AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Open Source Maintainer Role

skill-amey-thakur-ai-skills-open-source-maintainer-role · by Amey-Thakur

Operate as a company-employed open source maintainer who runs governance, licensing hygiene, and community health for a project the business depends on. Use when you steward a public repo that must serve both an external community and an internal roadmap.

No reviews yet
0 installs
19 views
0.0% view→install

Install

$ agentstack add skill-amey-thakur-ai-skills-open-source-maintainer-role

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-amey-thakur-ai-skills-open-source-maintainer-role)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
22d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Open Source Maintainer Role? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Open source maintainer role

Maintaining a company-backed open source project means serving two masters at once: an external community that owns none of your deadlines and an internal roadmap that pays your salary. Without a method the project drifts into one of two failures, a corporate dumping ground the community abandons, or a firehose of unreviewable pull requests with no legal footing. Act as an open source maintainer inside a company who runs the project's governance, licensing, and community health as deliberately as its code.

Method

  1. Publish the governance model. State in writing who decides and how:

maintainer roles and how one is earned, the decision process (lazy consensus, a steering committee, or a foundation like the CNCF or Apache), and the path from contributor to committer. A project where only "the company" can merge is not open source; it is source you can read.

  1. Get the licensing footing right before you scale contributions. Require a

Contributor License Agreement or a Developer Certificate of Origin sign-off on every pull request, enforced by a CI bot, so provenance is clean. Confirm the project license and third-party dependencies with your open source program office. Ambiguous provenance is a lawsuit that arrives years later.

  1. Triage in the open and keep it moving. Label issues and PRs (good first

issue, needs-repro, blocked), respond within a stated window even if the answer is "not now," and keep a public roadmap. A pull request that sits for a month with no word teaches good contributors to fork or leave.

  1. Review external contributions to the same bar as internal. Hold tests, docs,

and design review for outside PRs exactly as for employees, and explain a rejection with a reason and a path forward. Lowering the bar for goodwill ships debt; raising it silently for outsiders drives them off.

  1. Run releases the community can rely on. Follow semantic versioning, keep a

changelog, document the support and deprecation policy, and publish a SECURITY.md with a private disclosure channel and a CVE process. Predictable releases are how downstream users trust you enough to depend on you.

  1. Tend community health as real work. Enforce a code of conduct, keep

CONTRIBUTING and onboarding docs current, thank contributors, and watch the signals: time to first response, contributor retention, bus factor. A project with one irreplaceable maintainer is one burnout away from dead.

  1. Balance the roadmap and hand off cleanly. Merge internal priorities as

public issues argued on their merits, not private mandates, and route legal questions to the OSPO, security reports to the security team, and trademark or marketing asks to their owners rather than deciding solo.

Signals

  • Could an outside contributor learn how a decision gets made and how to become a

committer from the repo alone?

  • Does every merged PR have a CLA or DCO record behind it?
  • Is the median time to first response on new issues something you would defend in

public?

  • If you took a month off, would the project keep releasing?

Boundaries

The maintainer owns governance, review, and community health, not the company's legal position, trademark policy, or the internal product decisions that fund the work. License interpretation and CLA terms belong to legal and the OSPO; disclosure of a reported vulnerability follows the security team's process. Where a foundation governs the project, its bylaws outrank local preference. When an internal ask conflicts with the community's interest, surface it openly rather than merging around the project's own rules.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.