← Plugin catalog
Security
Awesome Maintainer Defense
DUC THANG LUU v1.1.1
Publisher description
From the marketplace listing
Inspect repository policy, GitHub Actions trust boundaries, and moderation automation without network access or repository mutation; generate reviewable remediation patches on request.
Language: English · Automatically detected from descriptions.
Files & skills
File archives
Plugin package13 files · 56.3 KBBrowse files →
Skill instructions
audit-repository-workflows1.9 KB
--- name: audit-repository-workflows description: Use when reviewing a local repository for governance gaps, GitHub Actions trust-boundary risks, unsafe moderation, or a requested remediation patch. --- # Audit repository workflows Use the bundled auditor for deterministic local evidence. A finding is a review lead, not proof of exploitability, compromise, authorship, intent, or contributor quality. ## Scope Resolve the exact repository directory and stay within it. The auditor reads local policy, workflow, and Git evidence without executing repository code or contacting GitHub. Live rulesets, organization policy, installed Apps, secrets, and external services remain outside the result. ## Operation 1. Read [references/commands.md](references/commands.md) and run `audit` first. 2. Prioritize critical and high findings. For each, report the rule ID, evidence location, triggering trust path, safe remediation, and missing external context. 3. If the user requested a fix or patch, run `fix`; otherwise stop after the report. `fix` writes only the requested unified-diff file and does not edit the target. 4. Review patch proposals in repository context and identify every change requiring owner authorization. ## Authority boundary Audit and patch generation do not authorize installation, patch application, repository edits, settings changes, commits, pushes, pull requests, merges, or moderation actions. Obtain explicit authority for the specific mutation immediately before performing it. Treat exit code 2 from `--fail-on` as a matched policy threshold. Keep JSON and SARIF private when paths or workflow details are sensitive. If local Git provenance is unavailable, state that limitation rather than inferring identity. ## Result Return scope, finding counts, prioritized evidence, remediation options, external-state limitations, and whether a patch file was generated. Never score a contributor or infer AI use.
Referenced files: 4
Package details
Publisher declarations from the archived package. These are separate from our research and the live service's terms.
- Package license
- MIT
- Package author
- Thang Luu
- Keywords
- github-actions, repository-security, governance, maintainers, audit
Declared capabilities
- Read
Package observed Oct 2, 2026.
Technical details
- First seen
- Sep 30, 2026 · 22:02 UTC
- Last seen
- Oct 2, 2026 · 18:00 UTC
- Collection status
- Collected
plugins_6a6edab2886c81918be9c9772e4ca904
Download plugin data (JSON)