Privacy Policy

SkillTrust scans AI-agent skills and related configuration so developers can judge risk before installation. This policy explains the data we collect, why we collect it, and how public/private scan visibility works.

Effective date: September 7, 2026

Who we are

SkillTrust is a hosted scanner, badge service, GitHub App, and GitHub Action for AI-agent skill security. The service is built around the open-source skill-detector engine and is available at skilltrust.app.

In this policy, “SkillTrust”, “we”, “us”, and “our” mean the operator of the SkillTrust service.

Data we collect

We collect the minimum data needed to run scans, show results, operate accounts, prevent abuse, and keep the service reliable.

  • Account data: email address, password hash if you use email/password login, GitHub user id/login/email if you use GitHub OAuth, session records, email verification tokens, and password reset tokens.
  • Scan data: submitted GitHub URLs or uploaded archive filenames, scan status, timestamps, skill name when detected, scores, axis grades, findings, file paths/line numbers referenced by findings, share/public flags, and HMAC-hashed IP addresses for rate limits.
  • Temporary scan contents: uploaded archives, cloned repositories, and pasted skill text are written only to temporary scan storage for the run and deleted once it finishes — pasted source text is never persisted beyond that. Scan metadata and findings may be retained.
  • GitHub App data: installation id, installed account/repository metadata, PR/check/comment metadata, webhook deliveries, and access allowlist records. GitHub installation tokens are short-lived and cached in memory only.
  • GitHub Action telemetry: action version, detector version, runner OS/architecture, repository visibility, hashed repository identifier, grade, finding count, trigger, and whether delta mode was enabled. No commit SHAs, branch names, file paths, finding details, or tokens are sent by the Action heartbeat.
  • Public corpus/gallery data: metadata and scan results for public repositories discovered from public sources.
  • Operational data: request logs, error logs, health/metrics data, email delivery metadata, and monitoring data.
  • Anonymous scan cookie: if you submit a scan without an account, we set a cookie holding a random id for 90 days, which identifies the report as yours so you can turn its public sharing on and off. It is used for nothing else.
  • Anonymous scan retention: an anonymous pasted or uploaded report is deleted after 30 days, even if it was shared publicly; an anonymous report of a public GitHub repository may remain, since repository pages and badges are built from it.

Public-site analytics and session replay

SkillTrust is the controller for public-site analytics. We use PostHog Cloud EU as our analytics processor to understand acquisition, aggregate product usage, the scan funnel, and — only after consent — usability through masked session replay. Contact legal@skilltrust.app for controller or privacy requests.

Before you choose, we send nothing to PostHog. If you reject, we use no analytics cookies, browser identifier, approximate location, or replay. PostHog still counts allowlisted page visits and scan outcomes without cookies by transiently combining IP address and user agent into an anonymous hash that changes daily. If you accept, PostHog uses first-party anonymous browser/session identifiers and may process approximate country, route name, referring domain, approved UTM campaign fields, browser, operating system, device type, viewport, clicks, scrolls, and masked DOM snapshots.

Analytics runs only on the public home, skill check form, gallery, methodology, documentation, and legal pages. It is excluded from scan/report/share URLs, repository pages, accounts, settings, CI/install, demos, badges, APIs, health and internal routes, and error pages. We disable broad element autocapture, mask all form inputs, stop replay before a scan submission leaves the browser, and exclude scan progress, errors, findings, targets, filenames, pasted/uploaded content, evidence, email, CSRF values, URL queries and fragments, and full referrers. Do not submit secrets even with these controls.

Accepted analytics events are retained for up to one year and session replays for up to 30 days in PostHog's EU cloud region. PostHog's DPA and current subprocessor information are available at https://posthog.com/docs/privacy/gdpr-compliance and https://posthog.com/subprocessors. The legal basis for first-party persistence, approximate location, and replay is consent; limited cookieless audience measurement is used only under the legal basis confirmed for SkillTrust's operating jurisdiction.

  • skilltrust.analytics.consent: strictly necessary preference containing policy version and accepted/rejected choice; kept until you change it or clear browser storage.
  • Accepted-mode PostHog first-party storage: anonymous analytics and replay identifiers; expiry is managed by the PostHog SDK and can be removed immediately through Analytics settings below.

How we use data

  • Run static scans and generate findings, scores, badges, share pages, PR comments, and check runs.
  • Respond to support, privacy, and deletion requests you send us.
  • Enforce rate limits, detect abuse, debug failures, secure the service, and measure reliability.
  • Build aggregate, non-identifying product metrics such as install counts, scan volume, and finding trends.
  • Maintain public security signals for public skill repositories, including the scanned-skills gallery and public badges.

Public and private scan visibility

Scans are not public by default. A scan becomes public only when the owner shares it or when it is part of SkillTrust's public corpus/gallery workflow for public repositories.

Private repository scans are not published as SEO pages, public share links, or public badges. Public repository landing pages and badges use public scan data only.

If you enable a public share link or badge, anyone with the link or badge URL can see the public scan result until you turn sharing off or delete the scan.

Service providers

We use service providers to operate SkillTrust. These may include GitHub for OAuth, repository access, GitHub App webhooks, checks, comments, and Actions; hosting/infrastructure providers; Cloudflare for DNS and related infrastructure; Resend for transactional email; and New Relic for production monitoring.

Providers process data only as needed to provide their services to SkillTrust. Public-site analytics and consented session replay use PostHog Cloud EU as described above. If we add materially different processors for paid billing, SSO, or messaging, we will update this policy.

Security

  • The scanner is static analysis: it reads files and does not execute repository code.
  • Uploaded/cloned scan workspaces are temporary and isolated with restrictive filesystem permissions.
  • GitHub App tokens are short-lived and not persisted to disk or database.
  • We use rate limits, CSRF protections, password hashing, and TLS in production.
  • Do not submit secrets, credentials, or private data you are not authorized to scan. Findings may include paths, line numbers, and evidence text from submitted content.

Retention and deletion

Temporary scan contents are deleted after scanning. Scan records, findings, public share states, GitHub installation metadata, telemetry heartbeats, logs, and backups may be retained as needed to operate the service, maintain history, prevent abuse, debug incidents, or satisfy legal/security obligations.

Signed-in users can delete individual scans from their account where the product exposes that action. For account deletion, GitHub App data deletion, or public corpus removal requests, follow the Data Deletion page.

Your choices

  • You can turn public sharing off for scans you own.
  • You can uninstall the GitHub App from GitHub at any time.
  • You can opt out of GitHub Action telemetry by setting telemetry: false in the Action input.
  • You can reject analytics or withdraw consent at any time through Analytics settings on this Privacy Policy page.
  • You can contact us to request access, correction, deletion, or export of account data.

Children

SkillTrust is a developer/security product and is not directed to children. Do not use SkillTrust if you are not old enough to use developer tools and GitHub services in your jurisdiction.

Changes

We may update this policy as the product changes. The effective date above shows when the current version took effect. Material changes will be reflected on this page.

Analytics settings

Current choice: Not selected

Accept anonymous analytics, approximate country, and masked session replay, or reject optional analytics and continue with cookieless visit counts only. You can change this choice at any time.

Contact

For privacy, terms, deletion, or security-process questions, email legal@skilltrust.app.