oss-governance
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists exclusively of instructional Markdown and structured JSON evaluation data. There are no executable scripts (Python, JavaScript, etc.) or binary files included.
- [SAFE]: The skill references established open-source projects (e.g., Node.js, Rust, Python, Apache) and industry metrics (e.g., CHAOSS) for governance research purposes. These are well-known, trusted sources in the context of open-source management.
- [SAFE]: The instructions incorporate security best practices, referencing the xz-utils backdoor incident (CVE-2024-3094) to guide the agent in recommending staged credential grants and supervised release cycles rather than immediate access.
- [SAFE]: The skill references other components from the same author ('samber/developer-relations-skills'), which represent legitimate vendor resources within the platform ecosystem.
Audit Metadata