openssf-best-practices
openssf-best-practices
Purpose
Default intent
When this skill is explicitly invoked without a task, perform a read-only local assessment of the current Git repository. Do not contact bestpractices.dev, GitHub APIs, or Scorecard until the user grants the required destination-specific consent. Do not modify repository files, create branches, or prepare a PR without explicit apply approval.
Set SKILL_DIR to the absolute directory containing this installed SKILL.md, and use the Python 3 interpreter selected for the session:
SKILL_DIR="/absolute/path/to/openssf-best-practices"
PYTHON_BIN="$(command -v python3)"
Run every helper as "$PYTHON_BIN" "$SKILL_DIR/scripts/<helper>.py" .... SKILL_DIR is never derived from the target repository; quoted argument-array values preserve paths containing spaces. Details: field format, truthfulness rules, pinned schema provenance, Scorecard provenance, and generated-output ignore rules.
Use this skill to improve a single GitHub repository against the OpenSSF Best Practices Badge criteria while preserving the integrity of the project's self-assessment.