oss-scorecard

Assess open-source project security and maintenance using OpenSSF Scorecard.

2|Updated Jan 15, 2026
One-click install
npx skills add https://github.com/DTMC-marketplace/governance --skill oss-scorecard
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: oss-scorecard
Source: https://github.com/DTMC-marketplace/governance/tree/main/skills/oss-scorecard
Command: npx skills add https://github.com/DTMC-marketplace/governance --skill oss-scorecard

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill addresses the challenge of evaluating the security posture of open-source projects, providing a clear assessment of their risk and maintenance status.

Core Features & Use Cases

  • Security Posture Assessment: Utilizes OpenSSF Scorecard to analyze open-source projects.
  • Risk Identification: Identifies potential security vulnerabilities and maintenance issues.
  • Compliance Evaluation: Supports assessment against regulatory requirements like the EU AI Act's Art. 15.
  • Use Case: A development team needs to integrate a new open-source library. They use this Skill to quickly assess its security risks before adoption.

Quick Start

Use the oss-scorecard skill to assess the security of the 'requests' library on GitHub.

Frequently Asked Questions about oss-scorecard

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess open-source security risks before adopting a new library?

To assess open-source security risks, this Skill evaluates the security posture and maintenance status of projects using OpenSSF Scorecard. It identifies potential vulnerabilities and maintenance issues to support risk mitigation strategies before adoption.

Can I check if an open-source project complies with the EU AI Act?

You can check EU AI Act compliance by evaluating open-source projects against regulatory requirements like Article 15. This Skill supports compliance evaluation by assessing the project's security posture and maintenance status using OpenSSF Scorecard.

Does the OpenSSF Scorecard assessment require GitHub repository integration?

OpenSSF Scorecard assessment requires integration with GitHub repositories to retrieve project data for analysis. This connection allows the Skill to accurately analyze the open-source project's security posture and maintenance status.

What is the best way to perform a cybersecurity audit for open-source dependencies?

The best way to perform a cybersecurity audit for open-source dependencies is using OpenSSF Scorecard to analyze project data. This approach identifies security vulnerabilities and maintenance issues, providing a clear assessment of risk for cybersecurity audits.

How do I identify maintenance issues in open-source projects?

To identify maintenance issues in open-source projects, this Skill uses OpenSSF Scorecard to retrieve and analyze GitHub repository data. It evaluates the project's maintenance status and flags potential security vulnerabilities during the risk assessment.