open-source-policy

Installation
SKILL.md

Open Source Policy Skill

Purpose

This skill provides comprehensive open source governance aligned with Hack23 AB's transparency principle, demonstrating that radical openness creates competitive advantage through evidence-based security excellence. It enables repository maintainers to implement required security badges, manage license compliance, generate SBOMs, and maintain security documentation that serves as both operational necessity and client demonstration.

When to Use This Skill

Apply this skill when:

  • ✅ Creating new public repositories
  • ✅ Preparing for OpenSSF Scorecard assessment (target: ≥7.0)
  • ✅ Configuring CII Best Practices badge (minimum: Passing)
  • ✅ Setting up SLSA Level 3 build attestations
  • ✅ Implementing license compliance scanning (FOSSA)
  • ✅ Generating SBOMs (CycloneDX/SPDX)
  • ✅ Creating security architecture documentation
  • ✅ Planning coordinated vulnerability disclosure
  • ✅ Responding to client due diligence requests
Related skills
Installs
7
Repository
hack23/cia
GitHub Stars
223
First Seen
Mar 4, 2026