stash-supply-chain-security
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as documentation for supply chain security controls within a pnpm workspace environment.\n- [SAFE]: Guidance is provided for maintaining lockfile integrity through registry pinning and the use of the onlyBuiltDependencies allowlist.\n- [SAFE]: Best practices for secret management are documented, specifically advising against committing credentials or tokens to the repository.\n- [SAFE]: External references target well-known security research and official package registries.
Audit Metadata