pnpm
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends using official migration and upgrade tools from well-known frameworks, including
@astrojs/upgrade,svelte-migrate, and@next/codemod. These are established tools for package maintenance. - [COMMAND_EXECUTION]: The instructions direct the agent to run standard project scripts such as
pnpm testorpnpm validateafter inspecting the project'spackage.jsonfile. This is standard behavior for development-oriented tools. - [PROMPT_INJECTION]: No attempts to override agent behavior or bypass safety guidelines were detected in the instructions.
- [DATA_EXFILTRATION]: No evidence of sensitive data access or unauthorized network operations was found. The skill specifically suggests security checks using the
agent:socketprocedure before package installation.
Audit Metadata