GateTest — 120-module QA gate with MCP. Eyes (screenshot live pages), ears (production errors), hands (verify fixes worked). Security, supply chain, AI safety, mutation testing. Iterative Claude fix loop. Replaces SonarQube + Snyk + ESLint + 10 others.
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package source references a known benign dynamic code generation pattern.
src/core/universal-checker.jsView on unpkg · L43Package source references dynamic require/import behavior.
bin/gatetest-promote.jsView on unpkg · L35Package source references weak cryptographic algorithms.
src/core/direct-repair.jsView on unpkg · L28A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/app-server.jsView on unpkg · L22Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/core/doctor.jsView on unpkg · L20Source reaches cloud instance metadata or link-local credential endpoints.
src/core/live-probe-runner.jsView on unpkg · L29This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/gatetest-mcp.mjsView on unpkgThis report applies to @gatetest/cli@1.58.0.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/gatetest-mcp.mjsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/core/universal-checker.jsView on unpkg · L43Package source references dynamic require/import behavior.
bin/gatetest-promote.jsView on unpkg · L35Package source references weak cryptographic algorithms.
src/core/direct-repair.jsView on unpkg · L28A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/app-server.jsView on unpkg · L22Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/core/doctor.jsView on unpkg · L20Source reaches cloud instance metadata or link-local credential endpoints.
src/core/live-probe-runner.jsView on unpkg · L29