gate-p6

A release gate that checks whether a system is ready to launch, with separate approval from quality assurance and security. Quality assurance checks whether it works as expected; security checks whether it is safe to operate.

In plain words
What is it for?
Use it to coordinate the final QA and security reviews and confirm that both teams explicitly approve go-live.
Why use it?
It prevents launch when either testing or security approval is missing, or when mandatory project rules are broken.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/jonase47/ccpr/gate-p6
Clone the repo
git clone --depth 1 https://github.com/jonase47/ccpr
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,584 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.01584
Opus 5 $0.00000 $0.00792
Sonnet 5 $0.00000 $0.00317
Haiku 4.5 $0.00000 $0.00158

Measured 2d ago against content hash 2b1043b68456, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

gate-p6 scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commands/gate-p6.md · 91 lines

How it starts

The opening of the file, as written. The whole thing — 91 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/gate-p6 – Release Gate: QA & Security Approval

Checks whether the system is ready for launch. Both QA and Security must explicitly grant approval. No go-live without dual approval.

No Argument ($ARGUMENTS not applicable)

Gate commands accept no arguments. They always check the complete current project status.

Pre-Flight

If docs/.gate-preflight-p6.md exists and is less than 10 minutes old, read it as a starting point. Mechanical checks (file existence, sections) are already done – focus on content evaluation.

Constitution Inviolables (mandatory pre-gate, applies to both sub-gates)

If docs/CONSTITUTION.md exists, the preflight report (docs/.gate-preflight-p6.md) includes a section "Constitution Inviolables (Required Read)" with the project's non-negotiable rules.

These Inviolables are mandatory input for both sub-gates (/gate-p6-qa and /gate-p6-security):

  • When invoking each sub-gate, pass the Inviolable bullets verbatim in the agent prompt.
  • Both QA and Security must check their evaluation against the Inviolables (e.g. „A11y-Inviolable forces WCAG 2.2 AA verification", „Security-Inviolable forces dependency-audit").
  • Any violation is an "Inviolable breach" — surface it explicitly in the sub-gate verdict and treat it as a No-Go signal for release.

If docs/CONSTITUTION.md is missing on a Full-Track project: stop the gate and recommend /constitution before proceeding (release without Constitution check is not advisable in Full-Track).

Flow

1. QA Approval

/gate-p6-qa – Evaluates all QA-relevant points (tests, accessibility, performance, bugs) and grants QA approval.

2. Security Approval

/gate-p6-security – Evaluates all security-relevant points (audit, pentest, DSGVO) and grants Security approval.

3. Consolidation (Orchestrator)

Read docs/quality/QA.md (phase index) first to get the status of all sub-indexes (A11Y.md, AUDIT.md, FUNCTIONAL.md, PENTEST.md) and direct detail files (EXPLORATORY.md, BUGFIX.md). Open the sub-indexes only when their status row indicates needs-rework or open Critical risks.

Read the full file on GitHub · 91 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 91 lines · 0 tokens per session scan A 2b1043b68456

Subscribe to this mod's changes

gate-p6 is a command published in the GitHub repository jonase47/ccpr (1 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,584 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.