oss-governance

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists exclusively of instructional Markdown and structured JSON evaluation data. There are no executable scripts (Python, JavaScript, etc.) or binary files included.
  • [SAFE]: The skill references established open-source projects (e.g., Node.js, Rust, Python, Apache) and industry metrics (e.g., CHAOSS) for governance research purposes. These are well-known, trusted sources in the context of open-source management.
  • [SAFE]: The instructions incorporate security best practices, referencing the xz-utils backdoor incident (CVE-2024-3094) to guide the agent in recommending staged credential grants and supervised release cycles rather than immediate access.
  • [SAFE]: The skill references other components from the same author ('samber/developer-relations-skills'), which represent legitimate vendor resources within the platform ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — oss-governance