential endpoints.
src/core/live-probe-runner.jsView on unpkg · L29This report applies to @gatetest/cli@1.56.2.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/gatetest.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/core/universal-checker.jsView on unpkg · L43Package source references dynamic require/import behavior.
bin/gatetest-promote.jsView on unpkg · L35Package source references weak cryptographic algorithms.
src/core/direct-repair.jsView on unpkg · L28A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/app-server.jsView on unpkg · L22Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/core/doctor.jsView on unpkg · L20Source reaches cloud instance metadata or link-local credential endpoints.
src/core/live-probe-runner.jsView on unpkg · L29