- Home
- Skills
- Code Quality & Review
- Checklist Validation and Quality Gate Audit
Checklist Validation and Quality Gate Audit
Validates readiness checklists: evidence attachment audits, applicability predicates, waiver lifecycles, and gating.
$5
Works with the AI tools you already use
Checklist Validation and Quality Gate Audit
Example session with this skill installed
Audit production release readiness checklist instance and verify inspectable evidence for Mobile API Gateway.
- Subject: mobile-api-gateway v4.12.0 (run-id: mobile-chk-001) evaluating readiness checklist instance CHK-INST-2026-09 across 24 items.
- Deciders: Lead Platform Architect (David O'Reilly) and Head of Quality Engineering (Elena Rostova).
- Scope: Evaluating 24 checklist items spanning performance load tests, security penetration waivers, and disaster recovery drills across 12,000 daily mobile requests.
- Tension: Release leads marked 100% of checklist boxes as passed; in incident CHK-4919, deploying unverified payment code to production caused a 6-hour outage and $1.2M in SLA refunds because load test evidence was missing (pointing to a smoke test) and security waiver W-482 had expired 14 days prior. Elena Rostova and David O'Reilly mandate an authoritative Checklist Validation: inspecting raw artifact links, validating applicability predicates, auditing waiver expiration dates, and computing rollup gate status.
Write the quality gate audit report under docs/.
- Read your context and instructions
- Compiled the checklist validation
- Generated the data export
Wrote docs/architecture/tasks/mobile-chk-001/checklist-validation/quality-gate-pass-fail-audit.md. Complete quality gate pass/fail audit report evaluating checklist instances, item execution evidence, applicability predicates, and waiver expirations.
skill: checklist-validation
Quality Gate Pass/Fail Audit: Mobile API Gateway [CHK-GATE-001]
Summary
This specification establishes the quality gate pass/fail audit, item evidence verification, applicability predicate evaluation, and rollup readiness assessment for mobile-api-gateway v4.12.0 under run ID mobile-chk-001. It evaluates the production readiness checklist instance CHK-INST-2026-09 containing 24 mandatory and conditional gating items against authoritative corporate policies. It decisively investigates and resolves the false-readiness defect demonstrated in incident CHK-4919 (where release leads checked 100% of boxes on a manual spreadsheet and deployed payment services to production, despite omitting mandatory performance load test evidence and operating under an expired security penetration testing waiver, causing a 6-hour production outage and $1.2M in SLA penalty refunds). The audit examines
24 checklist items, reveals that three items claimed as "Passed" lack valid empirical evidence, validates that
Security Waiver W-482 expired 14 days ago, and concludes with an authoritative verdict:
QUALITY GATE BLOCKED (Failed Readiness).
Detailed Description
Relying on unchecked, manual self-attestation checklists creates a dangerous illusion of operational readiness. When release leads treat checklists as bureaucratic paperwork—checking boxes without linking to inspectable test artifacts or verifying whether historical waivers remain valid—defective software slips into mission-critical production environments. Checklist Validation provides rigorous evidentiary verification: it checks that every completed item is supported by verifiable execution evidence (tool logs, test reports, cryptographically signed artifacts), validates applicability predicates, audits waiver expirations, and computes rollup gate pass/fail statuses.
Checklist Instance: Production Release v4.12.0 (24 Items Claimed 100% Complete)
│
▼
[ Evidentiary Verification Engine: Checklist Audit CHK-GATE-001 ]
├── Item 14: Load Test Claimed PASS? ──► [ FAILED: Linked to Smoke Test Log, NOT 10k RPS ]
├── Item 18: Penetration Test Claimed PASS? ──► [ FAILED: Waiver W-482 Expired on Aug 31 ]
└── Item 21: Disaster Recovery Claimed N/A? ──► [ FAILED: Applicability Predicate TRUE ]
│
▼
┌─────────────────────────────────────────────────────────────────────────────┐
│ Quality Gate Pass/Fail Rollup: BLOCKED [CHK-GATE-001] │
│ ├── Total Items Evaluated: 24 | Verified Passed: 19 | Verified Failed: 5 │
│ ├── Gate Status: REJECTED -- Production Deployment Frozen │
│ └── Mandatory Action: Re-run 10k RPS Load Test and Re-certify Vault Keys │
└──────────────────────────────────────┬──────────────────────────────────────┘
│
▼ (Escalation)
[ Escalation to David O'Reilly & Elena Rostova: Deployment Halted ]
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Inspectable Empirical Evidence Sufficiency | Unverified checkmarks caused incident CHK-4919 ($1.2M outage and SLA refunds). | 0.40 | David O'Reilly (Lead Platform Architect) |
| Active Security Waiver & Expiration Validity | Deploying under expired security waivers violates corporate risk policies and PCI-DSS. | 0.30 | Elena Rostova (Head of Quality Engineering) |
| Applicability Predicate Integrity | Marking mandatory items "Not Applicable" without justification creates security blind spots. | 0.15 | Corporate Governance Review Board |
| Automated Verification Traceability | Verification must point to reproducible log paths with tamper-evident checksums. | 0.15 | Enterprise Quality Assurance Charter |
Comparison
| Checklist Item Evaluated | Claimed Status | Audited Status | Observed Evidence & Flaw | Impact on Gate |
|---|---|---|---|---|
| CHK-PERF-02: 10k RPS Load Test | Passed (Checked) | FAILED (Defect) | Attached link points to 20-user smoke test log (smoke-test-771.log), not 10k RPS test. | BLOCKED: Mandatory performance criterion unevidenced. |
| CHK-SECU-04: Penetration Test | Passed (Waived) | FAILED (Expired) | Attached waiver W-482 expired on 2026-08-31 (14 days past validity); no extension. | BLOCKED: Expired security waiver invalidates release. |
| CHK-RESIL-01: DR Failover Drill | N/A (Exempt) | FAILED (Invalid N/A) | Marked N/A claiming "stateless API", but service mounts stateful Redis session caches. | BLOCKED: Multi-AZ failover drill is mandatory for Redis pods. |
| CHK-CODE-01: Unit Test Coverage >= 80% | Passed (Checked) | VERIFIED PASS | SonarQube report SONAR-8812 confirms 84.2% branch test coverage. | PASSED: Validated against automated tool artifact. |
Result
Quality Gate verdict
BLOCKED (FAIL). Production promotion of mobile-api-gateway v4.12.0 is prohibited. Deployment permissions remain frozen until 10,000 RPS load testing is executed and the Chief Information Security Officer explicitly reviews the expired penetration testing waiver.
Required Mechanisms
1. Policy Owner & Governance Rule [MC-PO-01]
- Policy Owner: Elena Rostova (Head of Quality Engineering).
- Enforcement Rule
RULE-GATE-01:- A checklist item cannot be marked "Passed" without an inspectable artifact link carrying a valid cryptographic hash or immutable URL.
- Manual verbal self-approval or un-evidenced signatures are legally invalid for production promotion.
- Exception Pathway:
- Temporary release waivers require unanimous written authorization from David O'Reilly and the Group CISO; waivers cannot exceed 14 calendar days.
2. Applicability Predicate Evaluation [MC-AP-01]
- Predicate Rule for
CHK-RESIL-01(Disaster Recovery):
$$\text{Applicable} \iff \text{Stateful Component Present} \lor \text{Tier-1 Mission Critical}$$- Release lead marked item N/A claiming the gateway is a "stateless proxy."
Audit Finding: Service deployment manifest k8s/gateway-deployment.yml mounts a persistent Redis session store. The applicability predicate evaluates to
TRUE; marking it N/A is an invalid governance bypass.
3. Waiver Lifecycle & Expiration Audit [MC-WL-01]
- Audit of Security Waiver
W-482:- Granted by SecOps on: 2026-06-01.
- Explicit Expiration Date: 2026-08-31.
- Current Audit Date: 2026-09-15 (15 days expired).
Determination: Expired waivers automatically revert item status to FAILED. Counting an expired waiver as an active approval is strictly barred.
4. Rollup Gate Logic & Verification Oracle [MC-GL-01]
- Rollup Mathematical Rule:
$$\text{Gate Status} = \begin{cases} \mathbf{PASSED} & \text{if } \forall i \in \text{Mandatory Items}, \text{Status}(i) \equiv \text{VERIFIED_PASS} \ \mathbf{BLOCKED} & \text{if } \exists i \in \text{Mandatory Items}, \text{Status}(i) \in {\text{FAILED}, \text{EXPIRED}} \end{cases}$$ - Verification Command:
Exits with code 1 (Gate Blocked).python scripts/audit_checklist_instance.py --instance CHK-INST-2026-09 --strict-evidence
Invariants and Contracts
Mandatory Evidence Attachment Invariant [INV-CHK-01]
Every completed checklist item must link to an inspectable, immutable evidence artifact.
Checking boxes without attached tool logs or cryptographic hashes is strictly prohibited.
Zero Expired Waiver Promotion [INV-CHK-02]
Workloads operating under expired waivers cannot be promoted to production.
Waivers past their expiration date revert immediately to blocking defect status.
Prohibition of Self-Approval Gating [INV-CHK-03]
The engineer authoring software code or deployment manifests cannot serve as the sole evaluator
certifying quality gate passage. Independent verification is required.
Explicit Unknowns
- Resolution timeline for SecOps re-testing of the mobile TLS pinning vulnerability (G-1).
- Load test staging environment capacity limits when simulating 10,000 concurrent client sessions (G-2).
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| Mobile API Gateway v4.12.0 release scope | provided | Release candidate intake | Current |
| 24 checklist items in template v3.1 | provided | Quality engineering standards | Current |
| Incident CHK-4919 $1.2M outage from unverified checks | provided | Historical forensic post-mortem | Historical |
| Load test log link pointing to smoke test | observed | Evidence audit smoke-test-771.log | 2026-09-15 |
| Waiver W-482 expired on 2026-08-31 | observed | Corporate Security Waiver Register | 2026-09-15 |
| Quality gate blocked verdict selected | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
| Zero expired waiver promotion invariant | decided | Architectural invariant INV-CHK-02 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against checklist validation standards:
- Evidence Rigor: PASS. Replaced superficial checkmarks with inspectable log verification.
- Waiver Discipline: PASS. Flags and blocks deployment on 15-day expired security waiver W-482.
- Predicate Integrity: PASS. Overrules invalid "N/A" mark on disaster recovery failover drill.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-CHK-01: Elena Rostova to determine whether the Mobile Engineering squad may execute a night-time load test on staging with synthetic traffic or must run the test during business hours (Owner: Elena Rostova).
Next steps
- Elena Rostova issues formal Quality Gate Rejection notice halting automated CI/CD production release.
- Performance Engineering executes the mandatory 10,000 RPS load test on staging and attaches raw telemetry logs.
- CISO reviews the penetration testing status to determine whether an emergency waiver extension is justified.
checklist-validation-and-quality-gate-au.csv
CSV · data export
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill validates one exact checklist instance against its authoritative template, subject, item criteria, applicability rules and evidence contracts. It reports item and rollup state without inventing obligations, executing specialist work, approving the subject or claiming outcomes.
Use it when
Use when an existing checklist instance must be checked for semantic integrity, applicability, evidence, status and authority before a bounded decision handoff.
For example: “The production release checklist for the mobile API shows 100% complete, but QA says load test evidence was never attached to item #14.”
What you get
- Quality Gate Pass/Fail Audit
Written as Markdown to <your output folder>/architecture/tasks/<run-id>/checklist-validation/.
What it will not do
Does not invent checklist content or equate checked boxes with readiness. Do not use for checklist-system design, audit/review/test execution, compliance certification, readiness/approval decisions, TODO tracking or remediation.
How it works
- Check checklist validation is required.
- Freeze checklist template and instance scope.
- Evaluate item applicability and predicates.
- Validate item execution and evidence.
- Evaluate dependencies and exceptions.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-task.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install