trust-scorecard

Compute and publish the quarterly Trust Scorecard tracking twelve commitments against targets.

Updated Apr 21, 2026
One-click install
npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill trust-scorecard
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: trust-scorecard
Source: https://github.com/brucebanner010198-commits/DevSecOps-Agency/tree/main/skills/trust-scorecard
Command: npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill trust-scorecard

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Quantifies and publishes the quarterly Trust Scorecard to track the twelve public commitments against targets and provide an auditable evidence trail.

Core Features & Use Cases

  • Automates measurement of all TRUST.md commitments against defined targets.
  • Assembles evidence from session logs, ADRs, LESSONS, and waivers to produce a verifiable scorecard.
  • Supports on-demand runs prior to external audits or public disclosures and updates the TRUST.md link accordingly.
  • Use Case: governance teams review quarterly health, surface drift signals, and trigger corrective actions.

Quick Start

Run the scorecard workflow at quarter end to publish the report with sourced evidence.

Frequently Asked Questions about trust-scorecard

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate quarterly compliance reporting against public commitments?

No, the Trust Scorecard currently supports quarterly measurement and on-demand runs before audits or public disclosures. It does not provide real-time commitment monitoring or continuous drift tracking outside scheduled governance intervals.

What evidence is needed to audit governance commitments for a Trust Scorecard?

Generate an audit-ready Trust Scorecard by running the workflow on-demand before public announcements. It measures all TRUST.md commitments against targets, assembles evidence from session logs and waivers, and updates TRUST.md references with the published report.

Can I run a compliance scorecard on-demand before external audits?

Yes, the scorecard workflow can be applied on-demand before audits or public announcements. It assembles evidence from ADRs, LESSONS, and waivers to produce a verifiable report and updates TRUST.md references accordingly.

Does the Trust Scorecard require specific dependencies or components to function?

No, the Trust Scorecard requires no external dependencies or components. It operates independently to compute metrics, assemble evidence from existing artifacts, and publish the quarterly report with TRUST.md reference updates.

Why does my quarterly compliance report show drift signals across governance artifacts?

Drift signals appear in the quarterly scorecard when measured commitments deviate from defined targets. The report surfaces these signals by cross-referencing ADRs, LESSONS, and waivers, enabling governance teams to trigger corrective actions.