sosa-governor

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate governance functionality, including audit log parsing, trust score management, and compliance checking based on the SOSA methodology.
  • [EXTERNAL_DOWNLOADS]: The skill references methodology documentation from the vendor's official GitHub repository (MSApps-Mobile/claude-plugins). This is an expected reference to established documentation.
  • [COMMAND_EXECUTION]: Includes instructions for the agent to use standard tools like 'grep' to scan project files for security best practices (e.g., searching for hardcoded keys). This is consistent with the skill's stated purpose as a security and auditing tool.
  • [DATA_EXPOSURE]: The skill accesses local configuration files within the plugin root (e.g., trust-state.json, budgets.json) to display governance status to the user. This is intended behavior for a reporting dashboard.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 01:39 PM
Security Audit — agent-trust-hub — sosa-governor