dora-metrics

Pass

Audited by Gen Agent Trust Hub on May 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill calculates DevOps Research and Assessment (DORA) metrics, which is a standard engineering management practice.
  • [COMMAND_EXECUTION]: The skill uses a Python module minister.dora_metrics to process git and GitHub data. This command execution is consistent with the skill's stated purpose of metric calculation.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the GitHub API to fetch PR and issue data. GitHub is an established service and its use here is necessary for the skill's functionality.
  • [DATA_EXFILTRATION]: No unauthorized network operations or credential harvesting patterns were detected. The skill processes local repository data and GitHub metadata for reporting purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
May 22, 2026, 12:25 PM
Security Audit — agent-trust-hub — dora-metrics