# trustgate

> trustgate — cognis-digital-trustgate. Use this tool when you need to detect security vulnerabilities in AI coding-agent projects, such as symlink-hijack, one-click-RCE, and unsafe-trust settings. It analyzes git projects to identify potential threats, providing outputs that highlight vulnerabilities and inputs that include project repositories and configurations. Ideal for use cases where security auditing and risk assessment are crucial, such as in open-source or collaborative coding environments.

Canonical page: https://skillsregistry.net/skills/cognis-digital-trustgate  
JSON: https://api.skillsregistry.net/v1/skills/cognis-digital-trustgate

## Description

Detect symlink-hijack / one-click-RCE / unsafe-trust settings in AI coding-agent projects

## Trust

- **Trust score (0–1):** 0.87
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Updated:** 2026-09-28

## Source

- **Source listing:** [GitHub](https://github.com/cognis-digital/trustgate)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "cognis-digital-trustgate"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/cognis-digital-trustgate` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/cognis-digital-trustgate/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
