Agent skill

Open Source Policy

by Hack23 in Hack23/cia

Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development

Apache-2.0Auto-check passedSecurity

Install Open Source Policy

skills CLI
$ npx skills add Hack23/cia --skill open-source-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia open-source-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/open-source-policy .claude/skills/open-source-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
open-source-policy
GitHub stars
239
Token cost
~4.6k tokens
SKILL.md length
1,088 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development

  • Works in 5 steps: Initial Security Configuration → Documentation Requirements → License Compliance → …
  • Tasks that involve Supply chain security
  • SKILL.md covers Purpose, When to Use This Skill, Required Security Badge… and Repository Setup Checklist, plus 8 more sections
  • Calls gh; reaches github.com and bestpractices.coreinfrastructure.org; needs FOSSA_API_KEY

What it does

Open Source Policy is an agent skill from Hack23/cia. Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development

Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Supply chain security, Regulatory compliance and Vulnerability scanning. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Supply chain security
  • Tasks that involve Regulatory compliance
  • Tasks that involve Vulnerability scanning

Example prompts

  • “/open-source-policy”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Initial Security Configuration
  2. Documentation Requirements
  3. License Compliance
  4. Security Badges
  5. Supply Chain Security

What it can do on your machine

Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • bestpractices.coreinfrastructure.org
    • scorecard.dev
    • sonarcloud.io
    • img.shields.io
    • api.securityscorecards.dev
    • slsa.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • FOSSA_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Open Source Policy loads about 4.6k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 1,088 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 1,088 words, ~4,641 tokens.

Download SKILL.mdSave it as .claude/skills/open-source-policy/SKILL.md (or your agent's skills folder).
name
open-source-policy
description
Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development
license
Apache-2.0

Open Source Policy Skill

Purpose

This skill provides comprehensive open source governance aligned with Hack23 AB's transparency principle, demonstrating that radical openness creates competitive advantage through evidence-based security excellence. It enables repository maintainers to implement required security badges, manage license compliance, generate SBOMs, and maintain security documentation that serves as both operational necessity and client demonstration.

When to Use This Skill

Apply this skill when:

  • ✅ Creating new public repositories
  • ✅ Preparing for OpenSSF Scorecard assessment (target: ≥7.0)
  • ✅ Configuring CII Best Practices badge (minimum: Passing)
  • ✅ Setting up SLSA Level 3 build attestations
  • ✅ Implementing license compliance scanning (FOSSA)
  • ✅ Generating SBOMs (CycloneDX/SPDX)
  • ✅ Creating security architecture documentation
  • ✅ Planning coordinated vulnerability disclosure
  • ✅ Responding to client due diligence requests

Do NOT use for:

  • ❌ Private/internal repositories (different policy applies)
  • ❌ Security incident response (use incident-response skill)
  • ❌ Tactical vulnerability remediation (use vulnerability-management skill)

Required Security Badge Architecture

mermaid
graph TB
    REPO["📦 Repository"] --> BADGES["🎖️ Security Badges"]
    
    BADGES --> OSS[OpenSSF Scorecard<br/>Target: ≥7.0]
    BADGES --> CII[CII Best Practices<br/>Minimum: Passing]
    BADGES --> SLSA[SLSA Level 3<br/>Build Attestation]
    BADGES --> QUALITY[Quality Gate<br/>SonarCloud: Passed]
    BADGES --> LICENSE[License Compliance<br/>FOSSA: Passing]
    
    OSS --> OSS_CHECKS{15 Automated Checks}
    OSS_CHECKS --> BRANCH[Branch Protection]
    OSS_CHECKS --> SIGNED[Signed Commits]
    OSS_CHECKS --> PINNED[Pinned Dependencies]
    OSS_CHECKS --> VULN[Vulnerability Scanning]
    OSS_CHECKS --> CODE_REVIEW[Code Review]
    
    CII --> CII_CRITERIA{70+ Criteria}
    CII_CRITERIA --> BASICS[Project Basics]
    CII_CRITERIA --> CHANGE[Change Control]
    CII_CRITERIA --> QUALITY_CII[Quality Assurance]
    CII_CRITERIA --> SECURITY[Security]
    CII_CRITERIA --> ANALYSIS[Analysis]
    
    SLSA --> BUILD_INTEGRITY[Build Provenance<br/>Signed Artifacts<br/>Reproducible Builds]
    
    QUALITY --> SONAR_METRICS[Code Coverage ≥80%<br/>Complexity Control<br/>Security Hotspots = 0]
    
    LICENSE --> FOSSA_SCAN[Automated License Scan<br/>Attribution Management<br/>Compliance Reports]
    
    BRANCH --> EVIDENCE["📊 Public Evidence"]
    SIGNED --> EVIDENCE
    QUALITY_CII --> EVIDENCE
    BUILD_INTEGRITY --> EVIDENCE
    SONAR_METRICS --> EVIDENCE
    FOSSA_SCAN --> EVIDENCE
    
    EVIDENCE --> CLIENTS["🤝 Client Trust<br/>Competitive Advantage"]
    
    style REPO fill:#1565C0,stroke:#0D47A1,stroke-width:3px,color:#fff
    style BADGES fill:#4CAF50,stroke:#2E7D32,stroke-width:2px,color:#fff
    style EVIDENCE fill:#FF9800,stroke:#F57C00,stroke-width:2px
    style CLIENTS fill:#9C27B0,stroke:#6A1B9A,stroke-width:2px,color:#fff

Repository Setup Checklist

Phase 1: Initial Security Configuration
  • Enable branch protection on main/master:
    • Require pull request reviews (1+ approvers)
    • Require status checks to pass
    • Require signed commits
    • Restrict push access
  • Enable Dependabot security updates
  • Enable GitHub secret scanning
  • Configure CodeQL analysis
  • Set up automated security scanning (SonarCloud)
Phase 2: Documentation Requirements
  • Create SECURITY_ARCHITECTURE.md with Mermaid diagrams
  • Create FUTURE_SECURITY_ARCHITECTURE.md for roadmap
  • Create SECURITY.md with vulnerability disclosure process
  • Create WORKFLOWS.md documenting CI/CD security gates
  • Create LICENSE (Apache 2.0 or compatible)
  • Create NOTICE for third-party attributions
  • Create CODE_OF_CONDUCT.md
  • Create CONTRIBUTING.md
  • Create CRA-ASSESSMENT.md (EU Cyber Resilience Act)
Phase 3: License Compliance
  • Integrate FOSSA scanning
  • Generate LICENSES/ directory with all dependency licenses
  • Add .reuse/dep5 for machine-readable licensing
  • Configure automated NOTICE file generation
  • Review all dependencies for license compatibility
Phase 4: Security Badges
Phase 5: Supply Chain Security
  • Implement SBOM generation (CycloneDX or SPDX)
  • Configure artifact signing (Sigstore/cosign)
  • Pin all GitHub Actions dependencies
  • Enable Dependabot version updates
  • Set up automated vulnerability scanning

OpenSSF Scorecard Optimization Guide

Target score: ≥7.0 across 15 automated checks

Critical Checks (Must Pass)

1. Branch-Protection (Weight: High)

yaml
# .github/branch-protection.yml
required_status_checks:
  strict: true
  contexts:
    - "CodeQL"
    - "SonarCloud Code Analysis"
    - "Security Scan"
required_pull_request_reviews:
  required_approving_review_count: 1
  dismiss_stale_reviews: true
enforce_admins: true
restrictions: null

2. Signed-Releases (Weight: High)

yaml
# .github/workflows/release.yml
- name: Sign artifacts
  uses: sigstore/gh-action-sigstore-python@cd84bbf8fc2bdfd61e0b9bb63e1a18050dd9ff99 # v2.1.1
  with:
    inputs: ./dist/*
- name: Generate SBOM
  uses: anchore/sbom-action@d94f46e13c6c62f59525ac9a1e147a99dc0b9bf5 # v0.15.1
  with:
    format: cyclonedx-json

3. Pinned-Dependencies (Weight: High)

yaml
# Pin ALL dependencies to specific SHA
# Bad:
uses: actions/checkout@v4
# Good:
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1

4. Token-Permissions (Weight: High)

yaml
# .github/workflows/*.yml
permissions:
  contents: read  # Least privilege
  security-events: write  # Only if needed

5. Vulnerabilities (Weight: High)

  • Enable Dependabot alerts
  • Configure CodeQL scanning
  • Integrate SonarCloud security analysis
  • Set SLAs for vulnerability remediation (see below)

6. Code-Review (Weight: High)

  • Require at least 1 approving review
  • No commits directly to default branch
  • Use CODEOWNERS file
Important Checks (Should Pass)

7. Dangerous-Workflow

  • Don't use pull_request_target without security review
  • Avoid script injection from user-controlled data

8. License

  • Include LICENSE file (Apache 2.0)
  • Add SPDX identifier to source files

9. SAST

  • Enable CodeQL with security queries
  • Add SonarCloud with Security Hotspot detection

10. Dependency-Update-Tool

  • Enable Dependabot for both security and version updates
yaml
# .github/dependabot.yml
version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
    open-pull-requests-limit: 10
Additional Checks

11. Fuzzing (Java/Spring projects)

  • Configure JQF for fuzz testing where applicable

12. Maintained

  • Commit at least every 90 days
  • Respond to issues within 14 days

13. Packaging

  • Publish to npm/Maven Central with provenance

14. Security-Policy

  • Maintain SECURITY.md with disclosure process

15. Binary-Artifacts

  • Avoid committing binary files (use package managers)

CII Best Practices Badge Requirements

Apply for badge at: https://bestpractices.coreinfrastructure.org/

Passing Level (Minimum Required)

Basics (13 criteria):

  • Project website URL
  • Basic project documentation
  • FLOSS license (Apache 2.0)
  • Public version-controlled source repository
  • Public discussion forum (GitHub Issues)
  • English language communication
  • Bug reporting process (SECURITY.md)
  • Security vulnerability disclosure (SECURITY.md)
  • Working build system
  • Automated test suite
  • New functionality testing
  • Warning flags enabled
  • Release notes for each version

Change Control (6 criteria):

  • Public version control (GitHub)
  • Unique version numbering (SemVer)
  • Changelog maintained
  • Previous versions available
  • Identification of committers
  • Commit review before integration

Quality (13 criteria):

  • Automated test suite runs on CI
  • Build warnings free
  • Static analysis (SonarCloud)
  • Dynamic analysis (OWASP ZAP for web apps)
  • Memory safety (Java/managed languages)
  • Automated test suite covers ≥80% statements
  • Test suite covers ≥70% branches
  • New tests added with new features
  • Continuous integration tests
  • Test policy documented

Security (11 criteria):

  • Secure coding standards documented
  • HTTPS for website/downloads
  • TLS 1.2+ for encrypted connections
  • Secure delivery mechanism (signed releases)
  • Automated security vulnerability detection
  • No known unpatched critical vulnerabilities
  • Public vulnerability disclosure process
  • Private vulnerability reporting channel
  • Hardening mechanism documented
  • Crypto published/peer-reviewed
  • Input validation

Analysis (10 criteria):

  • Static code analysis
  • Address all medium+ severity issues
  • Memory-safe language or analysis
  • Dynamic analysis on releases
  • Code coverage measurement
  • Continuous automated testing

Reference Implementation:

Show full SKILL.md (366 more words)Show less

SLSA Level 3 Implementation

Achieve Supply Chain Levels for Software Artifacts Level 3:

Requirements
  1. Source integrity: GitHub-hosted with signed commits
  2. Build integrity: Reproducible builds with provenance
  3. Provenance: Signed attestations for all artifacts
  4. Isolation: Builds run in ephemeral environments
Implementation
yaml
# .github/workflows/release.yml
name: Release with SLSA3
on:
  push:
    tags:
      - 'v*'

permissions:
  contents: read
  id-token: write  # For SLSA attestation

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
      - name: Build
        run: |
          npm ci
          npm run build
      - name: Generate provenance
        uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v1.9.0
        with:
          subjects: "dist/*"

Verification:

bash
# Verify SLSA attestation
gh attestation verify artifact.tar.gz --owner Hack23

License Compliance Framework

Approved Licenses (Pre-approved)

✅ Permissive:

  • MIT
  • Apache 2.0
  • BSD (2-clause, 3-clause)
  • ISC

✅ Weak Copyleft:

  • LGPL 2.1/3.0
  • MPL 2.0
  • EPL 2.0

✅ Documentation:

  • CC-BY-4.0
  • CC-BY-SA-4.0
Review Required (CEO Approval)

⚠️ Strong Copyleft:

  • GPL 2.0/3.0
  • AGPL 3.0

⚠️ Non-standard:

  • Custom licenses
  • Modified licenses
Prohibited

❌ Never Use:

  • Licenses with advertising clauses
  • Licenses incompatible with Apache 2.0
  • Unclear terms or missing attribution
FOSSA Integration

Setup:

yaml
# .github/workflows/fossa.yml
name: FOSSA Scan
on: [push, pull_request]

jobs:
  fossa:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
      - uses: fossas/fossa-action@f61a2c7c4e3c0f1b20a199f4eafe9e8e02d5bd7d # v1.3.3
        with:
          api-key: ${{ secrets.FOSSA_API_KEY }}

Badge:

markdown
[![FOSSA Status](https://app.fossa.com/api/projects/git%2Bgithub.com%2FHack23%2FREPO.svg?type=shield)](https://app.fossa.com/projects/git%2Bgithub.com%2FHack23%2FREPO?ref=badge_shield)

SBOM Generation Requirements

Per Secure Development Policy, generate SBOMs for all releases:

CycloneDX Format (Preferred for Java/Maven)
yaml
# pom.xml
<plugin>
  <groupId>org.cyclonedx</groupId>
  <artifactId>cyclonedx-maven-plugin</artifactId>
  <version>2.7.11</version>
  <executions>
    <execution>
      <goals>
        <goal>makeAggregateBom</goal>
      </goals>
    </execution>
  </executions>
</plugin>
SPDX Format (Preferred for npm/Node.js)
yaml
# .github/workflows/sbom.yml
- name: Generate SPDX SBOM
  run: |
    npm install -g @cyclonedx/cyclonedx-npm
    cyclonedx-npm --output-format spdx --output-file sbom.spdx.json

Artifact Locations:

  • Maven: target/bom.json
  • npm: sbom.spdx.json
  • GitHub Release: Attach SBOM to release assets

Vulnerability Management SLAs

Aligned with Vulnerability Management Policy:

SeverityDetectionRemediation DeadlineEscalation
CriticalAutomated (Dependabot/CodeQL)24 hoursImmediate CEO notification
HighAutomated7 daysWeekly status update
MediumAutomated30 daysMonthly review
LowAutomated90 daysQuarterly review

Remediation Options:

  1. Update dependency (preferred)
  2. Apply patch (if update breaks compatibility)
  3. Mitigate (compensating controls)
  4. Accept risk (document in Risk Register, CEO approval required)

Security Architecture Documentation Matrix

Per Secure Development Policy:

DocumentPurposeMermaid DiagramsUpdate Frequency
SECURITY_ARCHITECTURE.mdCurrent security implementationAuthentication flow, Data flow, InfrastructureEvery release
FUTURE_SECURITY_ARCHITECTURE.mdPlanned improvementsTarget architecture, Migration planQuarterly
THREAT_MODEL.mdSTRIDE analysis, Attack treesAttack trees, Data flow diagramsAnnually or with major changes
WORKFLOWS.mdCI/CD security gatesPipeline diagramWhen workflows change
SECURITY.mdVulnerability disclosureN/AAnnually

Mermaid Diagram Types:

  • flowchart - Authentication/authorization flows
  • sequenceDiagram - Request/response security
  • graph - Architecture layers
  • erDiagram - Data model security

Practical Examples

Example 1: CIA Platform (High Maturity)

Security Badge Status:

  • ✅ OpenSSF Scorecard: 8.1/10
  • ✅ CII Best Practices: Passing (100%)
  • ✅ SLSA Level 3: Implemented
  • ✅ SonarCloud: A (0 Security Hotspots)
  • ✅ FOSSA: Passing (0 Critical Issues)

Documentation:

Example 2: Setting Up New Repository

Step-by-step:

bash
# 1. Clone template
gh repo create Hack23/new-project --template Hack23/cia --public

# 2. Enable security features
gh api repos/Hack23/new-project/vulnerability-alerts -X PUT
gh api repos/Hack23/new-project/automated-security-fixes -X PUT

# 3. Configure branch protection
gh api repos/Hack23/new-project/branches/main/protection -X PUT \
  --input branch-protection.json

# 4. Add FOSSA
# Visit https://app.fossa.com/ and add repository

# 5. Register with OpenSSF Scorecard
# Visit https://scorecard.dev/ and add repository

# 6. Apply for CII Best Practices
# Visit https://bestpractices.coreinfrastructure.org/

# 7. Configure SonarCloud
# Visit https://sonarcloud.io/ and import project

# 8. Create required documentation
touch SECURITY_ARCHITECTURE.md
touch FUTURE_SECURITY_ARCHITECTURE.md
touch THREAT_MODEL.md
touch WORKFLOWS.md
touch SECURITY.md
touch CRA-ASSESSMENT.md

# 9. Add badges to README.md
# See badge examples below

Badge Examples for README.md

markdown
## Security Posture

[![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/Hack23/REPO/badge)](https://scorecard.dev/viewer/?uri=github.com/Hack23/REPO)
[![CII Best Practices](https://bestpractices.coreinfrastructure.org/projects/XXXX/badge)](https://bestpractices.coreinfrastructure.org/projects/XXXX)
[![SLSA 3](https://slsa.dev/images/gh-badge-level3.svg)](https://github.com/Hack23/REPO/attestations)
[![Quality Gate Status](https://sonarcloud.io/api/project_badges/measure?project=Hack23_REPO&metric=alert_status)](https://sonarcloud.io/summary/new_code?id=Hack23_REPO)
[![FOSSA Status](https://app.fossa.com/api/projects/git%2Bgithub.com%2FHack23%2FREPO.svg?type=shield)](https://app.fossa.com/projects/git%2Bgithub.com%2FHack23%2FREPO?ref=badge_shield)

## Security Documentation

[![Threat Model](https://img.shields.io/badge/Threat_Model-Public_Documentation-blue?style=flat-square&logo=github&logoColor=white)](./THREAT_MODEL.md)
[![STRIDE Analysis](https://img.shields.io/badge/STRIDE-Complete_Analysis-green?style=flat-square&logo=security&logoColor=white)](./THREAT_MODEL.md#stride-threat-analysis)
[![Security Architecture](https://img.shields.io/badge/Architecture-Documented-orange?style=flat-square&logo=blueprint&logoColor=white)](./SECURITY_ARCHITECTURE.md)

Standards & Policy References

Core Hack23 ISMS Policies:

All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/open-source-policy of Hack23/cia.

Open the folder on GitHubat commit bbed538

Compare with similar skills

Open Source Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Open Source Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Open Source Policy this skillHack23/cia239—~4.6kAutomated safety check: PassApache-2.0
Codebase Cleanup Deps Auditaiskillstore/marketplace4307 repos~490Automated safety check: PassNone
Dependency AuditMathews-Tom/armory328—~2.7kAutomated safety check: PassMIT
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Sbom SyftAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Sca Securityhardw00t/ai-security-arsenal104—~3kAutomated safety check: PassNone

Similar skills

  • Codebase Cleanup Deps Audit

    aiskillstore/marketplace

    You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.

    430 GitHub starsUsed in 7 repos~490 tokens
    SecurityAuto-check passed
  • Dependency Audit

    Mathews-Tom/armory

    Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.

    328 GitHub stars~2.7k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Sbom Syft

    AgentSecOps/SecOpsAgentKit

    Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives.

    220 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check passed
  • Sca Security

    hardw00t/ai-security-arsenal

    Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to…

    104 GitHub stars~3k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Vulnerability Scanning

    secondsky/claude-skills

    Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.

    227 GitHub stars~799 tokensUpdated 10 days ago
    SecurityAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Questions about Open Source Policy

What does Open Source Policy do?

Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development. Open Source Policy is an agent skill from Hack23/cia.

When should I use Open Source Policy?

Open Source Policy fits situations like: tasks that involve Supply chain security; tasks that involve Regulatory compliance; tasks that involve Vulnerability scanning.

How do I install Open Source Policy in Claude Code?

Run `npx skills add Hack23/cia --skill open-source-policy -a claude-code`. Or copy the skill folder (.github/skills/open-source-policy in Hack23/cia) into .claude/skills/open-source-policy in your project. Claude Code loads it when a task matches its description.

How do I install Open Source Policy in Codex?

Run `npx skills add Hack23/cia --skill open-source-policy -a codex`. Or copy the skill folder (.github/skills/open-source-policy in Hack23/cia) into .agents/skills/open-source-policy in your project. Codex loads it when a task matches its description.

Can I use Open Source Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill open-source-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/open-source-policy, .gemini/skills/open-source-policy, .github/skills/open-source-policy and .opencode/skills/open-source-policy in your project.

What does Open Source Policy need to run?

Going by SKILL.md and its folder, Open Source Policy needs the command-line tools its instructions call (gh) and credentials named FOSSA_API_KEY.

Does Open Source Policy access the network?

SKILL.md names 7 domains. In commands or code: github.com, bestpractices.coreinfrastructure.org, scorecard.dev, sonarcloud.io, img.shields.io, api.securityscorecards.dev and slsa.dev; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Open Source Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Open Source Policy use?

Open Source Policy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Open Source Policy use?

About 4.6k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Open Source Policy?

Skills that share tags, products or a category with Open Source Policy: Codebase Cleanup Deps Audit (aiskillstore/marketplace, 430 stars), Dependency Audit (Mathews-Tom/armory, 328 stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars) and Sbom Syft (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Open Source Policy?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.