VegaSec / Trust report
Repository AuditSAFE

Security Kernel Repository Baseline

Repository · Report VS-UNKNOWN-REPO-STRONG

0

Score / 100

Verdict

Cleared for watchlist

Repository signals look healthy across the public surfaces we inspect. This is not a code audit.

Surface analyzed
Repository Audit
Scan source confidence
92%

Low

Methodology
Public sources · v0

Automated, not analyst-reviewed

Generated
May 25, 2026, 3:00 PM UTC

Upgrade path

Need a private evidence memo?

Turn this public artifact into an operator-reviewed Private Review memo. Paid review stays separate from the public score.

Request Private Review

Share this report

Ready

Public-source signals. Not a substitute for a formal audit. No buy/sell recommendation.

Low signal

Issue and PR flow

20/100

Low signal

Evidence depth

18/100

Low signal

Docs and security signal

18/100

Low signal

Community surface

16/100

REPO

Repository identity

Security Kernel Repository Baseline

Generated May 25, 2026, 3:00 PM

Scanned GitHub repository

https://github.com/audited-protocol/security-kernel

VegaSec summary

This repository baseline shows strong public engineering evidence: active maintainers, visible tests and a security policy. VegaSec still presents it as evidence for sign-off, not a certification shortcut.

Repository freshness

Default branch state at scan time

Public-metadata triage on commit activity. This is not a code audit; it does not run against the repository's source, only against its public GitHub metadata.

Fresh · pushed in the last 30 days
Default branch
main
Latest push
May 24, 2026, 2:00 PM(1 d ago)
Latest commit SHA
b8d2f5a91c22
Commit timestamp
May 24, 2026, 1:48 PM

Re-submit the same repository URL on /scan to refresh the snapshot. Repositories with abandoned or stale activity are removed from Trust Index eligibility automatically — see docs/specs/trust-index.md.

Risk exposure

Risk exposure by category

Each row is a public-evidence dimension the audit scored. Higher values mean more signal worth investigating before relying on this repository.

  • Issue and PR flow

    Low signal

    20/100
  • Evidence depth

    Low signal

    18/100
  • Docs and security signal

    Low signal

    18/100
  • Community surface

    Low signal

    16/100
  • Maintainer control

    Low signal

    14/100
  • Engineering controls

    Low signal

    12/100
  • Activity cadence

    Low signal

    10/100

Repository hygiene checklist

Repository-specific checks for crypto codebases: freshness, engineering controls, tests, security policy, and dependency posture. This is metadata triage, not a code audit.

  • Default branch freshness

    Recent pushes and commit timestamps captured at scan time.

  • CI / build workflow signal

    Public workflow or build automation signals that indicate regression controls.

  • Automated test signal

    Presence and depth of public test files or test runner evidence.

  • License and provenance

    Public license and repository identity signals for reuse and operator review.

  • Security policy / disclosure

    SECURITY.md, disclosure guidance, or explicit security contact evidence.

  • Dependency posture

    Manifest and dependency-update signals that affect supply-chain hygiene.

  • Maintainer and community signals

    Stars, forks, issue flow, and maintainer surface used as context, never as proof of safety.

Pass! Caution Fail Unknown

Audit pack

Repository hygiene + security posture

Per-dimension reasoning over the public GitHub metadata captured at scan time. Hygiene markers are not a security audit; UNKNOWN entries are gaps for operator review.

  • Stalenessstrong

    Evidence

    • Latest push observed 1 days ago on main.

    Caveats

    • Freshness does not validate code quality.
  • Continuous integrationunknown

    Caveats

    • CI workflow signal was not captured at scan time.

    Next step

    • Operator review required to gather the missing signal before this dimension can be scored.
  • Automated testsunknown

    Caveats

    • Test file count was not captured at scan time.

    Next step

    • Operator review required to gather the missing signal before this dimension can be scored.
  • Licenseunknown

    Caveats

    • License signal was not captured at scan time.

    Next step

    • Operator review required to gather the missing signal before this dimension can be scored.
  • Security policyunknown

    Caveats

    • SECURITY.md signal was not captured at scan time.

    Next step

    • Operator review required to gather the missing signal before this dimension can be scored.
  • Release hygieneunknown

    Caveats

    • Release tag signal was not captured at scan time.

    Next step

    • Operator review required to gather the missing signal before this dimension can be scored.
  • Dependency postureunknown

    Caveats

    • Dependabot / dependency update bot signal was not captured at scan time.

    Next step

    • Operator review required to gather the missing signal before this dimension can be scored.
  • Maintainer signalsunknown

    Caveats

    • Maintainer signals (stars / forks / open issues) were not captured at scan time.

    Next step

    • Operator review required to gather the missing signal before this dimension can be scored.

Evidence

Evidence that explains the verdict

Each row is one public-data signal pulled from automated sources. Use it as a starting point for review, not as a final answer.

  • Maintainer cadence and release notes are visible
  • Security policy and tests are present
  • Operator sign-off can focus on deeper evidence

Baseline source confidence

0%

Methodology baseline used by the verdict engine. Higher baseline reduces the penalty for ambiguous data; low baseline pushes the verdict toward UNKNOWN/WATCH. May differ from the scan source confidence shown at the top when the live scan supplied a fresher signal.

Badges

source-verifiedrepository-auditsecurity-policy-presentoperator-signoff-ready

How to read this report

Score, confidence, ranking — four moving parts, no hand-tuning.

Generated 2026-05-25T12:00:00.000-03:00 · Repository · REPO-STRONG

Score bands

  • 019

    AVOID-style triage

    Multiple high or critical findings, low source confidence, or unverified context. Public action should pause until a Private Review or a re-scan with better evidence.

  • 2049

    High caution

    Notable findings or thin evidence. Worth a Private Review before relying on the artifact.

  • 5069

    Watch

    Mixed signals: some evidence, some gaps. Re-scan after material changes to the target.

  • 7089

    Clear surface (automated) · this report

    No critical or high findings via static analysis. Not a safety claim — human review still recommended for diligence work.

  • 90100

    Strong surface (automated)

    No critical or high findings, verified source, and high source confidence. Not a safety claim — human review still recommended for diligence work.

Score
Deterministic 0–100 derived from severity counts. Same formula across every report. Lower means more risk.
Confidence
Separate axis. Measures how much VegaSec trusts the input data. Low confidence pushes the verdict toward UNKNOWN; the two are never collapsed into one number.
Ranking / percentile
Only meaningful within the eligible Trust Index set. Shown on /trust-index when the eligible pool is large enough. Today the public index is a controlled preview.

Private Review is separate

A paid Private Review does not raise the public score on this report. Public score reflects public-source evidence only. Private Review adds operator attestation and a confidential memo, never a score bump.

Export and share

  • · Shareable public URL: copy from the report actions panel.
  • · Markdown export: every export carries the report id, target, verdict, generated timestamp, and the public-data disclaimer.
  • · PDF export: not in this MVP. Tracked as a follow-up — the Markdown export contains the same content and prints cleanly to PDF from a browser today.

Community artifact

Report ready to share, copy or export.

This link preserves the scanned target, route, confidence and Scan ID. Example report links are marked as public samples; live Token Audit and Repository Audit links require submitted context and fail closed to UNKNOWN when evidence is missing.

Ready

VegaSec is intelligence and triage. It is not financial advice, does not promise returns and does not replace manual due diligence.