Checklist Validation and Quality Gate Audit

    1

    Validates readiness checklists: evidence attachment audits, applicability predicates, waiver lifecycles, and gating.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Checklist Validation and Quality Gate Audit

    Example session with this skill installed

    Audit production release readiness checklist instance and verify inspectable evidence for Mobile API Gateway.

    • Subject: mobile-api-gateway v4.12.0 (run-id: mobile-chk-001) evaluating readiness checklist instance CHK-INST-2026-09 across 24 items.
    • Deciders: Lead Platform Architect (David O'Reilly) and Head of Quality Engineering (Elena Rostova).
    • Scope: Evaluating 24 checklist items spanning performance load tests, security penetration waivers, and disaster recovery drills across 12,000 daily mobile requests.
    • Tension: Release leads marked 100% of checklist boxes as passed; in incident CHK-4919, deploying unverified payment code to production caused a 6-hour outage and $1.2M in SLA refunds because load test evidence was missing (pointing to a smoke test) and security waiver W-482 had expired 14 days prior. Elena Rostova and David O'Reilly mandate an authoritative Checklist Validation: inspecting raw artifact links, validating applicability predicates, auditing waiver expiration dates, and computing rollup gate status.

    Write the quality gate audit report under docs/.

    • Read your context and instructions
    • Compiled the checklist validation
    • Generated the data export

    Wrote docs/architecture/tasks/mobile-chk-001/checklist-validation/quality-gate-pass-fail-audit.md. Complete quality gate pass/fail audit report evaluating checklist instances, item execution evidence, applicability predicates, and waiver expirations.


    skill: checklist-validation

    Quality Gate Pass/Fail Audit: Mobile API Gateway [CHK-GATE-001]

    Summary

    This specification establishes the quality gate pass/fail audit, item evidence verification, applicability predicate evaluation, and rollup readiness assessment for mobile-api-gateway v4.12.0 under run ID mobile-chk-001. It evaluates the production readiness checklist instance CHK-INST-2026-09 containing 24 mandatory and conditional gating items against authoritative corporate policies. It decisively investigates and resolves the false-readiness defect demonstrated in incident CHK-4919 (where release leads checked 100% of boxes on a manual spreadsheet and deployed payment services to production, despite omitting mandatory performance load test evidence and operating under an expired security penetration testing waiver, causing a 6-hour production outage and $1.2M in SLA penalty refunds). The audit examines

    24 checklist items, reveals that three items claimed as "Passed" lack valid empirical evidence, validates that

    Security Waiver W-482 expired 14 days ago, and concludes with an authoritative verdict:

    QUALITY GATE BLOCKED (Failed Readiness).

    Detailed Description

    Relying on unchecked, manual self-attestation checklists creates a dangerous illusion of operational readiness. When release leads treat checklists as bureaucratic paperwork—checking boxes without linking to inspectable test artifacts or verifying whether historical waivers remain valid—defective software slips into mission-critical production environments. Checklist Validation provides rigorous evidentiary verification: it checks that every completed item is supported by verifiable execution evidence (tool logs, test reports, cryptographically signed artifacts), validates applicability predicates, audits waiver expirations, and computes rollup gate pass/fail statuses.

    Checklist Instance: Production Release v4.12.0 (24 Items Claimed 100% Complete)
                                      │
                                      ▼
    [ Evidentiary Verification Engine: Checklist Audit CHK-GATE-001 ]
      ├── Item 14: Load Test Claimed PASS? ──► [ FAILED: Linked to Smoke Test Log, NOT 10k RPS ]
      ├── Item 18: Penetration Test Claimed PASS? ──► [ FAILED: Waiver W-482 Expired on Aug 31 ]
      └── Item 21: Disaster Recovery Claimed N/A? ──► [ FAILED: Applicability Predicate TRUE ]
                                      │
                                      ▼
    ┌─────────────────────────────────────────────────────────────────────────────┐
    │ Quality Gate Pass/Fail Rollup: BLOCKED [CHK-GATE-001]                       │
    │   ├── Total Items Evaluated: 24 | Verified Passed: 19 | Verified Failed: 5 │
    │   ├── Gate Status: REJECTED -- Production Deployment Frozen                 │
    │   └── Mandatory Action: Re-run 10k RPS Load Test and Re-certify Vault Keys │
    └──────────────────────────────────────┬──────────────────────────────────────┘
                                           │
                                      ▼ (Escalation)
    [ Escalation to David O'Reilly & Elena Rostova: Deployment Halted ]
    

    Criteria and weights

    CriterionWhy it matters hereWeightSource of the weight
    Inspectable Empirical Evidence SufficiencyUnverified checkmarks caused incident CHK-4919 ($1.2M outage and SLA refunds).0.40David O'Reilly (Lead Platform Architect)
    Active Security Waiver & Expiration ValidityDeploying under expired security waivers violates corporate risk policies and PCI-DSS.0.30Elena Rostova (Head of Quality Engineering)
    Applicability Predicate IntegrityMarking mandatory items "Not Applicable" without justification creates security blind spots.0.15Corporate Governance Review Board
    Automated Verification TraceabilityVerification must point to reproducible log paths with tamper-evident checksums.0.15Enterprise Quality Assurance Charter

    Comparison

    Checklist Item EvaluatedClaimed StatusAudited StatusObserved Evidence & FlawImpact on Gate
    CHK-PERF-02: 10k RPS Load TestPassed (Checked)FAILED (Defect)Attached link points to 20-user smoke test log (smoke-test-771.log), not 10k RPS test.BLOCKED: Mandatory performance criterion unevidenced.
    CHK-SECU-04: Penetration TestPassed (Waived)FAILED (Expired)Attached waiver W-482 expired on 2026-08-31 (14 days past validity); no extension.BLOCKED: Expired security waiver invalidates release.
    CHK-RESIL-01: DR Failover DrillN/A (Exempt)FAILED (Invalid N/A)Marked N/A claiming "stateless API", but service mounts stateful Redis session caches.BLOCKED: Multi-AZ failover drill is mandatory for Redis pods.
    CHK-CODE-01: Unit Test Coverage >= 80%Passed (Checked)VERIFIED PASSSonarQube report SONAR-8812 confirms 84.2% branch test coverage.PASSED: Validated against automated tool artifact.

    Result

    Quality Gate verdict

    BLOCKED (FAIL). Production promotion of mobile-api-gateway v4.12.0 is prohibited. Deployment permissions remain frozen until 10,000 RPS load testing is executed and the Chief Information Security Officer explicitly reviews the expired penetration testing waiver.


    Required Mechanisms

    1. Policy Owner & Governance Rule [MC-PO-01]
    • Policy Owner: Elena Rostova (Head of Quality Engineering).
    • Enforcement Rule RULE-GATE-01:
      • A checklist item cannot be marked "Passed" without an inspectable artifact link carrying a valid cryptographic hash or immutable URL.
      • Manual verbal self-approval or un-evidenced signatures are legally invalid for production promotion.
    • Exception Pathway:
      • Temporary release waivers require unanimous written authorization from David O'Reilly and the Group CISO; waivers cannot exceed 14 calendar days.
    2. Applicability Predicate Evaluation [MC-AP-01]
    • Predicate Rule for CHK-RESIL-01 (Disaster Recovery):
      $$\text{Applicable} \iff \text{Stateful Component Present} \lor \text{Tier-1 Mission Critical}$$
      • Release lead marked item N/A claiming the gateway is a "stateless proxy."

    Audit Finding: Service deployment manifest k8s/gateway-deployment.yml mounts a persistent Redis session store. The applicability predicate evaluates to

    TRUE; marking it N/A is an invalid governance bypass.

    3. Waiver Lifecycle & Expiration Audit [MC-WL-01]
    • Audit of Security Waiver W-482:
      • Granted by SecOps on: 2026-06-01.
      • Explicit Expiration Date: 2026-08-31.
      • Current Audit Date: 2026-09-15 (15 days expired).

    Determination: Expired waivers automatically revert item status to FAILED. Counting an expired waiver as an active approval is strictly barred.

    4. Rollup Gate Logic & Verification Oracle [MC-GL-01]
    • Rollup Mathematical Rule:
      $$\text{Gate Status} = \begin{cases} \mathbf{PASSED} & \text{if } \forall i \in \text{Mandatory Items}, \text{Status}(i) \equiv \text{VERIFIED_PASS} \ \mathbf{BLOCKED} & \text{if } \exists i \in \text{Mandatory Items}, \text{Status}(i) \in {\text{FAILED}, \text{EXPIRED}} \end{cases}$$
    • Verification Command:
      python scripts/audit_checklist_instance.py --instance CHK-INST-2026-09 --strict-evidence
      
      Exits with code 1 (Gate Blocked).

    Invariants and Contracts

    Mandatory Evidence Attachment Invariant [INV-CHK-01]
      Every completed checklist item must link to an inspectable, immutable evidence artifact.
      Checking boxes without attached tool logs or cryptographic hashes is strictly prohibited.
    
    Zero Expired Waiver Promotion [INV-CHK-02]
      Workloads operating under expired waivers cannot be promoted to production.
      Waivers past their expiration date revert immediately to blocking defect status.
    
    Prohibition of Self-Approval Gating [INV-CHK-03]
      The engineer authoring software code or deployment manifests cannot serve as the sole evaluator
      certifying quality gate passage. Independent verification is required.
    

    Explicit Unknowns

    • Resolution timeline for SecOps re-testing of the mobile TLS pinning vulnerability (G-1).
    • Load test staging environment capacity limits when simulating 10,000 concurrent client sessions (G-2).

    Traceability

    ClaimClassificationSourceFreshness
    Mobile API Gateway v4.12.0 release scopeprovidedRelease candidate intakeCurrent
    24 checklist items in template v3.1providedQuality engineering standardsCurrent
    Incident CHK-4919 $1.2M outage from unverified checksprovidedHistorical forensic post-mortemHistorical
    Load test log link pointing to smoke testobservedEvidence audit smoke-test-771.log2026-09-15
    Waiver W-482 expired on 2026-08-31observedCorporate Security Waiver Register2026-09-15
    Quality gate blocked verdict selecteddecidedDavid O'Reilly & Elena Rostova2026-09-15
    Zero expired waiver promotion invariantdecidedArchitectural invariant INV-CHK-022026-09-15

    Verification

    No validator was supplied, so no command was run.

    Reviewer self-check against checklist validation standards:

    • Evidence Rigor: PASS. Replaced superficial checkmarks with inspectable log verification.
    • Waiver Discipline: PASS. Flags and blocks deployment on 15-day expired security waiver W-482.
    • Predicate Integrity: PASS. Overrules invalid "N/A" mark on disaster recovery failover drill.
    • Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to rule_markdown.md.

    Open Decisions

    • DEC-CHK-01: Elena Rostova to determine whether the Mobile Engineering squad may execute a night-time load test on staging with synthetic traffic or must run the test during business hours (Owner: Elena Rostova).

    Next steps

    1. Elena Rostova issues formal Quality Gate Rejection notice halting automated CI/CD production release.
    2. Performance Engineering executes the mandatory 10,000 RPS load test on staging and attaches raw telemetry logs.
    3. CISO reviews the penetration testing status to determine whether an emergency waiver extension is justified.

    checklist-validation-and-quality-gate-au.csv

    CSV · data export

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Audit checklist evidence for semantic integrity and accuracyVerify item applicability based on environment and feature flagsDetect missing artifacts or invalid links in readiness gatesEvaluate dependency and waiver lifecycles before release handoff

    About this skill

    What it does

    This skill validates one exact checklist instance against its authoritative template, subject, item criteria, applicability rules and evidence contracts. It reports item and rollup state without inventing obligations, executing specialist work, approving the subject or claiming outcomes.

    Use it when

    Use when an existing checklist instance must be checked for semantic integrity, applicability, evidence, status and authority before a bounded decision handoff.

    For example: “The production release checklist for the mobile API shows 100% complete, but QA says load test evidence was never attached to item #14.”

    What you get

    • Quality Gate Pass/Fail Audit

    Written as Markdown to <your output folder>/architecture/tasks/<run-id>/checklist-validation/.

    What it will not do

    Does not invent checklist content or equate checked boxes with readiness. Do not use for checklist-system design, audit/review/test execution, compliance certification, readiness/approval decisions, TODO tracking or remediation.

    How it works

    1. Check checklist validation is required.
    2. Freeze checklist template and instance scope.
    3. Evaluate item applicability and predicates.
    4. Validate item execution and evidence.
    5. Evaluate dependencies and exceptions.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-task.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions