Skip to main content
Run any Skill in Manus
with one click

oss-hygiene

Stars1
Forks0
UpdatedMay 27, 2026 at 08:51

Bring an open-source GitHub repository up to community-standards and supply-chain hygiene baseline: scaffold the GitHub Community Standards files (README check, LICENSE, CODE_OF_CONDUCT, CONTRIBUTING, SECURITY, issue + PR templates), wire Dependabot version updates, the Dependency Review action, OpenSSF Scorecard, and CodeQL (when applicable), check Dependabot alerts and secret scanning, and add the OpenSSF Best Practices Badge link. Use when the user says "set up OSS hygiene", "make this repo open-source-ready", "add community health files", "wire dependabot", "add scorecard", "OSSF badge", "supply chain hardening", or invokes /oss-hygiene on a public repo. Idempotent — safe to re-run; diffs against templates and asks before overwriting. Distinct from /gh-bootstrap (merge-button + branch protection) and /safe-settings (org-scale settings as code): focuses on the contributor-facing and supply-chain surface, not merge or org policy. Run after /gh-bootstrap; before announcing the repo.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
18 files
SKILL.md
readonly