Terms of Service
These terms govern use of SkillTrust's hosted scanner, badges, public gallery, GitHub App, and GitHub Action integrations.
Effective date: May 27, 2026
Acceptance
By using SkillTrust, creating an account, submitting a scan, installing the GitHub App, or using the SkillTrust GitHub Action, you agree to these Terms. If you use SkillTrust for an organization, you represent that you have authority to bind that organization.
The service
SkillTrust provides static analysis for AI-agent skills and related configuration, including files such as SKILL.md, CLAUDE.md, .claude/settings.json, hooks, and MCP configuration. Results may include scores, axis grades, findings, badges, public pages, PR comments, and check runs.
The open-source skill-detector engine is licensed separately under its own open-source license. These Terms apply to the hosted SkillTrust service and integrations.
Accounts and authorization
- Provide accurate account information and keep credentials secure.
- Use OAuth, GitHub App installs, and repository access only for accounts and repositories you are authorized to scan.
- You are responsible for activity under your account, tokens, GitHub installation, and CI configuration.
- Tell us promptly if you believe your account or installation has been compromised.
Your content
You retain ownership of repositories, archives, code, prompts, configuration, and other content you submit or authorize SkillTrust to access.
You grant SkillTrust a limited license to fetch, upload, extract, analyze, store, display, and transmit that content and derived results as needed to provide the service, including scan history, public share links you enable, badges, PR comments, check runs, support, security, and abuse prevention.
For public repositories and public corpus scans, SkillTrust may display public repository metadata and derived scan results in public pages, badges, reports, or aggregate statistics.
Prohibited use
- Do not submit content you are not authorized to scan or disclose.
- Do not use SkillTrust to attack, overload, probe, scrape, or disrupt SkillTrust, GitHub, or third-party systems.
- Do not bypass rate limits, access controls, CSRF protections, or private-scan visibility controls.
- Do not upload malware, secrets dumps, personal data dumps, or content that violates law or third-party rights.
- Do not misrepresent SkillTrust results as a certification, endorsement, legal opinion, or guarantee of safety.
Scanner limitations
SkillTrust is a security aid, not a guarantee. The scanner is static analysis and may produce false positives, false negatives, incomplete results, or outdated results. A clean score does not mean a skill is safe, compliant, or vulnerability-free.
Results are not legal, compliance, audit, or professional security advice. You remain responsible for review, testing, policy decisions, and incident response in your own environment.
GitHub App and Action
If you install the GitHub App or Action, SkillTrust may read repository contents through GitHub APIs, receive webhooks, create/update check runs, and post/edit PR comments according to the permissions you grant in GitHub.
You can uninstall the GitHub App or remove the Action workflow at any time. GitHub Action telemetry is documented and can be disabled with the telemetry input.
Public sharing, badges, and gallery pages
Public share links, badges, and public gallery/repository pages are visible to anyone. Do not make a result public unless you are comfortable publishing the result and finding metadata.
SkillTrust may remove, hide, rate-limit, or refresh public pages and badges that are abusive, misleading, stale, legally risky, or operationally harmful.
Availability and changes
SkillTrust is a v0.x product. We may change, suspend, rate-limit, or discontinue features. Unless a separate written agreement says otherwise, SkillTrust is provided without uptime commitments or support guarantees.
Disclaimers
SkillTrust is provided “as is” and “as available”. To the maximum extent allowed by law, we disclaim warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, availability, and error-free operation.
To the maximum extent allowed by law, SkillTrust will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages; lost profits; lost data; security incidents in your environment; or business interruption arising from use of or inability to use the service.
Termination
You may stop using SkillTrust at any time. We may suspend or terminate access if we believe you violated these Terms, created risk for the service or others, or if we discontinue the service. Data deletion requests are handled under the Data Deletion page.
Contact
For privacy, terms, deletion, or security-process questions, email legal@skilltrust.app.