openssf-best-practices
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the OpenSSF Scorecard container image from the GitHub Container Registry. This operation is considered safe as it uses an immutable SHA256 digest (
sha256:3f24714...) to ensure the integrity of the downloaded artifact and targets a well-known organization (OpenSSF). - [COMMAND_EXECUTION]: Multiple scripts (
analyze_best_practices.py,scorecard_runner.py,github_auth.py,approval.py) usesubprocess.runto interact with system tools such asgit,gh,docker, andpodman. These calls are implemented safely using argument lists (shell=False), which prevents command injection vulnerabilities. - [DATA_EXFILTRATION]: The skill communicates with the
bestpractices.devAPI to fetch project status. For private repositories, a dedicated privacy gate (privacy.py) prevents the disclosure of repository identity until the user provides explicit destination-specific consent. - [CREDENTIALS_UNSAFE]: The skill manages GitHub tokens for authentication but includes several defensive measures: it redacts token values from error messages and logs, and
validate_best_practices.pyimplements regex-based scanning to prevent the accidental inclusion of secrets or private keys in generated justifications. - [PROMPT_INJECTION]: The
SKILL.mdincludes clear safety instructions and boundaries for the agent. It specifically defines 'Non-negotiable truthfulness rules' and warns the agent to treat all repository data and API responses as 'untrusted evidence,' effectively mitigating indirect prompt injection risks by requiring human review for all proposed changes.
Audit Metadata