Borrowing it
Nothing to install: this file belongs to Hack23/European-Parliament-MCP-Server. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Hack23/European-Parliament-MCP-Server/main/.github/skills/open-source-governance/SKILL.mdgit clone --depth 1 https://github.com/Hack23/European-Parliament-MCP-ServerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hack23/european-parliament-mcp-server/open-source-governance)<a href="https://agentmods.dev/skills/hack23/european-parliament-mcp-server/open-source-governance"><img src="https://agentmods.dev/badge/skills/hack23/european-parliament-mcp-server/open-source-governance/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hack23/european-parliament-mcp-server/open-source-governance"><img src="https://agentmods.dev/badge/skills/hack23/european-parliament-mcp-server/open-source-governance.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 2 findings, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Data Exfiltration · line 75 Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.Fix: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted.
- medium MCP Rug Pull · line 114 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00032 | $0.04623 |
| Opus 5 | $0.00016 | $0.02312 |
| Sonnet 5 | $0.00006 | $0.00925 |
| Haiku 4.5 | $0.00003 | $0.00462 |
Grade A, and why
open-source-governance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 493 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Open Source Governance Skill
Context
This skill applies when:
- Setting up new open source repositories
- Implementing security badges (OpenSSF Scorecard, SLSA, CII Best Practices)
- Managing license compliance and dependencies
- Generating and validating SBOMs (Software Bill of Materials)
- Handling vulnerability disclosure and remediation
- Creating governance artifacts (SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md)
- Monitoring supply chain security
- Managing exceptions to open source policies
This skill enforces Hack23 Open Source Policy v2.3 requirements for transparent, secure open source development.
Rules
1. Security Posture Evidence (Policy Section 1)
- OpenSSF Scorecard Badge: All repos MUST display OpenSSF Scorecard ≥7.0
- CII Best Practices: Minimum "Passing" level badge required
- SLSA Level 3: Build provenance and integrity attestation mandatory
- Quality Gate: SonarCloud or equivalent showing "Passed" status
- FOSSA License Compliance: License scanning badge required
- Public Metrics: All security posture metrics publicly visible
2. License Compliance Framework (Policy Section 4)
- Approved Licenses Only: Use MIT, Apache-2.0, BSD-3-Clause, ISC, PostgreSQL, Mozilla Public License 2.0
- Review Required: CC0-1.0, LGPL-2.1, LGPL-3.0 need explicit approval
- Prohibited Licenses: NEVER use GPL-2.0, GPL-3.0, AGPL-3.0, proprietary/closed-source
- Dependency Scanning: Automated license checking on every PR
- REUSE Compliance: Clear licensing for all files
3. Governance Artifacts (Policy Section 2)
- SECURITY.md: Vulnerability disclosure process, supported versions, security features
- CONTRIBUTING.md: Contribution guidelines, DCO sign-off requirements
- CODE_OF_CONDUCT.md: Community standards and enforcement
- LICENSE.md: Repository license (MIT or Apache-2.0)
- CODEOWNERS: Maintainer assignments for security-critical paths
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 493 lines · 32 tokens per session scan A 845f5e81ecd8
open-source-governance is a skill published in the GitHub repository Hack23/European-Parliament-MCP-Server (28 stars, last pushed yesterday), licensed Apache-2.0. It adds 32 tokens to every session and 4,623 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
check-country-risk
Retrieve composite country risk intelligence — Country Instability Index (CII), travel advisory level, and active sanctions exposure — for one country by ISO code. Use when the user asks how risky or unstable a country is right now.
check-sanctions-pressure
Retrieve normalized OFAC sanctions pressure — designation summaries, recent additions, and per-country/per-program aggregates including sanctioned vessels and aircraft. Use when the user asks which countries or programs face sanctions pressure, or what was recently designated.
prior-art-search
Systematic 7-step methodology for comprehensive patent prior art searches and patentability assessments using BigQuery and CPC classification.
mpep-search
Expert system for searching USPTO MPEP, 35 USC statutes, 37 CFR regulations, and post-Jan 2024 updates.
source-verification
Walks through structured verification of sources, claims, images, video, and documents across five verification modes — visual media, documents, anonymous sources, expert credentials, and social media content — using the SIFT framework, forensic metadata inspection, deepfake indicators, C2PA Content Credentials, and…
Australia — ABR / ASIC Lookup
Live, real-time queries to Australian Business Register (ABR — ABN Lookup) (Australia). Drops the OpenRegistry MCP toolset onto a single-country workflow when the user names ABR / ASIC, the country, or its registry directly. ID format: 11-digit ABN or 9-digit ACN (e.g. ABN 33 123 456 789, ACN 004 028 077 for BHP Group…