← Plugin catalog
Security

Awesome Maintainer Defense

DUC THANG LUU v1.1.1

Publisher description

From the marketplace listing

Inspect repository policy, GitHub Actions trust boundaries, and moderation automation without network access or repository mutation; generate reviewable remediation patches on request.

Language: English · Automatically detected from descriptions.

Files & skills

File archives

Plugin package13 files · 56.3 KBBrowse files →
Skill instructions
audit-repository-workflows1.9 KB

View saved version →

---
name: audit-repository-workflows
description: Use when reviewing a local repository for governance gaps, GitHub Actions trust-boundary risks, unsafe moderation, or a requested remediation patch.
---

# Audit repository workflows

Use the bundled auditor for deterministic local evidence. A finding is a review lead, not proof of exploitability, compromise, authorship, intent, or contributor quality.

## Scope

Resolve the exact repository directory and stay within it. The auditor reads local policy, workflow, and Git evidence without executing repository code or contacting GitHub. Live rulesets, organization policy, installed Apps, secrets, and external services remain outside the result.

## Operation

1. Read [references/commands.md](references/commands.md) and run `audit` first.
2. Prioritize critical and high findings. For each, report the rule ID, evidence location, triggering trust path, safe remediation, and missing external context.
3. If the user requested a fix or patch, run `fix`; otherwise stop after the report. `fix` writes only the requested unified-diff file and does not edit the target.
4. Review patch proposals in repository context and identify every change requiring owner authorization.

## Authority boundary

Audit and patch generation do not authorize installation, patch application, repository edits, settings changes, commits, pushes, pull requests, merges, or moderation actions. Obtain explicit authority for the specific mutation immediately before performing it.

Treat exit code 2 from `--fail-on` as a matched policy threshold. Keep JSON and SARIF private when paths or workflow details are sensitive. If local Git provenance is unavailable, state that limitation rather than inferring identity.

## Result

Return scope, finding counts, prioritized evidence, remediation options, external-state limitations, and whether a patch file was generated. Never score a contributor or infer AI use.

Referenced files: 4

Package details

Publisher declarations from the archived package. These are separate from our research and the live service's terms.

Package license
MIT
Package author
Thang Luu
Keywords
github-actions, repository-security, governance, maintainers, audit

Declared capabilities

  • Read

Package observed Oct 2, 2026.

Technical details
First seen
Sep 30, 2026 · 22:02 UTC
Last seen
Oct 2, 2026 · 18:00 UTC
Collection status
Collected

plugins_6a6edab2886c81918be9c9772e4ca904

Download plugin data (JSON)