Privacy Policy
SkillTrust scans AI-agent skills and related configuration so developers can judge risk before installation. This policy explains the data we collect, why we collect it, and how public/private scan visibility works.
Effective date: May 27, 2026
Who we are
SkillTrust is a hosted scanner, badge service, GitHub App, and GitHub Action for AI-agent skill security. The service is built around the open-source skill-detector engine and is available at skilltrust.app.
In this policy, “SkillTrust”, “we”, “us”, and “our” mean the operator of the SkillTrust service.
Data we collect
We collect the minimum data needed to run scans, show results, operate accounts, prevent abuse, and keep the service reliable.
- Account data: email address, password hash if you use email/password login, GitHub user id/login/email if you use GitHub OAuth, session records, email verification tokens, and password reset tokens.
- Scan data: submitted GitHub URLs or uploaded archive filenames, scan status, timestamps, skill name when detected, scores, axis grades, findings, file paths/line numbers referenced by findings, share/public flags, and HMAC-hashed IP addresses for rate limits.
- Temporary scan contents: uploaded archives and cloned repositories are extracted into temporary directories for scanning and removed after the scan process finishes. Scan results and finding evidence may be stored.
- GitHub App data: installation id, installed account/repository metadata, PR/check/comment metadata, webhook deliveries, and private-beta allowlist records. GitHub installation tokens are short-lived and cached in memory only.
- GitHub Action telemetry: action version, detector version, runner OS/architecture, repository visibility, hashed repository identifier, grade, finding count, trigger, and whether delta mode was enabled. No commit SHAs, branch names, file paths, finding details, or tokens are sent by the Action heartbeat.
- Public corpus/gallery data: metadata and scan results for public repositories discovered from public sources.
- Operational data: request logs, error logs, health/metrics data, email delivery metadata, and monitoring data.
How we use data
- Run static scans and generate findings, scores, badges, share pages, PR comments, and check runs.
- Provide account login, dashboards, scan history, settings, and support.
- Enforce rate limits, detect abuse, debug failures, secure the service, and measure reliability.
- Build aggregate, non-identifying product metrics such as install counts, scan volume, and finding trends.
- Maintain public security signals for public skill repositories, including the scanned-skills gallery and public badges.
Public and private scan visibility
Scans are not public by default. A scan becomes public only when the owner shares it or when it is part of SkillTrust's public corpus/gallery workflow for public repositories.
Private repository scans are not published as SEO pages, public share links, or public badges. Public repository landing pages and badges use public scan data only.
If you enable a public share link or badge, anyone with the link or badge URL can see the public scan result until you turn sharing off or delete the scan.
Service providers
We use service providers to operate SkillTrust. These may include GitHub for OAuth, repository access, GitHub App webhooks, checks, comments, and Actions; hosting/infrastructure providers; Cloudflare for DNS and related infrastructure; Resend for transactional email; and New Relic for production monitoring.
Providers process data only as needed to provide their services to SkillTrust. If we add materially different processors for paid billing, SSO, messaging, or analytics, we will update this policy.
Security
- The scanner is static analysis: it reads files and does not execute repository code.
- Uploaded/cloned scan workspaces are temporary and isolated with restrictive filesystem permissions.
- GitHub App tokens are short-lived and not persisted to disk or database.
- We use rate limits, CSRF protections, password hashing, and TLS in production.
- Do not submit secrets, credentials, or private data you are not authorized to scan. Findings may include paths, line numbers, and evidence text from submitted content.
Retention and deletion
Temporary scan contents are deleted after scanning. Scan records, findings, public share states, GitHub installation metadata, telemetry heartbeats, logs, and backups may be retained as needed to operate the service, maintain history, prevent abuse, debug incidents, or satisfy legal/security obligations.
Signed-in users can delete individual scans from their account where the product exposes that action. For account deletion, GitHub App data deletion, or public corpus removal requests, follow the Data Deletion page.
Your choices
- You can avoid creating an account for basic public URL scans.
- You can turn public sharing off for scans you own.
- You can uninstall the GitHub App from GitHub at any time.
- You can opt out of GitHub Action telemetry by setting telemetry: false in the Action input.
- You can contact us to request access, correction, deletion, or export of account data.
Children
SkillTrust is a developer/security product and is not directed to children. Do not use SkillTrust if you are not old enough to use developer tools and GitHub services in your jurisdiction.
Changes
We may update this policy as the product changes. The effective date above shows when the current version took effect. Material changes will be reflected on this page.
Contact
For privacy, terms, deletion, or security-process questions, email legal@skilltrust.app.