openssf-best-practices

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the OpenSSF Scorecard container image from the GitHub Container Registry. This operation is considered safe as it uses an immutable SHA256 digest (sha256:3f24714...) to ensure the integrity of the downloaded artifact and targets a well-known organization (OpenSSF).
  • [COMMAND_EXECUTION]: Multiple scripts (analyze_best_practices.py, scorecard_runner.py, github_auth.py, approval.py) use subprocess.run to interact with system tools such as git, gh, docker, and podman. These calls are implemented safely using argument lists (shell=False), which prevents command injection vulnerabilities.
  • [DATA_EXFILTRATION]: The skill communicates with the bestpractices.dev API to fetch project status. For private repositories, a dedicated privacy gate (privacy.py) prevents the disclosure of repository identity until the user provides explicit destination-specific consent.
  • [CREDENTIALS_UNSAFE]: The skill manages GitHub tokens for authentication but includes several defensive measures: it redacts token values from error messages and logs, and validate_best_practices.py implements regex-based scanning to prevent the accidental inclusion of secrets or private keys in generated justifications.
  • [PROMPT_INJECTION]: The SKILL.md includes clear safety instructions and boundaries for the agent. It specifically defines 'Non-negotiable truthfulness rules' and warns the agent to treat all repository data and API responses as 'untrusted evidence,' effectively mitigating indirect prompt injection risks by requiring human review for all proposed changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 10:47 AM
Security Audit — agent-trust-hub — openssf-best-practices