# Controlled pilot security review worksheet

This is a manual review aid, not a penetration test, certification, or proof of security effectiveness. Gated's current private preview covers one uniquely named GitHub branch at an exact existing commit in a selected non-critical repository.

**Keep private:** never include credential values, passkey material, private source code, customer data, or raw sensitive logs. Store evidence in an approved location. Redact identifiers, people, and evidence links before external sharing.

## Review scope

- Claim being assessed: __________
- Reviewer and repository owner: __________
- Date and environment: __________
- Selected repository, unique branch, and full existing SHA: __________
- Scope exclusions acknowledged: __________

## Questions and evidence

| Question | Observation | Evidence type and private reference | Open question or owner |
| --- | --- | --- | --- |
| Which policy applied to the exact request? | ___ | ___ | ___ |
| Who supplied required passkey approval? | ___ | ___ | ___ |
| Were execution inputs the reviewed inputs? | ___ | ___ | ___ |
| Was execution explicitly requested? | ___ | ___ | ___ |
| Did independent GitHub readback match? | ___ | ___ | ___ |
| Which alternate credentials could bypass the route? | ___ | ___ | ___ |
| How was an uncertain result reconciled? | ___ | ___ | ___ |
| Which repository automation could be triggered? | ___ | ___ | ___ |

Label evidence as live provider result, safe-mode rehearsal, documented behavior, or unresolved. Runtime safe-mode rehearsals do not prove live writes. Exact Gated request replay evidence does not establish generic provider idempotency. Inspect status and provider state after a timeout before considering another write.

## Findings and decision

- Finding and consequence for this narrow pilot: __________
- Evidence needed to resolve it: __________
- Owner and follow-up date: __________
- Decision: continue same scope / fix issue before continuing / stop
- Claims the evidence does not support: __________

No destructive probes or broader operations are part of this worksheet. Branch updates, deletion, merges, force pushes, and deployments remain outside the supported operation. A skill does not automatically intercept tools using independent credentials.
