verasic-github-governance
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell scripts to automate the initialization of repository governance. These scripts perform routine operations such as directory creation, template installation, and Git configuration management (e.g., setting core.hooksPath). All execution is localized to the repository being managed.
- [EXTERNAL_DOWNLOADS]: The skill references external tools (Lefthook, OpenTofu) and specific GitHub repositories for infrastructure-as-code (IaC) templates. These resources are part of the intended governance workflow and originate from the skill author's infrastructure.
- [PROMPT_INJECTION]: Instructions within SKILL.md and AGENTS.md guide the AI agent to follow specific governance protocols, such as using feature branches and ensuring CI job success before merging. These are legitimate operational constraints rather than safety bypasses.
Audit Metadata