mkit-attest
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill describes the use of the
mkitCLI tool for key generation, attestation production, and verification. These commands are integral to the skill's stated purpose of managing commit provenance. - [SAFE]: The skill incorporates explicit security guidance, such as instructing users to store trust-roots configuration outside of the repository to prevent a 'hostile-clone' from compromising the verification process.
- [SAFE]: It provides instructions for secure key management, advising that attestation signers be kept distinct from commit keys and that private keys should never be committed to version control.
Audit Metadata