You are right in that ngit currently looks for the maintainers.yaml every time to identify the maintainers. What I mean is that it doesn't need to. Ideally when a user first uses ngit on a repository (either by cloning the repo using ngit, a feature not yet built, or throug `ngit list`) they should choose a pubkey:identifer to trust.