stash-supply-chain-security

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as documentation for supply chain security controls within a pnpm workspace environment.\n- [SAFE]: Guidance is provided for maintaining lockfile integrity through registry pinning and the use of the onlyBuiltDependencies allowlist.\n- [SAFE]: Best practices for secret management are documented, specifically advising against committing credentials or tokens to the repository.\n- [SAFE]: External references target well-known security research and official package registries.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 09:11 PM