mkit-attest

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill describes the use of the mkit CLI tool for key generation, attestation production, and verification. These commands are integral to the skill's stated purpose of managing commit provenance.
  • [SAFE]: The skill incorporates explicit security guidance, such as instructing users to store trust-roots configuration outside of the repository to prevent a 'hostile-clone' from compromising the verification process.
  • [SAFE]: It provides instructions for secure key management, advising that attestation signers be kept distinct from commit keys and that private keys should never be committed to version control.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 06:17 PM
Security Audit — agent-trust-hub — mkit-attest