← Awesome Maintainer DefenseCONTENT HISTORY

Update to Awesome Maintainer Defense

Snapshot Sep 30, 2026 · 23:13 UTC · version 1.1.1

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "audit-repository-workflows",
  "description": "Use when reviewing a local repository for governance gaps, GitHub Actions trust-boundary risks, unsafe moderation, or a requested remediation patch.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 240
    },
    {
      "relative_path": "references/commands.md",
      "size_in_bytes": 1585
    },
    {
      "relative_path": "scripts/maintainer-defense.py",
      "size_in_bytes": 95866
    },
    {
      "relative_path": "scripts/run_auditor.py",
      "size_in_bytes": 569
    }
  ],
  "skill_md_contents": "---\nname: audit-repository-workflows\ndescription: Use when reviewing a local repository for governance gaps, GitHub Actions trust-boundary risks, unsafe moderation, or a requested remediation patch.\n---\n\n# Audit repository workflows\n\nUse the bundled auditor for deterministic local evidence. A finding is a review lead, not proof of exploitability, compromise, authorship, intent, or contributor quality.\n\n## Scope\n\nResolve the exact repository directory and stay within it. The auditor reads local policy, workflow, and Git evidence without executing repository code or contacting GitHub. Live rulesets, organization policy, installed Apps, secrets, and external services remain outside the result.\n\n## Operation\n\n1. Read [references/commands.md](references/commands.md) and run `audit` first.\n2. Prioritize critical and high findings. For each, report the rule ID, evidence location, triggering trust path, safe remediation, and missing external context.\n3. If the user requested a fix or patch, run `fix`; otherwise stop after the report. `fix` writes only the requested unified-diff file and does not edit the target.\n4. Review patch proposals in repository context and identify every change requiring owner authorization.\n\n## Authority boundary\n\nAudit and patch generation do not authorize installation, patch application, repository edits, settings changes, commits, pushes, pull requests, merges, or moderation actions. Obtain explicit authority for the specific mutation immediately before performing it.\n\nTreat exit code 2 from `--fail-on` as a matched policy threshold. Keep JSON and SARIF private when paths or workflow details are sensitive. If local Git provenance is unavailable, state that limitation rather than inferring identity.\n\n## Result\n\nReturn scope, finding counts, prioritized evidence, remediation options, external-state limitations, and whether a patch file was generated. Never score a contributor or infer AI use.\n"
}

SHA-256: 67b90d415916b5335855420bb9246964f976bbede1b59351510ba3ab626dac5b