22weltyang/skill-auditor

Scan AI Agent Skills and publish GitHub Code Scanning annotations.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jun 13, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: 22weltyang/skill-auditor@898dc8f29159fc08d2c5e8391f62b6daba6d8e84 # v0.8.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
pathRepository-relative directory or Skill path to scan..
recursiveDiscover and scan every Skill root below path.true
fail-onMinimum severity that fails the job.critical
min-severityMinimum severity included in rendered reports.info
configTrusted repository-relative config loaded from the base commit.""
baselineauto, none, or a repository-relative baseline from the base commit.auto
upload-sarifUpload SARIF to GitHub Code Scanning.true
upload-reportUpload JSON and SARIF workflow artifacts.true
namedescription
verdict
critical
warning
info
exit-code
sarif-file
json-file
content-hash