open-source-project-maintainer

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a guideline for open-source maintenance and project governance. It does not contain any executable scripts or prompts that attempt to bypass safety filters or exfiltrate data.
  • [SAFE]: It promotes strong security postures for the managed repositories, such as incorporating Trivy scans for Docker images, using Gitleaks for secret detection, and implementing staged npm publishes with SBOM and provenance data.
  • [SAFE]: The instructions for release propagation, such as version pinning in installation scripts and multi-arch builds, follow industry-standard security and reliability practices.
  • [SAFE]: Mentions of sensitive components like DOCS_SYNC_TOKEN are described as architectural placeholders for CI/CD workflows rather than being hardcoded or misused for data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:35 AM
Security Audit — agent-trust-hub — open-source-project-maintainer